use case
Authenticated Web Application Vulnerability Scan
Scan behind the login of websites and web apps

what it is
What is an Authenticated Vulnerability Scan?
An authenticated vulnerability scan logs in to the target web application. This allows the scan to cover sections of the application that are accessible only to logged in users. For many web applications, a significant amount of the content is behind a log in and an authenticated scan is required for a thorough security test.
You can authenticate using two methods:
By creating a selenium script to walk through your login form. Read below for details.
By configuring customized request headers for alternative authentication strategies like Basic Authentication, Bearer Token and API keys. Read more on Customize Request Headers (OWASP Zap).
how it works
How to set up and run an authenticated scan
With HostedScan Security you can easily run authenticated OWASP ZAP scans using a recorded login for your web application. HostedScan uses the recorded login to authenticate into your application and scan behind the login.
Follow the steps below to configure your authentication and run scans.
01
Record the Authentication
HostedScan uses Selenium recordings to capture and replay the login steps for a website. Selenium is a widely used open-source tool for recording and automating actions on a web page.
- Install the Selenium IDE browser extension for Firefox or run the Selenium IDE desktop application. The desktop application can be easily launched using a node package manager such as npm:
npx selenium-ide. Note that the Selenium IDE browser extension is currently not supported in Chrome due to recent changes in Chrome extension requirements. - Open the extension and select Record a new test in a new project, enter a name for the project, enter your website's URL, and then click Start recording.
- Your website will open in a new window where you will make the recording. Authenticate to your website and Selenium will record the actions.
Always use a test user account. Some scans will click buttons and submit forms as part of testing, which could cause changes to the account. - After logging in to your website, stop the recording and save it as a .side file.

- Install the Selenium IDE browser extension for Firefox or run the Selenium IDE desktop application. The desktop application can be easily launched using a node package manager such as npm:
02
Upload the Recorded Authentication to HostedScan
HostedScan uses Selenium recordings to capture and replay the login steps for a website. Selenium is a widely used open-source tool for recording and automating actions on a web page.
- In your HostedScan account, edit the Target you are configuring for authenticated scanning.
- Click Upload New File and upload the .side file that you previously recorded with Selenium.
- Under Logout Routes to Exclude, list the logout URLs for your application. e.g. https://mysite.com/logout.
It is important to configure these URLs so that the scanner does not visit them and unauthenticate during the scan. - Test your configuration by clicking >> Test Now. This will test if we can play back your Selenium recording. When the test is finished, verify that the captured screenshot shows your website authenticated as you expect.

03
Run Scan!
On the Targets menu click the New Scan button.
The scan may take a couple minutes to start as it goes through the authentication process.

04
Select an OWASP ZAP Active Web Application Scan.

05
Select your Target.

06
Select the option to enable authentication (where you select schedule and email settings) and click "Submit"

Benefits of using HostedScan
Strengthen your
cybersecurity
resilience
Strengthen your cybersecurity resilience
Strengthen your
cybersecurity
resilience
Mitigate security vulnerabilities
Discover CVEs, OWASP Top 10 vulnerabilities, and exploitable weaknesses across your entire infrastructure. Get prioritized remediation guidance with CVSS scoring and actionable risk classifications—fix what matters first.
Manage your risk exposure
With regulations such as GDPR and CCPA, failure to maintain reasonable security procedures is grounds for lawsuits and fines.
Meet compliance requirements
Vulnerability scanning is essential for your compliance with SOC 2, ISO 27001, cyber insurance, and more.
Detect misconfigurations
90% of cyber attacks exploit simple misconfigurations, not zero-days. Detect exposed ports, weak credentials, outdated software, and common security gaps before attackers do—automatically, every day.
Map your attack surface
Your infrastructure changes constantly. Automatically discover and monitor all websites, servers, networks, and APIs—maintaining complete visibility of your attack surface without manual tracking.
Our Customers
5,000+ MSPs and IT teams who move faster
Speed and power,
without the complexity
The world's leading vulnerability scanners, all in one platform.






