Skip to content

Run an OWASP ZAP Passive Baseline in an Isolated Lab

OWASP ZAP’s baseline scan performs passive analysis of HTTP traffic. This lab runs it against OWASP Juice Shop inside a Docker network that is not published to the host, then saves a report for review.

Use the lab for training or against an application you own and are authorized to assess. A passive baseline is useful for finding common web security signals, but it is not a penetration test or a complete security assessment.


Step 1: Create a Private Docker Network

01

Prepare an Isolated Lab Network

Lab Setup

Confirm Docker is available and create a dedicated bridge network. The application container will not publish a port on the host; the scanner can reach it by its container name over this network.

Terminal window
docker --version
docker network create --internal zap-lab
mkdir -p zap-reports
❯ View Expected Console Output
Docker version ...
<network-id>

Step 2: Start the Training Application

02

Run Juice Shop Without Publishing a Host Port

Training Target

Start the official Juice Shop container on the private lab network. Because no host port is mapped, the training application is not directly reachable through the host’s network interfaces.

Terminal window
docker run -d --name juice-shop --network zap-lab \
bkimminich/juice-shop
docker ps --filter name=juice-shop
❯ View Expected Console Output
CONTAINER ID IMAGE STATUS
... bkimminich/juice-shop Up ...

Step 3: Run ZAP’s Passive Baseline

03

Generate a Baseline Report

Passive Review

Run the official stable ZAP container on the same network and mount only the report directory. The baseline script spiders the target and reports passive findings; it does not perform active attack scans.

Terminal window
docker run --rm --network zap-lab \
-v "$PWD/zap-reports:/zap/wrk/:rw" \
zaproxy/zap-stable \
zap-baseline.py -t http://juice-shop:3000 -r baseline.html
❯ View Expected Console Output
PASS: The target appears to be available
WARN-NEW: ...
Report generated at: /zap/wrk/baseline.html

Step 4: Triage Findings and Tear Down the Lab

04

Review Evidence and Remove Containers

Closeout

Open the HTML report, validate each alert in context, and record which findings are real, false positives, or accepted risks. Keep the report access-controlled if it contains application details. Remove the lab when finished.

Terminal window
ls -lh zap-reports/baseline.html
docker rm -f juice-shop
docker network rm zap-lab
❯ View Expected Console Output
baseline.html ...K
juice-shop
zap-lab
OWASP ZAP Alerts tab showing passive response-header findings for Juice Shop

Figure 1: ZAP’s Alerts view lists passive response-header findings for the isolated Juice Shop target.

Comments