First Scan
Once a sensor is registered and online, you assign scanners to it. Scanners are the discovery engines — each type knows how to find crypto assets from a specific source.
Step 1 — Add a Scanner
Section titled “Step 1 — Add a Scanner”- Go to Sensors → expand your sensor card
- Click Add Scanner
- The scanner catalogue opens — browse by category or search
- Select a scanner type (e.g., TLS Endpoint for network scanning)
- Configure it:
# Example: TLS Endpoint scannerendpoints: - api.yourcompany.com:443 - mail.yourcompany.com:993 - internal.service:8443timeoutMs: 10000- Set a schedule (hourly, daily, weekly)
- Optionally add a label (e.g., “Production Web Servers”)
- Click Save Scanner
Step 2 — Trigger the Scan
Section titled “Step 2 — Trigger the Scan”The scan will run automatically according to schedule. To run immediately:
- Expand the sensor card
- Find the scanner row in the table
- Click Scan Now in the Actions column
Or click Force Scan All at the bottom to trigger every assigned scanner.
Step 3 — View Results
Section titled “Step 3 — View Results”After the scan completes (typically seconds to minutes depending on target count):
- Dashboard — shows updated asset counts, risk distribution, and recent scans
- Inventory — browse all discovered assets with filters
- Sensor card — shows scan status, asset count, and timestamp
Click any asset in the inventory to open the detail panel showing:
- Algorithm, key size, and quantum risk level
- Certificate details (subject, issuer, validity, serial number)
- Discovery location (target URL, hostname, scanner type)
- Key pair relationships (linked certificates, keys)
- Scanner metadata
What Gets Discovered
Section titled “What Gets Discovered”Depending on the scanner type, you’ll see:
| Scanner | Assets Found |
|---|---|
| TLS Endpoint | Certificates (full chain), public keys, protocols, cipher suites |
| Filesystem | Certificates, private keys, public keys from PEM/DER/P12/JKS files |
| Source Code | Algorithm usage, hardcoded keys, crypto library imports |
| Binary | Code signatures, embedded certificates, linked crypto libraries |
| SSH Endpoint | SSH host keys, key exchange algorithms, encryption algorithms |
| AWS | ACM certificates, KMS keys, IAM credentials |
| Windows Cert Store | All certificates from LocalMachine/CurrentUser stores |
Next Steps
Section titled “Next Steps”- Dashboard — Understand the analytics
- Inventory — Browse and filter assets
- Compliance — Evaluate against policy standards
- Scanner Reference — Configure all scanner types