Module Architecture
Module Architecture
A high-level view of the scanner's functional modules and what each is responsible for
Module overview
The scanner is organized into a small set of functional areas that form a clear pipeline — from the command line, through scanning and analysis, to formatted output.
| Module | Responsibility |
|---|---|
| Command-line interface | Parse arguments, validate input, load configuration, initialize logging, and dispatch to a scanning mode |
| Core analysis | Detect cryptographic algorithms and compute risk scores |
| Scanners | Implement the scanning modes (agent, filesystem, domain, network) |
| Parsers | Read the supported certificate, keystore, and configuration formats |
| Output | Render results as JSON, YAML, SARIF, or a terminal report |
| Utilities | Logging, error handling, and platform-specific helpers |
Core analysis
Identifies the cryptographic algorithm used by a certificate and assesses its quantum vulnerability. It determines the algorithm family and key size, then returns a quantum-risk value. Recognized categories include RSA, ECDSA, DSA, Ed25519, 3DES, RC4, post-quantum (PQC) algorithms, and an "unknown" fallback for anything it cannot classify.
Turns each finding into a single risk score with a derived priority level (P0 Critical through P4 Info) and a short breakdown explaining how the score was reached. The detailed model is documented in QRS Scoring.
When a certificate is parsed, the following metadata is extracted and used throughout the rest of the pipeline:
| Field | Description |
|---|---|
| Subject | Certificate subject distinguished name |
| Issuer | Issuer distinguished name |
| Serial | Certificate serial number |
| Valid from / until | Validity period |
| Algorithm | Detected cryptographic algorithm |
| Key size | Public key size |
| Quantum-vulnerable | Whether the certificate is vulnerable to quantum attack |
A reference list of known algorithms (keyed by object identifier) records each algorithm's name, category, quantum-vulnerability, and deprecation status.
Scanners
Agent
Performs a full system scan of the local host: it inspects the operating-system certificate stores and, unless disabled, also examines running processes and the filesystem (with dedicated certificate-store handling for Linux, Windows, and macOS). All discovered items are aggregated into a single result.
Filesystem
Recursively walks a directory tree (with configurable depth and optional symlink following) and inspects files in parallel, routing each to the right parser by type: PEM/CRT/CER, DER, PKCS#12 (.p12/.pfx), and Java keystores (.jks/.jceks). Unrecognized files are skipped.
Domain
Connects to a target host and port over TLS, retrieves the presented certificate chain, analyzes each certificate, and can enumerate the cipher suites the server supports.
Network
Passively captures network traffic and reassembles TCP streams to extract TLS handshakes; capture and parsing run concurrently until a configured duration elapses or the scan is interrupted. Certificates seen in the handshakes are analyzed and reported.
Parsers
Output
Utilities
Data model
A scan produces a single result that bundles:
- Scan metadata — scanner version, scan mode, date, host name, and duration.
- Findings — each describes a discovered asset: an identifier, its type (certificate or keystore), its location, the extracted certificate information, and its risk assessment.
- Statistics — aggregate counts across the findings.