16 lines
680 B
Markdown
16 lines
680 B
Markdown
# OWASP ZAP Methodology
|
|
|
|
ZAP performs web application tests from ephemeral GitLab Kubernetes-executor pods. Targets come from the `web_applications` group in root `assets.yml`; authentication values come from environment-scoped GitLab variables.
|
|
|
|
The OWASP ASVS source material used to develop the finding-to-control mapping is retained under `reference/OWASP_ASVS`.
|
|
|
|
`run.sh` executes ZAP baseline scanning and a focused TLS preflight, because ZAP
|
|
does not enumerate all protocol and cipher weaknesses. `scripts/normalize.py`
|
|
maps both evidence sources to OWASP ASVS 5 controls using `asvs-mapping.json`.
|
|
|
|
Run with:
|
|
|
|
```bash
|
|
./methodologies/zap/run.sh https://target.example
|
|
```
|