You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OWASP ZAP中获取扫描规则关联告警列表并自动生成表格

Automatically Generate Alert Tables in OWASP ZAP

Got it, let's figure out how to generate that alert table automatically (or semi-automatically) in OWASP ZAP, so you don't have to manually copy URLs anymore. Here are three solid methods to get this done:

Method 1: Use ZAP's Built-in Export Feature (No Code Needed)

This is the quickest way for one-off exports:

  • After running your scan, click the Alerts tab in ZAP's left-hand panel.
  • Select all alerts you want to include (use Ctrl+A to select everything).
  • Right-click the selected alerts, then choose Export → Export Selected Alerts.
  • In the export dialog, pick CSV as the format (it’s the easiest to convert to a Markdown table).
  • Once exported, open the CSV in Excel, Google Sheets, or a Markdown editor with a CSV-to-table tool (like VS Code’s Markdown All in One extension) to convert it into your desired table format. The CSV includes all the fields you need:
    • Alert Name (maps to ZAP’s "Alert" field)
    • URL (direct from the alert)
    • Scan Type (ZAP’s "Source" field)
    • Scan_Name (match scan IDs to names via ZAP’s Scans tab if needed)
    • WASCID and CWEID (directly included in the export)

Method 2: Use ZAP's REST API for Programmatic Export

If you need to automate this (e.g., for CI/CD pipelines), use ZAP’s REST API. Here’s a quick Python script to fetch alerts and output a ready-to-use Markdown table:

First, enable ZAP’s API: Go to Tools → Options → API, check "Enable API", and copy your API key from this screen.

import requests

ZAP_BASE_URL = "http://localhost:8080"
API_KEY = "your_api_key_here"

# Fetch all alerts from ZAP
alerts_response = requests.get(f"{ZAP_BASE_URL}/JSON/alerts/view/alerts/", params={"apikey": API_KEY})
alerts = alerts_response.json()["alerts"]

# Fetch scan details to map IDs to names
scans_response = requests.get(f"{ZAP_BASE_URL}/JSON/scans/view/scans/", params={"apikey": API_KEY})
scans = {scan["id"]: scan["name"] for scan in scans_response.json()["scans"]}

# Define table columns
columns = ["Alert Name", "URL", "Scan Type", "Scan_Name", "WASCID", "CWEID"]

# Print Markdown table header
print("| " + " | ".join(columns) + " |")
print("| " + " | ".join(["---" for _ in columns]) + " |")

# Print each alert row
for alert in alerts:
    scan_name = scans.get(str(alert["scanId"]), "N/A")
    row = [
        alert["alert"],
        alert["url"],
        alert["source"],
        scan_name,
        alert["wascId"],
        alert["cweId"]
    ]
    print("| " + " | ".join(str(item) for item in row) + " |")

Run this script, and it’ll print the Markdown table directly to your terminal. You can modify it to save the table to a file if needed.

Method 3: Use ZAP's Built-in Script Console

If you prefer to work entirely within ZAP’s UI, use the Script Console:

  • Open ZAP, go to Tools → Script Console.
  • Create a new JavaScript script (click the the "+" button, choose "JavaScript" as the type).
  • Paste this code into the editor:
// Fetch all alerts
var alerts = org.parosproxy.paros.core.scanner.Alert.getAlerts();
// Map scan IDs to names
var scans = org.parosproxy.paros.control.Control.getSingleton().getScanner().getScans();
var scanMap = new java.util.HashMap();
for (var i = 0; i < scans.size(); i++) {
    var scan = scans.get(i);
    scanMap.put(scan.getId(), scan.getName());
}

// Define table columns
var columns = ["Alert Name", "URL", "Scan Type", "Scan_Name", "WASCID", "CWEID"];

// Print Markdown header
print("| " + columns.join(" | ") + " |");
print("| " + columns.map(() => "---").join(" | ") + " |");

// Print each alert row
for (var j = 0; j < alerts.size(); j++) {
    var alert = alerts.get(j);
    var scanName = scanMap.get(alert.getScanId()) || "N/A";
    var row = [
        alert.getName(),
        alert.getUri().toString(),
        alert.getSource(),
        scanName,
        alert.getWascId(),
        alert.getCweId()
    ];
    print("| " + row.join(" | ") + " |");
}
  • Click the "Run" button (▶️), and the script will output the Markdown table directly in the console. Just copy and paste it wherever you need.

内容的提问来源于stack exchange,提问作者Ferda-Ozdemir-Sonmez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:26:06