Filesystem Scanners
Filesystem scanners read certificate and key files directly from disk — PEM, DER, PKCS#12, JKS, and SSH key formats.
Filesystem Certificates & Keys
Section titled “Filesystem Certificates & Keys”Type: filesystem-certs
Category: Filesystem
Access Mode: AGENT
Produces: certificate, public-key, private-key
Recursively scans directories for cryptographic files. Parses PEM, DER, PKCS#12, JKS, and standalone key files.
What It Discovers
Section titled “What It Discovers”- X.509 certificates (PEM and DER encoded)
- Private keys (RSA, EC, Ed25519 — PKCS#1, PKCS#8, encrypted PEM)
- Public keys (standalone PEM/DER files)
- Java Keystores (JKS) — all entries
- PKCS#12 files (.p12, .pfx) — certificates and keys
- Certificate Signing Requests (CSR)
Supported File Extensions
Section titled “Supported File Extensions”.pem, .crt, .cer, .key, .csr, .der, .p12, .pfx, .jks
Configuration
Section titled “Configuration”paths: - /etc/ssl/certs - /opt/app/keystores - /home/deploy/.sshpassword: changeitConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
paths | string list | Yes | — | Directories to scan recursively |
password | string | No | — | Password for PKCS#12 and JKS keystores |
- The scanner reads files but never modifies them
- Encrypted PEM keys are detected but cannot be parsed without the passphrase (they still appear as assets with algorithm info)
- Keystores with individual entry passwords different from the store password may not fully parse
SSH Key Files
Section titled “SSH Key Files”Type: filesystem-keys
Category: Filesystem
Access Mode: AGENT
Produces: public-key, private-key
Scans standard SSH key locations for authorized keys, identity files, and host keys.
What It Discovers
Section titled “What It Discovers”- SSH private keys (
id_rsa,id_ed25519,id_ecdsa) - SSH public keys (
.pubfiles) authorized_keysentries- SSH host keys (
/etc/ssh/ssh_host_*)
Configuration
Section titled “Configuration”paths: - ~/.ssh - /etc/sshConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
paths | string list | No | ~/.ssh, /etc/ssh, Windows user .ssh dir | Directories to scan |
No configuration required — works with sensible defaults for the current platform.
Remote Filesystem (Agentless)
Section titled “Remote Filesystem (Agentless)”Type: filesystem-remote
Category: Filesystem
Access Mode: SSH, WINRM
Produces: certificate, public-key, private-key
Scans remote machines over SSH or WinRM without needing a sensor installed on each target. Useful for scanning many servers from a single sensor.
What It Discovers
Section titled “What It Discovers”Same as the local filesystem scanner — certificates, keys, and keystores on remote machines.
Configuration
Section titled “Configuration”hosts: - host: webserver1.internal transport: ssh port: 22 username: cbom-scanner privateKey: /opt/cbom/scanner-key os: linux scanPaths: - /etc/ssl - /opt/app/certs - host: winserver1.internal transport: winrm port: 5986 username: cbom-svc password: secure-password os: windows scanPaths: - C:\Certificates scanCertStore: true scanTrustStores: trueConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
hosts | object list | Yes | — | Remote hosts to scan |
hosts[].host | string | Yes | — | Hostname or IP |
hosts[].transport | string | Yes | — | ssh or winrm |
hosts[].port | integer | No | 22 (SSH) / 5986 (WinRM) | Connection port |
hosts[].username | string | Yes | — | Login username |
hosts[].password | string | No | — | Password (alternative to key) |
hosts[].privateKey | string | No | — | Path to SSH private key file |
hosts[].os | string | No | linux | Operating system: linux or windows |
hosts[].scanPaths | string list | Yes | — | Directories to scan on remote |
hosts[].scanCertStore | boolean | No | false | Also scan Windows Certificate Store (WinRM) |
hosts[].scanTrustStores | boolean | No | false | Discover and scan Java truststores |
- SSH transport uses the provided key or password for authentication
- WinRM transport requires HTTPS (port 5986) — ensure WinRM is configured for remote management
- Each host failure is isolated — one unreachable host won’t stop the scan of others
- Keystore passwords — If your keystores use different passwords, create multiple scanner configs (one per password)
- Permissions — The sensor process needs read access to the scanned directories
- Large directories — The scanner handles large directory trees efficiently but avoid scanning entire root filesystems
Related
Section titled “Related”- Network Scanners — Scan TLS/SSH endpoints
- Source Code Scanner — Scan code repos for crypto usage