Skip to main content

Session Cookie

HostedScan supports setting custom cookies for the ZAP scanner. This may be a good option for a one-time scan. For recurring scheduled scans we recommend using the recorded login because a fixed cookie value will expire after some time.

Usually the easiest way to do this it to log in to the web application as you normally would. Then inspect the cookie storage using your browser's developer tools and find the session cookie.

  • In your HostedScan account, edit the Target you are configuring for authenticated scanning.

    Configure HostedScan target for authenticated scanning
  • Configure the session cookie

    Configure cookie on target
  • Exclude logout URLs from the scan

    Ensure that the scanner does not log out during the scan by excluding the logout URL(s).

    Exclude URLs from scan

3. Run a scan!

  • Click the "New Scan" button
  • Select the OWASP ZAP Active Web Application Scan
  • Select your target
  • Continue through the scan options and click "Run Scan"