From first probe to compliance report in four steps.
pqprobe scan example.com
example.com — Grade: C (score: 79)
Protocol TLS 1.3 ✓
Key Exchange X25519 (classical only)
Cipher AES-256-GCM ✓
Certificate ECDSA P-256, expires 2026-11-03
Post-Quantum
PQC key exchange ✗ not negotiated
Hybrid key exchange ✗ not negotiated
CNSA 2.0
2027 deadline NOT READY
2030 deadline NOT READY
2035 deadline NOT READY
Deductions
Post-Quantum No PQC support — max grade capped at C
Trajectory: NEW (probe again to establish trend)
This is what most well-configured servers look like today. TLS 1.3, strong ciphers, valid certificate — and zero post-quantum protection. SSL Labs would give this an A. pqprobe gives it a C because PQC preparedness is what matters for the deadlines ahead.
pqprobe-static scan . --output sarif
Analyzes source code for cryptographic usage — hardcoded algorithms, weak key sizes, deprecated ciphers, insecure TLS config. 176 detection patterns across Go, Python, Java, C, C++, JavaScript, TypeScript, Rust, C#, Ruby, PHP, Zig, Swift and Kotlin, plus config files (nginx, Apache, YAML, JSON). Cryptographic libraries are detected by name, 21 of them, and an import is reported as a library component distinct from an algorithm asset.
SARIF output uploads directly to GitHub or GitLab Security tabs. No new dashboard — findings appear alongside your existing code scanning results.
# GitHub Actions
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: pqprobe-results.sarif
# GitLab CI
artifacts:
reports:
sast: pqprobe-results.sarif
pqprobe dep-audit .
go.mod — 3 crypto dependencies
crypto/tls (stdlib) PQC: ✓ since Go 1.24 Current: Go 1.22 ⚠ upgrade
golang.org/x/crypto PQC: ✓ since v0.31.0 Current: v0.28.0 ⚠ upgrade
github.com/lib/pq PQC: inherits stdlib No action needed
Summary: 2 dependencies need version bumps for PQC support
Covers go.mod, package.json, requirements.txt, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, and .csproj. Reports which libraries use cryptography, whether they support PQC, and the minimum version to upgrade to.
Probe the same targets over time. pqprobe compares results and assigns a migration trajectory:
pqprobe analyze example.com --days 90
Most organizations right now are STABLE. That's the finding — you haven't started, and the deadline hasn't stopped.
Add --project to extrapolate your trajectory against actual compliance deadlines:
pqprobe analyze example.com --project
For each CNSA 2.0 milestone (2027, 2030, 2035) and other frameworks with deadlines, you get: on track, at risk, stalled, or regressing — with projected completion date. Requires 3+ scans.
pqprobe export-cbom output.json # CycloneDX Cryptographic Bill of Materials
pqprobe export --output inventory.csv # Full inventory for CMDB/SIEM
pqprobe report example.com # Detailed report for a single target
pqprobe grades measure post-quantum preparedness, not just classical TLS hygiene. A perfect classical configuration without PQC caps at grade C.
| Grade | Score | Meaning |
|---|---|---|
| A | 90–100 | PQC deployed (hybrid or pure). Clean classical config. On track for CNSA 2.0. |
| B | 80–89 | PQC deployed with some classical issues to resolve. |
| C | 70–79 | Good classical config, zero PQC. Most competent servers today. SSL Labs says A. We say: start migrating. |
| D | 50–69 | No PQC plus classical problems — CBC ciphers, legacy protocols, certificate issues. |
| F | 0–49 | Multiple serious issues or fatal conditions (SSL 3.0, RC4, expired certs). Fix the foundation before thinking about PQC. |
Every probe shows the deductions that produced your grade. No black boxes.
Scores start at 100. Each issue found subtracts points. A criticality multiplier (LOW 1.0x, MEDIUM 1.1x, HIGH 1.2x) scales deductions based on data sensitivity.
| Category | Condition | Base Points |
|---|---|---|
| Certificate | Expired | -50 |
| Certificate | SHA-1 signature | -30 |
| Key Exchange | RSA key exchange (no forward secrecy) | -25 |
| Certificate | RSA < 2048 bits | -25 |
| Key Exchange | DHE < 2048 bits | -20 |
| Certificate | Self-signed | -20 |
| Cipher | CBC mode ciphers | -15 |
| Protocol | No TLS 1.3 (1.2 only) | -8 |
| Certificate | Validity > 398 days | -5 |
After deductions, a cap is applied based on PQC preparedness:
| PQC Status | Max Score | Best Possible Grade |
|---|---|---|
| No PQC | 79 | C |
| Hybrid PQC (classical + PQC) | 95 | A |
| Pure PQC | 100 | A |
These set the score to 0 (grade F) immediately:
Analyze source code for cryptographic usage with pqprobe-static.
pqprobe-static scan .
Scan current directory for crypto usage
pqprobe-static scan . --output json
JSON output for automation
pqprobe-static scan . --output sarif
SARIF output for GitHub/GitLab Code Scanning
pqprobe-static scan . --output cbom
CycloneDX 1.6 Cryptographic Bill of Materials
Output formats: SARIF, JSON, text, CycloneDX 1.6 CBOM. The CBOM is emitted natively by the binary, so it works in CI pipelines and benchmark harnesses with no server. Identical sources produce byte-identical output apart from the timestamp, with stable bom-refs and a content-derived serial number, so a committed CBOM diffs cleanly. Findings with no CycloneDX representation are counted in metadata.properties and reported on stderr rather than dropped.
176 detection patterns across Go, Python, Java, C, C++, JavaScript, TypeScript, Rust, C#, Ruby, PHP, Zig, Swift and Kotlin. Cryptographic libraries are detected by name, 21 of them, and an import is reported as a library component distinct from an algorithm asset. Detects insecure random, deprecated algorithms (MD5, SHA-1, DES, RC4, Blowfish), weak KDFs, hardcoded IVs/nonces, insecure TLS config, weak key sizes, and certificate pinning. Also scans config files (nginx, Apache, YAML, JSON), and parses X.509 certificates in PEM and DER form for subject, issuer, validity, signature algorithm and key size.
176 detection patterns across 17 source extensions, plus configuration, certificate, keystore and documentation formats. Selection is by extension: a file whose extension is not listed is never opened.
| Language | Extensions | What is read |
|---|---|---|
| C | .c | OpenSSL, libsodium and liboqs call sites, named curves and algorithm string literals |
| C# | .cs | System.Security.Cryptography call sites and NuGet dependencies |
| C++ | .cc, .cpp | as C, plus C++ wrappers around the same libraries |
| C++ header | .hpp | declarations and macro-defined algorithm selections |
| C/C++ header | .h | declarations and macro-defined algorithm selections |
| Go | .go | call sites, imports, struct tags and go.mod/go.sum dependencies |
| Java | .java | JCA/JCE call sites, provider strings, keystore loads and Maven/Gradle dependencies |
| JavaScript | .js | WebCrypto, Node crypto, and package.json dependencies |
| Kotlin | .kt | JCA/JCE call sites, as Java |
| PHP | .php | OpenSSL and sodium bindings, and composer.json dependencies |
| Python | .py | call sites, imports and requirements.txt/pyproject.toml dependencies |
| Ruby | .rb | OpenSSL bindings and Gemfile dependencies |
| Rust | .rs | RustCrypto and ring call sites, and Cargo.toml dependencies |
| Swift | .swift | CryptoKit and CommonCrypto call sites |
| TypeScript | .ts | as JavaScript. .tsx and .jsx are not read |
| Zig | .zig | std.crypto call sites |
Configuration: .cfg, .cnf, .conf, .config, .ini, .options, .properties, .toml, .yaml, .yml. Certificates and keys:
.cer, .crt, .der, .key, .pem. Keystore containers: .bcfks, .jks, .keystore, .ks, .p12, .pfx, .truststore. Documentation and
structured data: .json, .jsonc, .md. Dependency manifests are matched by
filename rather than extension, for Go, npm, PyPI, Cargo, RubyGems, Maven/Gradle, Conan, Composer and NuGet.
21 cryptographic libraries are recognised by name. An import is reported as a library component, distinct from an algorithm asset: it is evidence the library is present, not that any particular algorithm is called.
| Library | Provides |
|---|---|
@noble/ciphers | symmetric |
@noble/hashes | symmetric |
@noble/post-quantum | post-quantum |
@noble/secp256k1 | classical |
AWS-LC | general |
Apple CryptoKit | general |
Botan | general |
Bouncy Castle PQC | post-quantum |
CIRCL | general |
Cisco hash-sigs | post-quantum |
Go crypto/mlkem | post-quantum |
Google Tink | general |
PQClean/pqm4 KEM API | post-quantum |
RustCrypto | general |
Zig std.crypto | general |
libcrux | post-quantum |
liboqs | post-quantum |
orion | general |
pqm4 | post-quantum |
s2n-tls pq-crypto | post-quantum |
wolfSSL | general |
Frameworks are not modelled as a category. A framework is read through the files it is written in and the dependencies it declares, so a Spring or Django project is covered to the extent its language and manifests are, and no further.
Audit dependency manifests for crypto library usage and PQC preparedness.
pqprobe dep-audit .
Audit current project for crypto dependencies
pqprobe dep-audit /path/to/project
Audit a specific project directory
pqprobe dep-audit . --output json
JSON output for automation
Parses go.mod, package.json, requirements.txt, Pipfile, pyproject.toml, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, and *.csproj. Reports algorithms used, PQC preparedness, and minimum versions needed for PQC support across 8 ecosystems.
Import Microsoft Defender for Endpoint Advanced Hunting exports and map software inventory to PQC preparedness assessments. Zero-deployment crypto library census across large fleets.
pqprobe import mde --source export.csv
Import a single CSV export
pqprobe import mde --source ./mde-exports/
Import a directory of exports
pqprobe import mde --source export.csv --dry-run
Preview without database writes
pqprobe import mde --source export.csv --output json
JSON output for automation
pqprobe import mde --source export.csv --crypto-map custom.json
Use custom crypto mapping file
Supports DeviceTvmSoftwareInventory and DeviceFileCertificateInfo table exports (CSV and JSON). Deduplicates by (device, software, version). Maps 15 crypto libraries (OpenSSL, GnuTLS, NSS, LibreSSL, BouncyCastle, wolfSSL, libssh, libssh2, .NET, Java/OpenJDK, Go, rustls, AWS-LC, BoringSSL, mbedTLS) to PQC capability assessments with version-range matching. Each device becomes a scan result with the same A–F scoring, trajectory tracking, and compliance export as active probes. Unrecognized software is tagged as “unknown” for inventory visibility. The --crypto-map flag accepts a custom JSON mapping file to extend coverage without recompiling.
Export from MDE Advanced Hunting:
DeviceTvmSoftwareInventory
| project DeviceId, DeviceName, SoftwareName, SoftwareVersion, SoftwareVendor, OSPlatform, OSVersion
Find cryptographic artifacts on local filesystems.
pqprobe scan-local
Scan default paths for crypto files
sudo pqprobe scan-local --system
Scan system paths (requires root)
pqprobe scan-local /etc/ssl ~/.ssh
Scan specific directories
pqprobe scan-local --sensitivity 2
Critical data sensitivity (affects scoring)
pqprobe scan-local --output json
JSON output for automation
Finds certificates (.pem, .crt, .cer, .der, .p12, .pfx), private keys, Java keystores, SSH keys, GPG keyrings, and crypto config files. Works on Linux, macOS, and Windows.
Probe individual hosts for cryptographic configuration across multiple protocols.
pqprobe scan example.com
TLS/HTTPS - versions, ciphers, certificates, PQC detection
pqprobe scan-ssh server.example.com
SSH - key exchange, host keys, ciphers, MACs
pqprobe scan-rdp server.example.com
RDP - TLS, NLA, CredSSP, security protocol
pqprobe scan-smtp mail.example.com
SMTP - STARTTLS, TLS config, certificates
pqprobe scan-imap imap.example.com
IMAP - STARTTLS, implicit TLS (993)
pqprobe scan-pop3 mail.example.com
POP3 - STLS, POP3S (995)
pqprobe scan-ldap ldap.example.com
LDAP - STARTTLS, LDAPS (636)
pqprobe scan-smb fileserver.example.com
SMB/NTLM - NTLMv1/v2, signing, encryption, ESS
pqprobe scan-mysql db.example.com
MySQL - SSL/TLS capability, auth plugins, ciphers
pqprobe scan-postgres db.example.com
PostgreSQL - SSL mode, TLS version, ciphers
pqprobe scan-mongodb mongo.example.com
MongoDB - TLS mode, server version, auth
pqprobe scan-redis redis.example.com
Redis - TLS (Redis 6+), version, auth
pqprobe scan-cassandra cassandra.example.com
Cassandra - CQL TLS (9142), version, auth
pqprobe scan-kafka kafka.example.com
Kafka - SSL/SASL_SSL (9093/9094), API versions
pqprobe scan-amqp rabbitmq.example.com
RabbitMQ/AMQP - AMQPS (5671), protocol version
pqprobe scan-xmpp xmpp.example.com
XMPP - STARTTLS, implicit TLS (5223), SASL
pqprobe scan-fhir fhir.hospital.org
FHIR - R4/R5, SMART on FHIR, TLS, HIPAA
pqprobe scan-hl7 hl7.hospital.org
HL7/MLLP - HL7v2, secure MLLP, PHI protection
pqprobe scan-dicom pacs.hospital.org
DICOM - Medical imaging, DICOM-TLS, AE titles
pqprobe scan-ftp ftp.example.com
FTP - AUTH TLS, FTPS (990), explicit/implicit
Analyze captured network traffic across 13 protocols. No active connections to targets.
pqprobe passive analyze capture.pcap
Analyze pcap/pcapng file — 13-protocol detection
pqprobe passive analyze capture.pcap --sensitivity 2
PHI-level sensitivity for healthcare captures
pqprobe passive analyze capture.pcap --output json
JSON output for automation
pqprobe passive analyze capture.pcap --verbose
Detailed output with per-connection info
Reads pcap and pcapng files from SPAN ports, network taps, or tcpdump. Detects 13 protocols: TLS (ClientHello/ServerHello, cipher suites, certificates, PQC indicators), SSH (version strings, key exchange algorithms), SMTP/IMAP/POP3/FTP STARTTLS upgrades, PostgreSQL SSL and MySQL SSL negotiation, RDP security protocol detection (TLS, CredSSP, NLA), LDAP STARTTLS, XMPP STARTTLS, HL7v2 MLLP (message type, facility — CRITICAL finding for unencrypted medical data), and DICOM (AE Titles, Implementation UID — CRITICAL finding for unencrypted imaging data). Scores each observed host using the same A–F grading as active probes. Results feed into trajectory tracking, change detection, and compliance exports. TLS 1.3 certificates are encrypted and not available in passive mode — scoring uses cipher suite and key exchange data.
Discover cryptographic services across entire networks.
pqprobe discover --cidr 10.0.0.0/24
Discover all crypto services in a subnet
pqprobe discover --cidr 10.0.0.0/24 --concurrency 50
Parallel probing with 50 concurrent connections
Automatically detects 35 service types on 66 ports, including TLS, SSH, SMTP, IMAP, databases, message queues, healthcare protocols, and more.
Audit local machine cryptographic configuration.
pqprobe audit-windows
Audit Windows NTLM and crypto configuration
pqprobe audit-windows --output json
JSON output for automation
Checks LmCompatibilityLevel registry settings, NTLMv1/v2 policy, NTLM authentication events, and security configuration. Must be run locally on the Windows host.
Analyze cryptographic posture and track changes over time.
pqprobe analyze example.com --days 90
Analyze crypto trends over the last 90 days
pqprobe priorities --tier EMERGENCY
Show highest-priority migration targets
pqprobe efficiency example.com
Analyze cryptographic efficiency
pqprobe history example.com
View probe history for a target
Manage your cryptographic asset inventory.
pqprobe certificates --expiring 30
List certificates expiring within 30 days
pqprobe software
List detected software and versions
pqprobe targets
List all probe targets
pqprobe stats
Show inventory statistics
Export data and integrate with existing tools.
pqprobe compliance --list-profiles
List available compliance profiles (CNSA, PCI, NIS2, BSI, FIPS, HIPAA, DORA, CISA)
pqprobe compliance --profile cnsa2 --scan-id latest
Run CNSA 2.0 compliance assessment
pqprobe compliance --profile pci-dss-4 --scan-id latest -o json
Compliance assessment with JSON output
pqprobe export --output inventory.csv
Export full inventory to CSV
pqprobe export-certificates
Export certificate inventory
pqprobe export-cbom output.json
Export CycloneDX Cryptographic Bill of Materials
pqprobe report example.com
Generate detailed report for a target
pqprobe scan example.com -o json
JSON output for automation
pqprobe jira test
Test Jira connection and validate project
pqprobe jira export --scan-id latest
Export findings to Jira as trackable issues
pqprobe jira export --scan-id latest --project KEY
Export with explicit project key override
Requires PQPROBE_JIRA_URL, PQPROBE_JIRA_EMAIL, PQPROBE_JIRA_API_TOKEN, PQPROBE_JIRA_PROJECT environment variables. Re-scans automatically sync ticket status (close on resolution, reopen on regression).
pqprobe import mde --source export.csv
Import MDE software inventory for PQC assessment
pqprobe analyze-nmap scan.xml
Import and analyze nmap results
pqprobe --db inventory.db scan ...
Use SQLite for persistent storage
pqprobe --db postgres://... scan ...
Use PostgreSQL for persistent storage
PQProbe deploys as a single binary with zero external dependencies. No data leaves your network — the only outbound connections are to the targets you probe.
The tarball contains:
bin/pqprobe-server — API server and web dashboardbin/pqprobe — CLI probing toolbin/pqprobe-static — Static code analyzeretc/pqprobe.env.example — Configuration templateetc/pqprobe.service — systemd unit fileINSTALL.md — Step-by-step deployment guide# Extract
tar xzf pqprobe-*-linux-amd64.tar.gz
cd pqprobe-*/
# Create system user and directories
sudo useradd -r -s /bin/false pqprobe
sudo mkdir -p /opt/pqprobe/bin /opt/pqprobe/data
sudo cp bin/* /opt/pqprobe/bin/
sudo cp etc/pqprobe.env.example /opt/pqprobe/pqprobe.env
sudo chown -R pqprobe:pqprobe /opt/pqprobe
# Install systemd service
sudo cp etc/pqprobe.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now pqprobe
# Verify
curl http://localhost:8080/api/v1/health
# Build and run with Docker Compose
docker-compose up -d
# Or build individual images
docker build -f deployments/docker/Dockerfile.server -t pqprobe-server .
docker build -f deployments/docker/Dockerfile.cli -t pqprobe-cli .
docker build -f deployments/docker/Dockerfile.static -t pqprobe-static .
By default, the dashboard and API are open. To require authentication for all non-public routes:
# In /opt/pqprobe/pqprobe.env
PQPROBE_REQUIRE_AUTH=true
PQPROBE_JWT_SECRET=your-secret-here # for persistent sessions
When auth is required and no API keys exist, the server prints a bootstrap admin API key on first startup. Create additional keys with:
sudo -u pqprobe /opt/pqprobe/bin/pqprobe-server \
-db /opt/pqprobe/data/pqprobe.db create-key
Use the API key with any request:
curl http://localhost:8080/api/v1/scans -H "X-API-Key: pqp_your_key_here"
For browser-based login, create a GitHub OAuth App and set:
PQPROBE_GITHUB_CLIENT_ID=your-client-id
PQPROBE_GITHUB_CLIENT_SECRET=your-client-secret
PQPROBE_GITHUB_CALLBACK_URL=https://your-domain/api/v1/auth/github/callback
| Environment Variable | Flag | Default | Description |
|---|---|---|---|
PQPROBE_REQUIRE_AUTH | --require-auth | false | Require JWT or API key for non-public routes |
PQPROBE_JWT_SECRET | --jwt-secret | ephemeral | Secret for signing JWT tokens |
PQPROBE_GITHUB_CLIENT_ID | --github-client-id | GitHub OAuth App client ID | |
PQPROBE_GITHUB_CLIENT_SECRET | --github-client-secret | GitHub OAuth App client secret | |
PQPROBE_GITHUB_CALLBACK_URL | --github-callback-url | auto | OAuth callback URL |
PQPROBE_AUTO_SCAN_TARGETS | --auto-scan-targets | Path to JSON file with probe targets | |
PQPROBE_AUTO_SCAN_INTERVAL | --auto-scan-interval | 24 | Hours between automated probe cycles |
PQPROBE_SITE | --site | selfhosted | Nav variant: selfhosted shows Probes, Dashboard and Docs; public is the pqprobe.com site nav |
PQPROBE_JIRA_URL | Jira instance URL (e.g. https://company.atlassian.net) | ||
PQPROBE_JIRA_EMAIL | Jira account email for API auth | ||
PQPROBE_JIRA_API_TOKEN | Jira API token | ||
PQPROBE_JIRA_PROJECT | --project | Default Jira project key for issue export | |
--port | 8080 | Server port | |
--db | pqprobe.db | Database path | |
--workers | 16 | Background worker count | |
--queue-size | 5000 | Maximum queued probes | |
--rate-limit | 60 | Max requests per IP per window | |
--rate-window | 60 | Rate limit window (seconds) | |
--secure-cookies | false | Set Secure flag on cookies (use behind HTTPS) |