Network Scanners
Network scanners connect to remote services and extract cryptographic information from the protocol handshake — without needing access to the server’s filesystem or configuration.
TLS Endpoint Scanner
Section titled “TLS Endpoint Scanner”Type: network-tls
Category: Network
Access Mode: NETWORK
Produces: certificate, public-key, protocol
Connects to any TLS-speaking endpoint and extracts the full certificate chain, cipher suite negotiation, and protocol version.
What It Discovers
Section titled “What It Discovers”- Full certificate chain (leaf → intermediate → root)
- Public keys from each certificate
- Negotiated protocol version (TLS 1.2, TLS 1.3)
- Cipher suite details
- Certificate expiry and validity information
Configuration
Section titled “Configuration”endpoints: - api.example.com:443 - mail.example.com:993 - internal.service:8443 - 10.0.1.50:636timeoutMs: 10000Config Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
endpoints | string list | Yes | — | Host:port entries to scan. Any TLS-speaking port works (HTTPS, IMAPS, LDAPS, etc.) |
timeoutMs | integer | No | 10000 | Connection timeout in milliseconds |
Example Output
Section titled “Example Output”For api.example.com:443, you’ll get:
- Certificate: “api.example.com” (RSA-2048, expires 2025-03-15)
- Certificate: “DigiCert SHA2 Intermediate CA” (RSA-2048, CA)
- Public Key: RSA-2048 public key (api.example.com)
- Protocol: TLS 1.3 with TLS_AES_256_GCM_SHA384
SSH Endpoint Scanner
Section titled “SSH Endpoint Scanner”Type: network-ssh
Category: Network
Access Mode: NETWORK
Produces: public-key, protocol
Connects to SSH servers and extracts host keys, key exchange algorithms, and encryption details from the SSH handshake. Does not authenticate — only performs the initial handshake.
What It Discovers
Section titled “What It Discovers”- SSH host keys (RSA, Ed25519, ECDSA)
- Key exchange algorithms offered
- Encryption algorithms (ciphers)
- MAC algorithms
- Host key fingerprints
Configuration
Section titled “Configuration”endpoints: - server1.example.com:22 - server2.example.com - 10.0.1.100:2222timeoutMs: 10000Config Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
endpoints | string list | Yes | — | Host:port entries. Port defaults to 22 if omitted |
timeoutMs | integer | No | 10000 | Connection timeout in milliseconds |
Example Output
Section titled “Example Output”For server1.example.com:22:
- Public Key: Ed25519 host key (server1.example.com)
- Public Key: RSA-4096 host key (server1.example.com)
- Public Key: ECDSA-256 host key (server1.example.com)
- Protocol: SSH-2 with key exchange curve25519-sha256
- Port flexibility — TLS scanner works on any port speaking TLS, not just 443. Use it for IMAPS (993), LDAPS (636), SMTPS (465), database TLS, etc.
- Internal services — Deploy a sensor on the same network as internal services to scan endpoints not reachable from the internet.
- Scan frequency — Use
dailyfor production endpoints,weeklyfor stable infrastructure. - Timeout tuning — Increase
timeoutMsfor slow or geographically distant endpoints.
Related
Section titled “Related”- Filesystem Scanners — Scan certificate and key files
- Sensors — Assign scanners to sensors