Run an OWASP ZAP Passive Baseline in an Isolated Lab
OWASP ZAP’s baseline scan performs passive analysis of HTTP traffic. This lab runs it against OWASP Juice Shop inside a Docker network that is not published to the host, then saves a report for review.
Use the lab for training or against an application you own and are authorized to assess. A passive baseline is useful for finding common web security signals, but it is not a penetration test or a complete security assessment.
Step 1: Create a Private Docker Network
Prepare an Isolated Lab Network
Lab SetupConfirm Docker is available and create a dedicated bridge network. The application container will not publish a port on the host; the scanner can reach it by its container name over this network.
docker --versiondocker network create --internal zap-labmkdir -p zap-reports❯ View Expected Console Output
Docker version ...<network-id>Step 2: Start the Training Application
Run Juice Shop Without Publishing a Host Port
Training TargetStart the official Juice Shop container on the private lab network. Because no host port is mapped, the training application is not directly reachable through the host’s network interfaces.
docker run -d --name juice-shop --network zap-lab \ bkimminich/juice-shopdocker ps --filter name=juice-shop❯ View Expected Console Output
CONTAINER ID IMAGE STATUS... bkimminich/juice-shop Up ...Step 3: Run ZAP’s Passive Baseline
Generate a Baseline Report
Passive ReviewRun the official stable ZAP container on the same network and mount only the report directory. The baseline script spiders the target and reports passive findings; it does not perform active attack scans.
docker run --rm --network zap-lab \ -v "$PWD/zap-reports:/zap/wrk/:rw" \ zaproxy/zap-stable \ zap-baseline.py -t http://juice-shop:3000 -r baseline.html❯ View Expected Console Output
PASS: The target appears to be availableWARN-NEW: ...Report generated at: /zap/wrk/baseline.htmlStep 4: Triage Findings and Tear Down the Lab
Review Evidence and Remove Containers
CloseoutOpen the HTML report, validate each alert in context, and record which findings are real, false positives, or accepted risks. Keep the report access-controlled if it contains application details. Remove the lab when finished.
ls -lh zap-reports/baseline.htmldocker rm -f juice-shopdocker network rm zap-lab❯ View Expected Console Output
baseline.html ...Kjuice-shopzap-lab
Figure 1: ZAP’s Alerts view lists passive response-header findings for the isolated Juice Shop target.