Name:zap-api-scan
Category:Scanners
Publisher:trickest-mhmdiaa
Created:5/25/2022
Container:
quay.io/trickest/zap-api-scan:v2.11.1Output Type:
License:Unknown
Source:View Source
Parameters
-juse the Ajax spider in addition to the traditional one-Uusername to use for authenticated scans - must be defined in the given context file-ainclude the alpha active and passive scan rules as well-dshow debug messages in stdout-Ddelay in seconds to wait for passive scanning-lminimum level to show: PASS, IGNORE, INFO, WARN or FAIL, use with -s (short-output) to hide example URLs-fAPI format: openapi, soap, or graphql--schemaGraphQL schema URL, e.g. https://www.example.com/schema.graphqls-Tmax time in minutes to wait for ZAP to start and the passive scan to run-Othe hostname to override in the (remote) OpenAPI spec-SSafe mode this will skip the active scan and perform a baseline scan-cconfig file to use to INFO, IGNORE or FAIL warnings-zZAP command line options-ncontext file which will be loaded prior to scanning the target-sshort output format - dont show PASSes or example URLs-ttarget API definition file, OpenAPI or SOAP-ttarget API definition URL (e.g. https://www.example.com/openapi.json, https://www.example.com/graphql)