TLS Probe
Probe a single TLS endpoint - handshake inspection of protocol version, cipher suite, key exchange, and certificate chain
Packet Capture
Offline analysis of a captured .pcap / .pcapng file to extract TLS handshakes and detect classical vs post-quantum key exchange
Source Code
Static analysis of a local source path for cryptographic usage - algorithms, key sizes, and vulnerable function calls, with SARIF output in CI mode
SSH Keys
Discover SSH keys from ssh-agent, ~/.ssh, and /etc/ssh and assess their algorithms for quantum vulnerability
Vault
Inventory keys held in a vault registered in the Cockpit (Securosys HSM, AWS KMS, Azure Key Vault) and assess their algorithms
Cloud (legacy)
Placeholder inventory of cloud KMS keys (AWS KMS / Azure Key Vault / GCP Cloud KMS) - legacy source, use Vault instead
JFrog Artifactory
Scan a JFrog Artifactory instance for cryptographic material, with an optional JFrog Xray PQC-readiness scan of artifacts
Terraform IaC
Analyze Terraform HCL and state files for cryptographic configuration - keys, certificates, and algorithms in infrastructure-as-code
Fortinet
Scan FortiGate / FortiOS appliances via REST API for certificates, VPN configuration, and SSL profiles, and assess quantum readiness
Agent
The persistent agent daemon that connects a host to DuoKey Cockpit, and the one-shot host inventory scan for local cryptographic discovery
Domain
TLS handshake analysis with full certificate chain extraction, cipher suite detection, and optional PQ key exchange detection
Filesystem
Recursive discovery of certificates, keystores, and private keys across directories and OS certificate stores
Network
Live capture from a network interface for quantum-vulnerable TLS and SSH handshakes (requires the pcap-live build feature)