Bugcrowd HUNT

You can add a lot of extensions and addons to ZAP, one of them is "Bugcrowd HUNT"

What is ZAP?

Bugcrowd HUNT is a passively scan for known vulnerabilities in web applications. Once you navigate in the website, the traffic will go through ZAP. This add on scans for known vulnerabilities as you go.

In your Kali machine navigate via your terminal to a folder you’d like to store the scripts.

git clone https://github.com/bugcrowd/HUNT

cd to the folder you just downloaded, and copy the "passive" folder to:

/root/.ZAP/scripts/scripts/

This is what your path will look like.

/root/.ZAP/scripts/scripts/passive/

Now, in ZAP, click the “Manage Add-Ons” icon: