Known-Good Configuration Baseline
A verified Caddy configuration containing the approved Juice Shop reverse-proxy routing is preserved as the approved security baseline.
Provide a trusted reference for identifying unauthorized configuration changes.
Caddy is an open-source web server and reverse proxy that can serve web applications and route requests to backend services. It commonly uses the human-readable Caddyfile format to define site addresses, routing behavior, reverse-proxy destinations, request handling, logging, and other web-server functionality. Caddy also supports dynamic configuration through its administrative API.
The target web application in this use case is OWASP Juice Shop, an open-source deliberately insecure web application designed for security training, demonstrations, and security-tool testing. Juice Shop is built using technologies including Node.js, Express, and Angular.
In this architecture, Caddy is the primary web-server target, while OWASP Juice Shop is the backend web application placed behind Caddy. Caddy forwards requests received at its web endpoint to the Juice Shop backend through its reverse-proxy functionality.
Web-server configuration files are security-sensitive because unauthorized modifications can change how a web application processes requests. An attacker who obtains sufficient access to a Caddy host may modify the Caddyfile or another configuration component to redirect traffic, expose unintended services, alter request-handling behavior, weaken security controls, or introduce unauthorized routing rules.
Caddy supports configuration reloads through the caddy reload command and its administrative API. Configuration changes can therefore be applied to the running web server without unnecessarily stopping the service.
In this use case, a controlled Caddy web server is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. OWASP Juice Shop is deployed as the controlled backend application and placed behind Caddy so that changes to Caddy routing or reverse-proxy configuration can be observed through controlled web requests.
Kali Linux is used as the authorized security-testing platform. A controlled configuration-tampering scenario is created by modifying the laboratory Caddy configuration in a way that changes the expected routing behavior toward the Juice Shop application.
The security-monitoring layer uses Wazuh File Integrity Monitoring (FIM) to monitor Caddy configuration files. Wazuh FIM can detect file creation, modification, and deletion and supports real-time monitoring of specified Linux directories. It compares monitored file attributes and checksums against its stored baseline and generates alerts when changes are detected.
When unauthorized configuration modification is detected, the SOC workflow generates a security alert and invokes a controlled Wazuh Active Response action. Wazuh Active Response can execute predefined or custom scripts when specified rules or alert conditions are triggered.
The controlled response restores the approved Caddy configuration, validates the restored configuration, reloads Caddy using its supported configuration-reload mechanism, and verifies that the Juice Shop web application has returned to its known-good state.
OpenSearch is used for centralized investigation and correlation of configuration-integrity alerts, Caddy activity, response actions, and post-remediation validation.
The complete workflow demonstrates a SOC/MDR-style detection and response process in which Caddy configuration tampering is detected as a security event and automatically contained through controlled configuration restoration.
Complete Security Operations & Incident Response Workflow: Caddy Deployment → OWASP Juice Shop Deployment → Configuration Baseline → Configuration-Integrity Monitoring → Unauthorized Configuration Change → Wazuh FIM Detection → Security Alert → Event Correlation → Automated Response → Known-Good Configuration Restoration → Caddy Configuration Validation → Caddy Reload → Juice Shop Service Validation → OpenSearch Investigation → Post-Response Monitoring
Caddy provides the controlled web-server and reverse-proxy environment, while OWASP Juice Shop is the named backend web application used to demonstrate the effects of Caddy configuration changes. Caddy can forward incoming requests to a backend service, making it suitable for placing Juice Shop behind the web-server layer. The Caddyfile defines web-server behavior through directives and site configuration. Caddy also supports configuration management through its administrative API and reload workflow.
A Caddy deployment can be exposed to configuration-tampering risk when an attacker obtains unauthorized access to the host, configuration files, deployment pipeline, or administrative control interface. An unauthorized modification to a Caddy configuration can alter the routing or behavior of the web service without necessarily modifying the Juice Shop application itself.
The security problem is therefore:
The proposed SOC architecture establishes a known-good Caddy configuration baseline, continuously monitors the relevant configuration files, detects unauthorized changes, generates security alerts, and automatically restores the approved configuration through a controlled response mechanism. It then validates the Caddy configuration and the Juice Shop service after remediation, while OpenSearch supports centralized investigation and incident-timeline review.
The controlled attack scenario evaluates whether unauthorized modification of a Caddy configuration can be detected and automatically remediated by the security-monitoring architecture. The modification is designed to produce a measurable change in Caddy routing behavior toward the OWASP Juice Shop application while remaining within the isolated laboratory.
When the file-integrity deviation is detected, Wazuh generates the corresponding security event. A controlled Active Response mechanism then restores the approved configuration and triggers the required Caddy configuration reload. The response is validated by checking configuration integrity and the behavior of the OWASP Juice Shop web application.
The primary security concept is configuration-integrity monitoring. Critical web-server configuration files should have an established known-good state against which subsequent modifications can be evaluated. Wazuh File Integrity Monitoring provides this capability by monitoring specified files and directories and detecting creation, modification, and deletion events.
For this use case, the Caddy configuration is treated as a critical security asset, while the OWASP Juice Shop application is used to demonstrate the resulting web-service behavior. The second security concept is automated security response. Detection alone does not immediately restore a tampered web-server configuration, so the SOC workflow connects the integrity alert to a controlled Wazuh Active Response action. The response script restores the approved configuration, validates it, and reloads Caddy using its supported configuration-reload mechanism. The resulting application behavior is then verified through controlled requests to the OWASP Juice Shop service.
The secure processing flow is:
A verified Caddy configuration containing the approved Juice Shop reverse-proxy routing is preserved as the approved security baseline.
Provide a trusted reference for identifying unauthorized configuration changes.
The Caddy configuration file and relevant configuration directories are monitored by Wazuh FIM.
Detect unauthorized creation, modification, or deletion of monitored web-server configuration files.
Wazuh FIM is configured for real-time monitoring of the designated Linux configuration path.
Reduce the detection delay between configuration tampering and SOC alert generation.
Wazuh compares monitored file checksums and attributes with its stored integrity baseline.
Identify configuration-integrity deviations that may indicate unauthorized modification.
A Wazuh security rule evaluates the detected configuration-change event.
Convert a raw file-integrity event into an actionable SOC security alert.
Configuration-integrity events are correlated with Caddy and Ubuntu activity.
Provide context for determining whether the configuration change is expected or suspicious.
A controlled Wazuh Active Response script restores the approved Caddy configuration when the defined tampering alert is triggered.
Automatically return the monitored Caddy configuration to the known-good security state.
The restored Caddy configuration is validated before the active configuration is reloaded.
Prevent an invalid or corrupted configuration from being applied to the running web server.
The validated configuration is applied using the supported Caddy reload mechanism.
Restore the intended web-server behavior without unnecessarily stopping the running service.
The Caddy administrative API is restricted to the intended local or controlled management interface.
Reduce the risk of unauthorized direct control of the Caddy configuration.
The Caddy-to-Juice-Shop web path is tested after automated remediation.
Confirm that the restored configuration produces the expected application behavior.
OpenSearch is used to correlate integrity alerts, Caddy events, response execution, and validation results.
Provide a complete investigation timeline for the configuration-tampering incident.
Caddy provides the controlled web-server and reverse-proxy environment.
OWASP Juice Shop provides the named backend web application for the laboratory. It is an open-source deliberately insecure web application intended for security training and security-tool testing.
The Caddyfile provides the human-readable configuration used to define the laboratory web-server behavior.
Caddy provides an administrative API for managing the active configuration.
Wazuh provides File Integrity Monitoring and Active Response capabilities for security monitoring and controlled remediation.
Wazuh FIM establishes and monitors the integrity state of designated files and directories.
Wazuh Active Response executes a controlled response script when the configured security rule is triggered.
OpenSearch provides centralized investigation and correlation of security events.
Kali Linux provides the authorized security-testing environment for generating controlled configuration-tampering activity.
Ubuntu hosts Caddy, OWASP Juice Shop, and the monitored security components in the isolated laboratory.
cURL is used to validate the behavior of the Caddy web service before and after configuration changes.
VirtualBox provides the isolated security laboratory for the Ubuntu and Kali Linux virtual machines.