Skip to content

Inventory

The Inventory page is the primary interface for browsing all discovered cryptographic assets. Every certificate, key, algorithm usage, protocol, and signature found by any scanner appears here.


A tab bar at the top filters by asset type:

TabWhat It Shows
AllEvery asset across all types
CertificatesX.509 certificates from endpoints, files, keystores, AD
Private KeysRSA, EC, Ed25519 private keys
Public KeysStandalone public keys
Symmetric KeysAES, ChaCha20 keys
SignaturesCode signatures (Authenticode, JAR)
Source CodeCrypto API usage detected in source code

Each tab shows a count badge. The right side shows total result count, export buttons, and a relationship rebuild trigger.


A compact filter bar supports:

  • Full-text search — matches name, algorithm, subject, fingerprint, and other fields
  • Risk Level — CRITICAL, HIGH, MEDIUM, LOW, NONE
  • Algorithm — filter by algorithm name (RSA, EC, AES, etc.)
  • Scanner — filter by scanner type that discovered the asset
  • Sensor — filter by which sensor found it

When the Certificates tab is active:

  • Expiry — Expired, < 7 days, < 30 days, < 90 days, Valid
  • CA/EE — CA Only, End-Entity, Self-Signed

When the Source Code tab is active:

  • Language — Java, Python, Go, JavaScript, TypeScript, C#

Save frequently-used filter combinations for quick access. Saved searches appear as clickable chips below the filter bar.


The table shows key columns per asset type. Clicking any row opens the detail panel.


A slide-in panel from the right showing complete asset information:

  • Asset name, type badge, risk level badge
  • Algorithm, key size, fingerprint
  • Key Pair Fingerprint (clickable — shows all assets sharing the same key pair)
  • Subject, Issuer, Serial Number
  • Valid From / Valid Until (with expiry warning)
  • Signature Algorithm
  • Issuer Certificate Fingerprint
  • CA status, Self-Signed status
  • Key format, key purpose
  • Lifecycle state
  • Target URI, scanner type, hostname, sensor name, discovered timestamp
  • Custom metadata attached by the scanner (context labels, source info)
  • Visual tree showing:
    • Issuer chain (which CA issued this certificate)
    • Key pair members (linked private key, public key, certificate)
    • Issued certificates (what this CA has signed)

Two export options available from the tab bar:

  • JSON — raw asset data for custom processing
  • CDX — CycloneDX v1.6 CBOM export of the current filtered view