Docs

Documentation

From first probe to compliance report in four steps.

Getting Started

Step 1: Probe a domain

pqprobe scan example.com
example.com — Grade: C (score: 79)

  Protocol        TLS 1.3 ✓
  Key Exchange    X25519 (classical only)
  Cipher          AES-256-GCM ✓
  Certificate     ECDSA P-256, expires 2026-11-03

  Post-Quantum
    PQC key exchange    ✗ not negotiated
    Hybrid key exchange ✗ not negotiated

  CNSA 2.0
    2027 deadline       NOT READY
    2030 deadline       NOT READY
    2035 deadline       NOT READY

  Deductions
    Post-Quantum        No PQC support — max grade capped at C

  Trajectory: NEW (probe again to establish trend)

This is what most well-configured servers look like today. TLS 1.3, strong ciphers, valid certificate — and zero post-quantum protection. SSL Labs would give this an A. pqprobe gives it a C because PQC preparedness is what matters for the deadlines ahead.

Step 2: Analyze your code

pqprobe-static scan . --output sarif

Analyzes source code for cryptographic usage — hardcoded algorithms, weak key sizes, deprecated ciphers, insecure TLS config. 176 detection patterns across Go, Python, Java, C, C++, JavaScript, TypeScript, Rust, C#, Ruby, PHP, Zig, Swift and Kotlin, plus config files (nginx, Apache, YAML, JSON). Cryptographic libraries are detected by name, 21 of them, and an import is reported as a library component distinct from an algorithm asset.

SARIF output uploads directly to GitHub or GitLab Security tabs. No new dashboard — findings appear alongside your existing code scanning results.

# GitHub Actions
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: pqprobe-results.sarif

# GitLab CI
artifacts:
  reports:
    sast: pqprobe-results.sarif

Step 3: Check your dependencies

pqprobe dep-audit .
go.mod — 3 crypto dependencies

  crypto/tls (stdlib)     PQC: ✓ since Go 1.24    Current: Go 1.22 ⚠ upgrade
  golang.org/x/crypto     PQC: ✓ since v0.31.0    Current: v0.28.0 ⚠ upgrade
  github.com/lib/pq       PQC: inherits stdlib     No action needed

Summary: 2 dependencies need version bumps for PQC support

Covers go.mod, package.json, requirements.txt, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, and .csproj. Reports which libraries use cryptography, whether they support PQC, and the minimum version to upgrade to.

Step 4: Track your trajectory

Probe the same targets over time. pqprobe compares results and assigns a migration trajectory:

  • IMPROVING — you enabled PQC key exchange, upgraded a library, rotated to a stronger cert. The gap between your posture and the deadline is closing.
  • STABLE — nothing changed. The deadline is closer but you haven't moved.
  • DEGRADING — a new service appeared without PQC, something regressed, a cert downgraded. The gap is growing.
pqprobe analyze example.com --days 90

Most organizations right now are STABLE. That's the finding — you haven't started, and the deadline hasn't stopped.

Add --project to extrapolate your trajectory against actual compliance deadlines:

pqprobe analyze example.com --project

For each CNSA 2.0 milestone (2027, 2030, 2035) and other frameworks with deadlines, you get: on track, at risk, stalled, or regressing — with projected completion date. Requires 3+ scans.

Export

pqprobe export-cbom output.json          # CycloneDX Cryptographic Bill of Materials
pqprobe export --output inventory.csv     # Full inventory for CMDB/SIEM
pqprobe report example.com               # Detailed report for a single target

Grades

pqprobe grades measure post-quantum preparedness, not just classical TLS hygiene. A perfect classical configuration without PQC caps at grade C.

GradeScoreMeaning
A90–100PQC deployed (hybrid or pure). Clean classical config. On track for CNSA 2.0.
B80–89PQC deployed with some classical issues to resolve.
C70–79Good classical config, zero PQC. Most competent servers today. SSL Labs says A. We say: start migrating.
D50–69No PQC plus classical problems — CBC ciphers, legacy protocols, certificate issues.
F0–49Multiple serious issues or fatal conditions (SSL 3.0, RC4, expired certs). Fix the foundation before thinking about PQC.

Every probe shows the deductions that produced your grade. No black boxes.

Deductions

Scores start at 100. Each issue found subtracts points. A criticality multiplier (LOW 1.0x, MEDIUM 1.1x, HIGH 1.2x) scales deductions based on data sensitivity.

CategoryConditionBase Points
CertificateExpired-50
CertificateSHA-1 signature-30
Key ExchangeRSA key exchange (no forward secrecy)-25
CertificateRSA < 2048 bits-25
Key ExchangeDHE < 2048 bits-20
CertificateSelf-signed-20
CipherCBC mode ciphers-15
ProtocolNo TLS 1.3 (1.2 only)-8
CertificateValidity > 398 days-5

PQC Cap

After deductions, a cap is applied based on PQC preparedness:

PQC StatusMax ScoreBest Possible Grade
No PQC79C
Hybrid PQC (classical + PQC)95A
Pure PQC100A

Fatal Conditions

These set the score to 0 (grade F) immediately:

  • SSL 2.0 or SSL 3.0 detected
  • TLS 1.0 or TLS 1.1 detected (deprecated by RFC 8996, PCI DSS 4.0, BSI TR-02102)
  • DES/3DES cipher (non-ECDHE)
  • RC4 cipher
  • EXPORT cipher
  • MD5 certificate signature

CLI Reference

Code Analysis

Analyze source code for cryptographic usage with pqprobe-static.

pqprobe-static scan . Scan current directory for crypto usage
pqprobe-static scan . --output json JSON output for automation
pqprobe-static scan . --output sarif SARIF output for GitHub/GitLab Code Scanning
pqprobe-static scan . --output cbom CycloneDX 1.6 Cryptographic Bill of Materials

Output formats: SARIF, JSON, text, CycloneDX 1.6 CBOM. The CBOM is emitted natively by the binary, so it works in CI pipelines and benchmark harnesses with no server. Identical sources produce byte-identical output apart from the timestamp, with stable bom-refs and a content-derived serial number, so a committed CBOM diffs cleanly. Findings with no CycloneDX representation are counted in metadata.properties and reported on stderr rather than dropped.

176 detection patterns across Go, Python, Java, C, C++, JavaScript, TypeScript, Rust, C#, Ruby, PHP, Zig, Swift and Kotlin. Cryptographic libraries are detected by name, 21 of them, and an import is reported as a library component distinct from an algorithm asset. Detects insecure random, deprecated algorithms (MD5, SHA-1, DES, RC4, Blowfish), weak KDFs, hardcoded IVs/nonces, insecure TLS config, weak key sizes, and certificate pinning. Also scans config files (nginx, Apache, YAML, JSON), and parses X.509 certificates in PEM and DER form for subject, issuer, validity, signature algorithm and key size.

Languages and libraries

176 detection patterns across 17 source extensions, plus configuration, certificate, keystore and documentation formats. Selection is by extension: a file whose extension is not listed is never opened.

LanguageExtensionsWhat is read
C.cOpenSSL, libsodium and liboqs call sites, named curves and algorithm string literals
C#.csSystem.Security.Cryptography call sites and NuGet dependencies
C++.cc, .cppas C, plus C++ wrappers around the same libraries
C++ header.hppdeclarations and macro-defined algorithm selections
C/C++ header.hdeclarations and macro-defined algorithm selections
Go.gocall sites, imports, struct tags and go.mod/go.sum dependencies
Java.javaJCA/JCE call sites, provider strings, keystore loads and Maven/Gradle dependencies
JavaScript.jsWebCrypto, Node crypto, and package.json dependencies
Kotlin.ktJCA/JCE call sites, as Java
PHP.phpOpenSSL and sodium bindings, and composer.json dependencies
Python.pycall sites, imports and requirements.txt/pyproject.toml dependencies
Ruby.rbOpenSSL bindings and Gemfile dependencies
Rust.rsRustCrypto and ring call sites, and Cargo.toml dependencies
Swift.swiftCryptoKit and CommonCrypto call sites
TypeScript.tsas JavaScript. .tsx and .jsx are not read
Zig.zigstd.crypto call sites

Configuration: .cfg, .cnf, .conf, .config, .ini, .options, .properties, .toml, .yaml, .yml. Certificates and keys: .cer, .crt, .der, .key, .pem. Keystore containers: .bcfks, .jks, .keystore, .ks, .p12, .pfx, .truststore. Documentation and structured data: .json, .jsonc, .md. Dependency manifests are matched by filename rather than extension, for Go, npm, PyPI, Cargo, RubyGems, Maven/Gradle, Conan, Composer and NuGet.

21 cryptographic libraries are recognised by name. An import is reported as a library component, distinct from an algorithm asset: it is evidence the library is present, not that any particular algorithm is called.

LibraryProvides
@noble/cipherssymmetric
@noble/hashessymmetric
@noble/post-quantumpost-quantum
@noble/secp256k1classical
AWS-LCgeneral
Apple CryptoKitgeneral
Botangeneral
Bouncy Castle PQCpost-quantum
CIRCLgeneral
Cisco hash-sigspost-quantum
Go crypto/mlkempost-quantum
Google Tinkgeneral
PQClean/pqm4 KEM APIpost-quantum
RustCryptogeneral
Zig std.cryptogeneral
libcruxpost-quantum
liboqspost-quantum
oriongeneral
pqm4post-quantum
s2n-tls pq-cryptopost-quantum
wolfSSLgeneral

Frameworks are not modelled as a category. A framework is read through the files it is written in and the dependencies it declares, so a Spring or Django project is covered to the extent its language and manifests are, and no further.

Dependency Audit

Audit dependency manifests for crypto library usage and PQC preparedness.

pqprobe dep-audit . Audit current project for crypto dependencies
pqprobe dep-audit /path/to/project Audit a specific project directory
pqprobe dep-audit . --output json JSON output for automation

Parses go.mod, package.json, requirements.txt, Pipfile, pyproject.toml, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, and *.csproj. Reports algorithms used, PQC preparedness, and minimum versions needed for PQC support across 8 ecosystems.

MDE Import

Import Microsoft Defender for Endpoint Advanced Hunting exports and map software inventory to PQC preparedness assessments. Zero-deployment crypto library census across large fleets.

pqprobe import mde --source export.csv Import a single CSV export
pqprobe import mde --source ./mde-exports/ Import a directory of exports
pqprobe import mde --source export.csv --dry-run Preview without database writes
pqprobe import mde --source export.csv --output json JSON output for automation
pqprobe import mde --source export.csv --crypto-map custom.json Use custom crypto mapping file

Supports DeviceTvmSoftwareInventory and DeviceFileCertificateInfo table exports (CSV and JSON). Deduplicates by (device, software, version). Maps 15 crypto libraries (OpenSSL, GnuTLS, NSS, LibreSSL, BouncyCastle, wolfSSL, libssh, libssh2, .NET, Java/OpenJDK, Go, rustls, AWS-LC, BoringSSL, mbedTLS) to PQC capability assessments with version-range matching. Each device becomes a scan result with the same A–F scoring, trajectory tracking, and compliance export as active probes. Unrecognized software is tagged as “unknown” for inventory visibility. The --crypto-map flag accepts a custom JSON mapping file to extend coverage without recompiling.

KQL Query

Export from MDE Advanced Hunting:

DeviceTvmSoftwareInventory
| project DeviceId, DeviceName, SoftwareName, SoftwareVersion, SoftwareVendor, OSPlatform, OSVersion

Local Discovery

Find cryptographic artifacts on local filesystems.

pqprobe scan-local Scan default paths for crypto files
sudo pqprobe scan-local --system Scan system paths (requires root)
pqprobe scan-local /etc/ssl ~/.ssh Scan specific directories
pqprobe scan-local --sensitivity 2 Critical data sensitivity (affects scoring)
pqprobe scan-local --output json JSON output for automation

Finds certificates (.pem, .crt, .cer, .der, .p12, .pfx), private keys, Java keystores, SSH keys, GPG keyrings, and crypto config files. Works on Linux, macOS, and Windows.

Protocol Probing

Probe individual hosts for cryptographic configuration across multiple protocols.

Web & TLS

pqprobe scan example.com TLS/HTTPS - versions, ciphers, certificates, PQC detection

Remote Access

pqprobe scan-ssh server.example.com SSH - key exchange, host keys, ciphers, MACs
pqprobe scan-rdp server.example.com RDP - TLS, NLA, CredSSP, security protocol

Email

pqprobe scan-smtp mail.example.com SMTP - STARTTLS, TLS config, certificates
pqprobe scan-imap imap.example.com IMAP - STARTTLS, implicit TLS (993)
pqprobe scan-pop3 mail.example.com POP3 - STLS, POP3S (995)

Directory & Authentication

pqprobe scan-ldap ldap.example.com LDAP - STARTTLS, LDAPS (636)
pqprobe scan-smb fileserver.example.com SMB/NTLM - NTLMv1/v2, signing, encryption, ESS

Databases

pqprobe scan-mysql db.example.com MySQL - SSL/TLS capability, auth plugins, ciphers
pqprobe scan-postgres db.example.com PostgreSQL - SSL mode, TLS version, ciphers
pqprobe scan-mongodb mongo.example.com MongoDB - TLS mode, server version, auth
pqprobe scan-redis redis.example.com Redis - TLS (Redis 6+), version, auth
pqprobe scan-cassandra cassandra.example.com Cassandra - CQL TLS (9142), version, auth

Message Queues

pqprobe scan-kafka kafka.example.com Kafka - SSL/SASL_SSL (9093/9094), API versions
pqprobe scan-amqp rabbitmq.example.com RabbitMQ/AMQP - AMQPS (5671), protocol version
pqprobe scan-xmpp xmpp.example.com XMPP - STARTTLS, implicit TLS (5223), SASL

Healthcare

pqprobe scan-fhir fhir.hospital.org FHIR - R4/R5, SMART on FHIR, TLS, HIPAA
pqprobe scan-hl7 hl7.hospital.org HL7/MLLP - HL7v2, secure MLLP, PHI protection
pqprobe scan-dicom pacs.hospital.org DICOM - Medical imaging, DICOM-TLS, AE titles

File Transfer

pqprobe scan-ftp ftp.example.com FTP - AUTH TLS, FTPS (990), explicit/implicit

Passive Analysis

Analyze captured network traffic across 13 protocols. No active connections to targets.

pqprobe passive analyze capture.pcap Analyze pcap/pcapng file — 13-protocol detection
pqprobe passive analyze capture.pcap --sensitivity 2 PHI-level sensitivity for healthcare captures
pqprobe passive analyze capture.pcap --output json JSON output for automation
pqprobe passive analyze capture.pcap --verbose Detailed output with per-connection info

Reads pcap and pcapng files from SPAN ports, network taps, or tcpdump. Detects 13 protocols: TLS (ClientHello/ServerHello, cipher suites, certificates, PQC indicators), SSH (version strings, key exchange algorithms), SMTP/IMAP/POP3/FTP STARTTLS upgrades, PostgreSQL SSL and MySQL SSL negotiation, RDP security protocol detection (TLS, CredSSP, NLA), LDAP STARTTLS, XMPP STARTTLS, HL7v2 MLLP (message type, facility — CRITICAL finding for unencrypted medical data), and DICOM (AE Titles, Implementation UID — CRITICAL finding for unencrypted imaging data). Scores each observed host using the same A–F grading as active probes. Results feed into trajectory tracking, change detection, and compliance exports. TLS 1.3 certificates are encrypted and not available in passive mode — scoring uses cipher suite and key exchange data.

Network Discovery

Discover cryptographic services across entire networks.

pqprobe discover --cidr 10.0.0.0/24 Discover all crypto services in a subnet
pqprobe discover --cidr 10.0.0.0/24 --concurrency 50 Parallel probing with 50 concurrent connections

Automatically detects 35 service types on 66 ports, including TLS, SSH, SMTP, IMAP, databases, message queues, healthcare protocols, and more.

Endpoint Auditing

Audit local machine cryptographic configuration.

Windows

pqprobe audit-windows Audit Windows NTLM and crypto configuration
pqprobe audit-windows --output json JSON output for automation

Checks LmCompatibilityLevel registry settings, NTLMv1/v2 policy, NTLM authentication events, and security configuration. Must be run locally on the Windows host.

Analysis

Analyze cryptographic posture and track changes over time.

pqprobe analyze example.com --days 90 Analyze crypto trends over the last 90 days
pqprobe priorities --tier EMERGENCY Show highest-priority migration targets
pqprobe efficiency example.com Analyze cryptographic efficiency
pqprobe history example.com View probe history for a target

Inventory

Manage your cryptographic asset inventory.

pqprobe certificates --expiring 30 List certificates expiring within 30 days
pqprobe software List detected software and versions
pqprobe targets List all probe targets
pqprobe stats Show inventory statistics

Export & Integration

Export data and integrate with existing tools.

Compliance Assessment

pqprobe compliance --list-profiles List available compliance profiles (CNSA, PCI, NIS2, BSI, FIPS, HIPAA, DORA, CISA)
pqprobe compliance --profile cnsa2 --scan-id latest Run CNSA 2.0 compliance assessment
pqprobe compliance --profile pci-dss-4 --scan-id latest -o json Compliance assessment with JSON output

Export Formats

pqprobe export --output inventory.csv Export full inventory to CSV
pqprobe export-certificates Export certificate inventory
pqprobe export-cbom output.json Export CycloneDX Cryptographic Bill of Materials
pqprobe report example.com Generate detailed report for a target
pqprobe scan example.com -o json JSON output for automation

Jira Integration

pqprobe jira test Test Jira connection and validate project
pqprobe jira export --scan-id latest Export findings to Jira as trackable issues
pqprobe jira export --scan-id latest --project KEY Export with explicit project key override

Requires PQPROBE_JIRA_URL, PQPROBE_JIRA_EMAIL, PQPROBE_JIRA_API_TOKEN, PQPROBE_JIRA_PROJECT environment variables. Re-scans automatically sync ticket status (close on resolution, reopen on regression).

Tool Integration

pqprobe import mde --source export.csv Import MDE software inventory for PQC assessment
pqprobe analyze-nmap scan.xml Import and analyze nmap results
pqprobe --db inventory.db scan ... Use SQLite for persistent storage
pqprobe --db postgres://... scan ... Use PostgreSQL for persistent storage

Deployment

PQProbe deploys as a single binary with zero external dependencies. No data leaves your network — the only outbound connections are to the targets you probe.

Install

The tarball contains:

  • bin/pqprobe-server — API server and web dashboard
  • bin/pqprobe — CLI probing tool
  • bin/pqprobe-static — Static code analyzer
  • etc/pqprobe.env.example — Configuration template
  • etc/pqprobe.service — systemd unit file
  • INSTALL.md — Step-by-step deployment guide
# Extract
tar xzf pqprobe-*-linux-amd64.tar.gz
cd pqprobe-*/

# Create system user and directories
sudo useradd -r -s /bin/false pqprobe
sudo mkdir -p /opt/pqprobe/bin /opt/pqprobe/data
sudo cp bin/* /opt/pqprobe/bin/
sudo cp etc/pqprobe.env.example /opt/pqprobe/pqprobe.env
sudo chown -R pqprobe:pqprobe /opt/pqprobe

# Install systemd service
sudo cp etc/pqprobe.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now pqprobe

# Verify
curl http://localhost:8080/api/v1/health

Docker

# Build and run with Docker Compose
docker-compose up -d

# Or build individual images
docker build -f deployments/docker/Dockerfile.server -t pqprobe-server .
docker build -f deployments/docker/Dockerfile.cli -t pqprobe-cli .
docker build -f deployments/docker/Dockerfile.static -t pqprobe-static .

Authentication

By default, the dashboard and API are open. To require authentication for all non-public routes:

# In /opt/pqprobe/pqprobe.env
PQPROBE_REQUIRE_AUTH=true
PQPROBE_JWT_SECRET=your-secret-here  # for persistent sessions

When auth is required and no API keys exist, the server prints a bootstrap admin API key on first startup. Create additional keys with:

sudo -u pqprobe /opt/pqprobe/bin/pqprobe-server \
  -db /opt/pqprobe/data/pqprobe.db create-key

Use the API key with any request:

curl http://localhost:8080/api/v1/scans -H "X-API-Key: pqp_your_key_here"

GitHub OAuth (optional)

For browser-based login, create a GitHub OAuth App and set:

PQPROBE_GITHUB_CLIENT_ID=your-client-id
PQPROBE_GITHUB_CLIENT_SECRET=your-client-secret
PQPROBE_GITHUB_CALLBACK_URL=https://your-domain/api/v1/auth/github/callback

Configuration Reference

Environment VariableFlagDefaultDescription
PQPROBE_REQUIRE_AUTH--require-authfalseRequire JWT or API key for non-public routes
PQPROBE_JWT_SECRET--jwt-secretephemeralSecret for signing JWT tokens
PQPROBE_GITHUB_CLIENT_ID--github-client-idGitHub OAuth App client ID
PQPROBE_GITHUB_CLIENT_SECRET--github-client-secretGitHub OAuth App client secret
PQPROBE_GITHUB_CALLBACK_URL--github-callback-urlautoOAuth callback URL
PQPROBE_AUTO_SCAN_TARGETS--auto-scan-targetsPath to JSON file with probe targets
PQPROBE_AUTO_SCAN_INTERVAL--auto-scan-interval24Hours between automated probe cycles
PQPROBE_SITE--siteselfhostedNav variant: selfhosted shows Probes, Dashboard and Docs; public is the pqprobe.com site nav
PQPROBE_JIRA_URLJira instance URL (e.g. https://company.atlassian.net)
PQPROBE_JIRA_EMAILJira account email for API auth
PQPROBE_JIRA_API_TOKENJira API token
PQPROBE_JIRA_PROJECT--projectDefault Jira project key for issue export
--port8080Server port
--dbpqprobe.dbDatabase path
--workers16Background worker count
--queue-size5000Maximum queued probes
--rate-limit60Max requests per IP per window
--rate-window60Rate limit window (seconds)
--secure-cookiesfalseSet Secure flag on cookies (use behind HTTPS)