S
24

Switched from Burp to OWASP ZAP for a 3-month pentest, might not go back

Ran a small pentest gig last month for a client in Austin, 14 APIs and a web app. I've been a Burp Suite Pro user since 2019, but my license was up for renewal at $449 and the client's budget was tight. Decided to try OWASP ZAP fully, even used its automation framework for the first time. It caught a broken auth token issue that Burp missed, or maybe I just missed it, hard to say. The UI took some getting used to, but the FuzzDB integration and free cost won me over. Has anyone else made the jump for real projects and stuck with ZAP longer than a trial?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.