Skip to content

First Scan

Once a sensor is registered and online, you assign scanners to it. Scanners are the discovery engines — each type knows how to find crypto assets from a specific source.


  1. Go to Sensors → expand your sensor card
  2. Click Add Scanner
  3. The scanner catalogue opens — browse by category or search
  4. Select a scanner type (e.g., TLS Endpoint for network scanning)
  5. Configure it:
# Example: TLS Endpoint scanner
endpoints:
- api.yourcompany.com:443
- mail.yourcompany.com:993
- internal.service:8443
timeoutMs: 10000
  1. Set a schedule (hourly, daily, weekly)
  2. Optionally add a label (e.g., “Production Web Servers”)
  3. Click Save Scanner

The scan will run automatically according to schedule. To run immediately:

  1. Expand the sensor card
  2. Find the scanner row in the table
  3. Click Scan Now in the Actions column

Or click Force Scan All at the bottom to trigger every assigned scanner.


After the scan completes (typically seconds to minutes depending on target count):

  1. Dashboard — shows updated asset counts, risk distribution, and recent scans
  2. Inventory — browse all discovered assets with filters
  3. Sensor card — shows scan status, asset count, and timestamp

Click any asset in the inventory to open the detail panel showing:

  • Algorithm, key size, and quantum risk level
  • Certificate details (subject, issuer, validity, serial number)
  • Discovery location (target URL, hostname, scanner type)
  • Key pair relationships (linked certificates, keys)
  • Scanner metadata

Depending on the scanner type, you’ll see:

ScannerAssets Found
TLS EndpointCertificates (full chain), public keys, protocols, cipher suites
FilesystemCertificates, private keys, public keys from PEM/DER/P12/JKS files
Source CodeAlgorithm usage, hardcoded keys, crypto library imports
BinaryCode signatures, embedded certificates, linked crypto libraries
SSH EndpointSSH host keys, key exchange algorithms, encryption algorithms
AWSACM certificates, KMS keys, IAM credentials
Windows Cert StoreAll certificates from LocalMachine/CurrentUser stores