Skip to content

Network Scanners

Network scanners connect to remote services and extract cryptographic information from the protocol handshake — without needing access to the server’s filesystem or configuration.


Type: network-tls
Category: Network
Access Mode: NETWORK
Produces: certificate, public-key, protocol

Connects to any TLS-speaking endpoint and extracts the full certificate chain, cipher suite negotiation, and protocol version.

  • Full certificate chain (leaf → intermediate → root)
  • Public keys from each certificate
  • Negotiated protocol version (TLS 1.2, TLS 1.3)
  • Cipher suite details
  • Certificate expiry and validity information
endpoints:
- api.example.com:443
- mail.example.com:993
- internal.service:8443
- 10.0.1.50:636
timeoutMs: 10000
FieldTypeRequiredDefaultDescription
endpointsstring listYes—Host:port entries to scan. Any TLS-speaking port works (HTTPS, IMAPS, LDAPS, etc.)
timeoutMsintegerNo10000Connection timeout in milliseconds

For api.example.com:443, you’ll get:

  • Certificate: “api.example.com” (RSA-2048, expires 2025-03-15)
  • Certificate: “DigiCert SHA2 Intermediate CA” (RSA-2048, CA)
  • Public Key: RSA-2048 public key (api.example.com)
  • Protocol: TLS 1.3 with TLS_AES_256_GCM_SHA384

Type: network-ssh
Category: Network
Access Mode: NETWORK
Produces: public-key, protocol

Connects to SSH servers and extracts host keys, key exchange algorithms, and encryption details from the SSH handshake. Does not authenticate — only performs the initial handshake.

  • SSH host keys (RSA, Ed25519, ECDSA)
  • Key exchange algorithms offered
  • Encryption algorithms (ciphers)
  • MAC algorithms
  • Host key fingerprints
endpoints:
- server1.example.com:22
- server2.example.com
- 10.0.1.100:2222
timeoutMs: 10000
FieldTypeRequiredDefaultDescription
endpointsstring listYes—Host:port entries. Port defaults to 22 if omitted
timeoutMsintegerNo10000Connection timeout in milliseconds

For server1.example.com:22:

  • Public Key: Ed25519 host key (server1.example.com)
  • Public Key: RSA-4096 host key (server1.example.com)
  • Public Key: ECDSA-256 host key (server1.example.com)
  • Protocol: SSH-2 with key exchange curve25519-sha256

  • Port flexibility — TLS scanner works on any port speaking TLS, not just 443. Use it for IMAPS (993), LDAPS (636), SMTPS (465), database TLS, etc.
  • Internal services — Deploy a sensor on the same network as internal services to scan endpoints not reachable from the internet.
  • Scan frequency — Use daily for production endpoints, weekly for stable infrastructure.
  • Timeout tuning — Increase timeoutMs for slow or geographically distant endpoints.