Skip to content

Filesystem Scanners

Filesystem scanners read certificate and key files directly from disk — PEM, DER, PKCS#12, JKS, and SSH key formats.


Type: filesystem-certs
Category: Filesystem
Access Mode: AGENT
Produces: certificate, public-key, private-key

Recursively scans directories for cryptographic files. Parses PEM, DER, PKCS#12, JKS, and standalone key files.

  • X.509 certificates (PEM and DER encoded)
  • Private keys (RSA, EC, Ed25519 — PKCS#1, PKCS#8, encrypted PEM)
  • Public keys (standalone PEM/DER files)
  • Java Keystores (JKS) — all entries
  • PKCS#12 files (.p12, .pfx) — certificates and keys
  • Certificate Signing Requests (CSR)

.pem, .crt, .cer, .key, .csr, .der, .p12, .pfx, .jks

paths:
- /etc/ssl/certs
- /opt/app/keystores
- /home/deploy/.ssh
password: changeit
FieldTypeRequiredDefaultDescription
pathsstring listYes—Directories to scan recursively
passwordstringNo—Password for PKCS#12 and JKS keystores
  • The scanner reads files but never modifies them
  • Encrypted PEM keys are detected but cannot be parsed without the passphrase (they still appear as assets with algorithm info)
  • Keystores with individual entry passwords different from the store password may not fully parse

Type: filesystem-keys
Category: Filesystem
Access Mode: AGENT
Produces: public-key, private-key

Scans standard SSH key locations for authorized keys, identity files, and host keys.

  • SSH private keys (id_rsa, id_ed25519, id_ecdsa)
  • SSH public keys (.pub files)
  • authorized_keys entries
  • SSH host keys (/etc/ssh/ssh_host_*)
paths:
- ~/.ssh
- /etc/ssh
FieldTypeRequiredDefaultDescription
pathsstring listNo~/.ssh, /etc/ssh, Windows user .ssh dirDirectories to scan

No configuration required — works with sensible defaults for the current platform.


Type: filesystem-remote
Category: Filesystem
Access Mode: SSH, WINRM
Produces: certificate, public-key, private-key

Scans remote machines over SSH or WinRM without needing a sensor installed on each target. Useful for scanning many servers from a single sensor.

Same as the local filesystem scanner — certificates, keys, and keystores on remote machines.

hosts:
- host: webserver1.internal
transport: ssh
port: 22
username: cbom-scanner
privateKey: /opt/cbom/scanner-key
os: linux
scanPaths:
- /etc/ssl
- /opt/app/certs
- host: winserver1.internal
transport: winrm
port: 5986
username: cbom-svc
password: secure-password
os: windows
scanPaths:
- C:\Certificates
scanCertStore: true
scanTrustStores: true
FieldTypeRequiredDefaultDescription
hostsobject listYes—Remote hosts to scan
hosts[].hoststringYes—Hostname or IP
hosts[].transportstringYes—ssh or winrm
hosts[].portintegerNo22 (SSH) / 5986 (WinRM)Connection port
hosts[].usernamestringYes—Login username
hosts[].passwordstringNo—Password (alternative to key)
hosts[].privateKeystringNo—Path to SSH private key file
hosts[].osstringNolinuxOperating system: linux or windows
hosts[].scanPathsstring listYes—Directories to scan on remote
hosts[].scanCertStorebooleanNofalseAlso scan Windows Certificate Store (WinRM)
hosts[].scanTrustStoresbooleanNofalseDiscover and scan Java truststores
  • SSH transport uses the provided key or password for authentication
  • WinRM transport requires HTTPS (port 5986) — ensure WinRM is configured for remote management
  • Each host failure is isolated — one unreachable host won’t stop the scan of others

  • Keystore passwords — If your keystores use different passwords, create multiple scanner configs (one per password)
  • Permissions — The sensor process needs read access to the scanned directories
  • Large directories — The scanner handles large directory trees efficiently but avoid scanning entire root filesystems