CLI Reference
CLI Reference
Complete reference guide for the DuoKey PQC Scanner command-line interface.
Synopsis
dke-scanner-agent [OPTIONS] <COMMAND>
Description
Post-Quantum Cryptography readiness scanner. Scan systems, filesystems, and networks for quantum-vulnerable cryptographic assets.
Quick Reference
Everything the agent can do, in one screen. Each command has its own section below.
# ─── Enrolment ─────────────────────────────────────────────────────────────
dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN>
dke-scanner-agent info # capabilities and available verbs
# ─── Remote TLS ────────────────────────────────────────────────────────────
dke-scanner-agent domain --target example.com # report (default)
dke-scanner-agent domain --target example.com --format table
dke-scanner-agent domain --target example.com --format json -o scan.json
dke-scanner-agent domain --target example.com --pqc --format json -o pqc-scan.json
dke-scanner-agent domain --target "a.com,b.com,10.0.0.0/24" --ports 443,8443 \
--timeout 10 --concurrency 20 --retries 1
# ─── Local inventory ───────────────────────────────────────────────────────
dke-scanner-agent filesystem --path /etc/ssl --format json -o fs.json
dke-scanner-agent filesystem --path . --scan-windows-certstore --certstore-name ALL
dke-scanner-agent ssh --format json -o ssh.json
dke-scanner-agent inventory --format json -o inventory.json # filesystem + ssh + certstore
# ─── CBOM (CycloneDX) ──────────────────────────────────────────────────────
dke-scanner-agent cbom --path /etc/ssl --app-name my-app --app-version 1.0.0 -o cbom.json
dke-scanner-agent cbom --input fs.json --app-name my-app -o cbom.json
dke-scanner-agent cbom --input fs.json --spec-version 1.6 -o cbom-1.6.json
# ─── Source code ───────────────────────────────────────────────────────────
dke-scanner-agent source-code --path ./src -o code-cbom.json
dke-scanner-agent source-code --github-repo org/repo --github-token <TOKEN> --branch main
dke-scanner-agent source-code --gitlab-project <ID> --gitlab-token <TOKEN>
dke-scanner-agent source-code --azdo-org <ORG> --azdo-project <PRJ> --azdo-repo <REPO> --azdo-token <TOKEN>
# ─── Quantum Risk Score ────────────────────────────────────────────────────
dke-scanner-agent qrs --input pqc-scan.json # text
dke-scanner-agent qrs --input pqc-scan.json --format json
dke-scanner-agent qrs --input pqc-scan.json --format html -o qrs.html # -o required
dke-scanner-agent qrs --input pqc-scan.json --jurisdiction ksa
# ─── Infrastructure and cloud ──────────────────────────────────────────────
dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN>
dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> --repos libs-release
dke-scanner-agent terraform --path ./infra -o tf.json
dke-scanner-agent cloud --aws --regions eu-central-1,us-east-1 -o kms.json
dke-scanner-agent vault --vault-id <UUID> --token <USER_JWT>
# ─── CI/CD gate ────────────────────────────────────────────────────────────
dke-scanner-agent ci --source-path ./src --fail-on high # exit 1 above threshold
dke-scanner-agent ci --source-path ./src --format sarif -o results.sarif
dke-scanner-agent ci --source-path ./src --fail-on never # report only
# ─── Send to the cockpit ───────────────────────────────────────────────────
dke-scanner-agent upload-scan --target example.com --app-name my-service
dke-scanner-agent agent # persistent mode
Global Options
These options are available for all commands:
| Option | Description | Default |
|---|---|---|
| -h, --help | Display help information | - |
| -V, --version | Display version information | - |
| -v, --verbose | Enable verbose output (can be repeated: -v, -vv, -vvv, -vvvv) | Off |
Verbosity Levels
- No flags: Info and errors only
-v: + Warnings-vv: + Progress information-vvv: + Debug information-vvvv: + Trace information (very detailed)
CMDB Context Options
These options are shared across scanning commands (filesystem, domain, inventory, ci, source-code) and allow linking scan findings to CMDB Configuration Items.
| Option | Env Variable | Description | Default |
|---|---|---|---|
| --ci-id <ID> | PQC_CI_ID | CMDB CI identifier (sys_id) | - |
| --ci-name <NAME> | PQC_CI_NAME | Human-readable application name | - |
| --ci-type <TYPE> | PQC_CI_TYPE | CI type in CMDB | Application |
| --cmdb-adapter <ADAPTER> | PQC_CMDB_ADAPTER | CMDB system: servicenow, jira, generic_rest, none | none |
| --environment <ENV> | PQC_ENVIRONMENT | Environment classification (production, staging, dev, test) | unknown |
| --business-unit <UNIT> | PQC_BUSINESS_UNIT | Business unit owning the application | - |
| --owner <OWNER> | PQC_OWNER | Owner team or email | - |
| --tags <TAGS> | PQC_TAGS | Comma-separated tags | - |
| --domain-map <PATH> | PQC_DOMAIN_MAP | Path to domain mapping YAML file | - |
| --auto-push-cmdb | - | Auto-push findings to CMDB after scan | false |
When --ci-id and --ci-name are provided, they are automatically attached to every finding in the scan results. When publishing to ServiceNow, ci_id maps to the u_related_ci field (CMDB sys_id) and ci_name maps to u_business_application.
CI Context Precedence
The CI context is resolved in this order (highest priority first):
- CLI flags:
--ci-id,--ci-name, etc. - pqc.yaml: Repository-level configuration file (for source code scans)
- Domain mapping file:
--domain-mapYAML file mapping domains to applications - None: No CMDB linking (backward compatible)
pqc.yaml (Repository-Level Config)
Place a pqc.yaml file at the root of your repository to automatically provide CI context during source code scans:
ci_id: "APP-1234"
ci_name: "My Application"
ci_type: "Application"
cmdb: "servicenow"
environment: "production"
business_unit: "Engineering"
tags:
- "pci-scope"
- "internet-facing"
Domain Mapping File
Use a domain mapping YAML file to link domains to one or more applications. This is particularly useful for shared infrastructure where multiple applications share the same domain:
domain_mappings:
"api.mybank.com":
apps:
- ci_id: "APP-4421"
ci_name: "e-banking web"
owner: "team-frontend"
- ci_id: "APP-4422"
ci_name: "e-banking mobile backend"
owner: "team-mobile"
shared_infra: true
environment: "production"
business_unit: "Retail Banking"
"auth.mybank.com":
apps:
- ci_id: "APP-4430"
ci_name: "IAM service"
owner: "team-security"
environment: "production"
CMDB Context Examples
# Filesystem scan with CI linking
dke-scanner-agent filesystem \
--path /etc/ssl/certs \
--ci-id "APP-1234" \
--ci-name "My Application" \
--environment production \
--owner "team-security"
# Domain scan with domain mapping
dke-scanner-agent domain \
--target api.mybank.com \
--ci-id "APP-4421" \
--ci-name "e-banking portal" \
--domain-map ./pqc-domain-map.yaml
# Using environment variables
export PQC_CI_ID="APP-1234"
export PQC_CI_NAME="My App"
export PQC_ENVIRONMENT="production"
dke-scanner-agent filesystem --path /certs
Commands
dke-scanner-agent filesystem
Scan filesystem for certificates and keystores.
dke-scanner-agent filesystem [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| -p, --path <PATH> | Root path to scan | . (current directory) |
| --max-depth <N> | Maximum directory depth (0 = unlimited) | 10 |
| --follow-symlinks | Follow symbolic links | false |
| --extensions <EXTS> | File extensions to scan (comma-separated) | .jks,.p12,.pfx,.pem,.crt,.cer,.key |
| --exclude <PATTERNS> | Exclude patterns (comma-separated) | node_modules,.git,target |
| --threads <N> | Number of parallel threads | 4 |
| -o, --output <FILE> | Output file path (stdout if not specified) | - |
| --format <FMT> | Output format: json, yaml, terminal, html | json |
| --scan-windows-certstore | Scan Windows Certificate Store (Windows only) | false |
| --certstore-name <NAME> | Specific Windows cert store: MY, ROOT, CA, TRUST, or ALL | ALL |
Examples
# Basic filesystem scan
dke-scanner-agent filesystem --path /etc/ssl/certs
# Scan current directory recursively
dke-scanner-agent filesystem
# Scan with depth limit
dke-scanner-agent filesystem --path /opt --max-depth 3
# Scan specific file types only
dke-scanner-agent filesystem --path /certs --extensions .pem,.crt
# Exclude additional patterns
dke-scanner-agent filesystem --path /app --exclude "node_modules,.git,target,*.bak,*.old"
# Save to file with specific format
dke-scanner-agent filesystem --path . --output results.json --format json
dke-scanner-agent filesystem --path . --output results.yaml --format yaml
dke-scanner-agent filesystem --path . --output report.html --format html
# Windows: Scan Windows Certificate Store
dke-scanner-agent filesystem --scan-windows-certstore
# Windows: Scan specific certificate store
dke-scanner-agent filesystem --scan-windows-certstore --certstore-name MY
# Parallel scanning with 8 threads
dke-scanner-agent filesystem --path /large-dir --threads 8
# Follow symbolic links
dke-scanner-agent filesystem --path /data --follow-symlinks
Supported File Formats
- Java KeyStore:
.jks - PKCS#12:
.p12,.pfx - PEM Certificates:
.pem,.crt,.cer - Private Keys:
.key,.pem - Windows Certificate Store: LocalMachine and CurrentUser stores (MY, ROOT, CA, TRUST)
- Configuration files: Detected by content
dke-scanner-agent domain
Scan a remote TLS endpoint. Runs a classic SSL/TLS audit by default; add --pqc for the Post-Quantum readiness report and Quantum Risk Score.
dke-scanner-agent domain [OPTIONS] --target <TARGET>
Options
| Option | Description | Default |
|---|---|---|
| -t, --target <TARGET> | (Required) Target hosts, comma-separated (domain, IP, or CIDR range) | - |
| -p, --ports <PORTS> | Ports to scan, comma-separated | 443 |
| --timeout <SECS> | Connection timeout in seconds per target | 10 |
| --concurrency <N> | Maximum number of concurrent TLS connections | 20 |
| --retries <N> | Retry attempts per target on connection failure | 1 |
| --pqc | Run the Post-Quantum readiness scan (live key-exchange probe) instead of the classic SSL audit | false |
| -j, --jurisdiction <CODE> | Jurisdiction code (eu, us, ae, us_nss, ...) driving the QRS scoring profile. Only applies with --pqc | Civilian |
| -o, --output <FILE> | Output file path | - |
| --format <FMT> | Classic SSL: report (default), table, json, or summary. PQC (--pqc): report (default), json, or summary | report |
Examples
# Classic SSL/TLS audit of a single domain
dke-scanner-agent domain --target example.com
# Scan a custom port
dke-scanner-agent domain --target api.bank.com --ports 8443
# Scan multiple ports and an IP address
dke-scanner-agent domain --target 203.0.113.10 --ports 443,8443
# Post-Quantum readiness scan with Quantum Risk Score
dke-scanner-agent domain --target example.com --pqc
# PQC scan with a jurisdiction-specific scoring profile
dke-scanner-agent domain --target example.com --pqc --jurisdiction eu
# Long timeout for slow servers
dke-scanner-agent domain --target slow-server.com --timeout 30
# Save results
dke-scanner-agent domain --target example.com --output scan-results.json --format json
domain replaces the legacy top-level scan command (kept as a hidden alias for backward compatibility). Only domain --pqc produces the algorithm-detection report and Quantum Risk Score; the classic (non---pqc) audit reports certificate, cipher-suite, protocol, and vulnerability information.
dke-scanner-agent agent
Run as a persistent process connected to a DKE Cockpit server, sending periodic heartbeats. This command does not scan anything by itself — for a one-shot, full local-host cryptographic inventory, use inventory below.
dke-scanner-agent agent [OPTIONS]
Run enroll first to register the host with a cockpit and persist its configuration. Subsequent agent runs read that configuration automatically.
Options
| Option | Description | Default |
|---|---|---|
| -s, --server <URL> | Override the cockpit URL from the enrollment configuration | Enrolled server |
| --heartbeat-interval <SECS> | Heartbeat interval in seconds; overrides the enrollment configuration | Enrolled interval |
| --config <PATH> | Custom configuration-file path | ~/.dke/agent.toml |
Examples
# Enroll the host with a cockpit (one-time)
dke-scanner-agent enroll --server https://cockpit.example.com --token <enrollment-token>
# Start the persistent agent
dke-scanner-agent agent
# Override the cockpit URL and heartbeat interval for this run
dke-scanner-agent agent --server https://cockpit.example.com --heartbeat-interval 60
dke-scanner-agent inventory
Full local-host cryptographic inventory: filesystem certificate sweep and SSH keys, plus, on Windows, the certificate store, installed-application inventory, and registry crypto policy.
dke-scanner-agent inventory [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --no-filesystem | Skip the filesystem certificate sweep | false |
| --no-apps | Skip the installed-application inventory (Windows only) | false |
| --no-registry | Skip the registry crypto-policy sweep (Windows only) | false |
| --no-ssh | Skip the SSH key sweep | false |
| --no-browser-stores | Skip the browser certificate store (Windows only) | false |
| --path <PATH> | Restrict the filesystem sweep to this path (repeatable) | OS-default cert directories |
| -o, --output <FILE> | Output file path | - |
| --format <FMT> | Output format: json, summary | json |
Examples
# Full host inventory
sudo dke-scanner-agent inventory
# Skip the SSH key sweep
sudo dke-scanner-agent inventory --no-ssh
# Skip all Windows-only components
dke-scanner-agent inventory --no-apps --no-registry --no-browser-stores
# Save to file
sudo dke-scanner-agent inventory --output system-scan.json
# Verbose output
sudo dke-scanner-agent inventory -vvv --output scan.json
Platform-Specific Requirements
# Elevated permissions recommended for full filesystem/SSH access
sudo dke-scanner-agent inventory
dke-scanner-agent packet-capture
Analyze a .pcap/.pcapng file offline for quantum-vulnerable cryptographic handshakes (TLS and SSH). Requires the scanner to be built with the pcap feature.
dke-scanner-agent packet-capture [OPTIONS] --pcap-file <FILE>
Options
| Option | Description | Default |
|---|---|---|
| --pcap-file <FILE> | (Required) Path to the .pcap / .pcapng file | - |
| --max-packets <N> | Maximum packets to process (0 = unlimited) | Unlimited |
| --pqc-only | Keep only PQC-relevant findings | false |
| -o, --output <FILE> | Output file path (stdout if not specified) | - |
| --format <FMT> | Output format: json, summary | json |
It does not capture live traffic. Instead, it reconstructs network flows from the capture file and parses cryptographic handshakes to assess PQC readiness:
- TLS 1.2/1.3: Parses ClientHello and ServerHello messages, extracts supported groups, key share extensions, and SNI
- SSH 2.0: Parses KEXINIT messages for key exchange algorithm negotiation
Examples
# Analyze a PCAP file
dke-scanner-agent packet-capture --pcap-file capture.pcap
# Analyze a PcapNG file (Wireshark export)
dke-scanner-agent packet-capture --pcap-file traffic.pcapng --output results.json
# Keep only PQC-relevant findings
dke-scanner-agent packet-capture --pcap-file capture.pcap --pqc-only
# Limit packets processed for large captures
dke-scanner-agent packet-capture --pcap-file large_capture.pcap --max-packets 500000
Use Wireshark or tcpdump to capture traffic first, then analyze the resulting file with the scanner:
tcpdump -i eth0 -w capture.pcap "tcp port 443 or tcp port 22"
dke-scanner-agent network
Live-captures from a network interface (libpcap/Npcap) and detects quantum-vulnerable TLS handshakes in real time. Requires the scanner to be built with the pcap-live feature and the system capture library.
dke-scanner-agent network [OPTIONS] --interface <IF>
Options
| Option | Description | Default |
|---|---|---|
| -i, --interface <IF> | (Required) Interface to capture from (e.g. eth0) | - |
| --capture-duration-secs <SECS> | Capture duration in seconds | Unbounded |
| --max-flows <N> | Maximum number of flows to track | Unbounded |
| --bpf-filter <FILTER> | Optional BPF filter (e.g. "tcp port 443") | - |
| --pqc-only | Keep only PQC-relevant findings | false |
| -o, --output <FILE> | Output file path (stdout if not specified) | - |
| --format <FMT> | Output format: json, summary | json |
Examples
# Live capture on eth0
sudo dke-scanner-agent network --interface eth0
# Bound the capture duration
sudo dke-scanner-agent network --interface eth0 --capture-duration-secs 300
# Filter to TLS traffic only
sudo dke-scanner-agent network --interface eth0 --bpf-filter "tcp port 443"
# Save results
sudo dke-scanner-agent network --interface eth0 --output network-scan.json
Live capture typically requires elevated privileges (root / Administrator) to open the network interface.
dke-scanner-agent ci
CI/CD mode - scan source code and generate CBOM.
dke-scanner-agent ci [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --source-path <PATH> | Source code path to scan | . |
| --max-depth <N> | Maximum directory depth | 10 |
| -o, --output <FILE> | Output file path | - |
| --format <FMT> | Output format: json, sarif | json |
| --fail-on <LEVEL> | Fail CI on severity level: critical, high, medium, never | high |
Examples
# Scan current directory
dke-scanner-agent ci
# Scan specific directory
dke-scanner-agent ci --source-path /path/to/code
# Generate SARIF for GitHub/GitLab integration
dke-scanner-agent ci --format sarif --output results.sarif
# Fail on critical findings only
dke-scanner-agent ci --fail-on critical
# Never fail the build
dke-scanner-agent ci --fail-on never
# Save to file
dke-scanner-agent ci --output ci-results.json
# Limit scan depth
dke-scanner-agent ci --source-path . --max-depth 5
Exit Codes
| Code | Meaning |
|---|---|
| 0 | Success (no issues or severity below threshold) |
| 1 | Findings at or above --fail-on threshold |
| 2 | Scan error |
CI/CD Integration Examples
- name: PQC Security Scan
run: |
dke-scanner-agent ci --format sarif --output results.sarif
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: results.sarif
dke-scanner-agent source-code
Source code crypto scanner with Git provider integrations.
dke-scanner-agent source-code [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| -p, --path <PATH> | Local path to scan | - |
| --gitlab-project <PROJECT> | GitLab project (group/project) | - |
| --gitlab-token <TOKEN> | GitLab token | GITLAB_TOKEN env var |
| --gitlab-url <URL> | GitLab base URL | https://gitlab.com |
| --github-repo <REPO> | GitHub repository (owner/repo) | - |
| --github-token <TOKEN> | GitHub token | GITHUB_TOKEN env var |
| --github-url <URL> | GitHub base URL | https://api.github.com |
| --azdo-org <ORG> | Azure DevOps organization | - |
| --azdo-project <PROJECT> | Azure DevOps project | - |
| --azdo-repo <REPO> | Azure DevOps repository | - |
| --azdo-token <TOKEN> | Azure DevOps PAT token | AZDO_TOKEN env var |
| --azdo-url <URL> | Azure DevOps base URL | https://dev.azure.com |
| --branch <BRANCH> | Branch to scan | main/master |
| --languages <LANGS> | Languages to scan (comma-separated) | Auto-detect |
| --max-depth <N> | Maximum directory depth | 10 |
| -o, --output <FILE> | Output file path | - |
| --format <FMT> | Output format: json, yaml, terminal, html | json |
Examples
# Scan local directory
dke-scanner-agent source-code --path /path/to/code
# Scan GitLab project
dke-scanner-agent source-code \
--gitlab-project mygroup/myproject \
--gitlab-token $GITLAB_TOKEN
# Scan GitHub repository
dke-scanner-agent source-code \
--github-repo owner/repo \
--github-token $GITHUB_TOKEN
# Scan Azure DevOps repository
dke-scanner-agent source-code \
--azdo-org myorg \
--azdo-project myproject \
--azdo-repo myrepo \
--azdo-token $AZDO_TOKEN
# Scan specific branch
dke-scanner-agent source-code \
--github-repo owner/repo \
--github-token $GITHUB_TOKEN \
--branch develop
# Scan specific languages
dke-scanner-agent source-code \
--path . \
--languages "java,python,go"
# Self-hosted GitLab
dke-scanner-agent source-code \
--gitlab-project group/project \
--gitlab-url https://gitlab.company.com \
--gitlab-token $TOKEN
# GitHub Enterprise
dke-scanner-agent source-code \
--github-repo org/repo \
--github-url https://github.company.com/api/v3 \
--github-token $TOKEN
# Save results
dke-scanner-agent source-code --path . --output scan.json --format json
Environment Variables
GITLAB_TOKEN: GitLab personal access tokenGITHUB_TOKEN: GitHub personal access tokenAZDO_TOKEN: Azure DevOps personal access token (PAT)
Supported Languages
The scanner auto-detects and analyzes cryptographic usage in:
Languages
- Java
- Python
- Go
- JavaScript/TypeScript
- C/C++
- C#
- Ruby
- PHP
- And more...
Compliance-framework checking and ServiceNow publishing are available in DuoKey CPM, but are not standalone dke-scanner-agent CLI commands. Compliance checking runs against saved scan results inside the product; ServiceNow integration is configured server-side. See ServiceNow Integration for details.
dke-scanner-agent cbom
Export scan results as CBOM (Cryptography Bill of Materials).
dke-scanner-agent cbom [OPTIONS] --input <FILE>
Options
| Option | Description | Default |
|---|---|---|
| -i, --input <FILE> | (Required) Scan results file (JSON) to convert | - |
| -o, --output <FILE> | Output file for CBOM | <input>-cbom.json |
| --app-name <NAME> | Application name for CBOM metadata | From scan |
| --app-version <VER> | Application version for CBOM metadata | 1.0 |
| --pretty | Pretty-print JSON output | true |
Description
Generates a CycloneDX 1.7 CBOM (Cryptography Bill of Materials) from scan results. The CBOM format provides:
- Standardized cryptographic asset inventory
- Component relationships and dependencies
- Compliance with CycloneDX specification
- Integration with SBOM tools and workflows
Examples
# Basic CBOM generation
dke-scanner-agent cbom --input scan-results.json
# Custom output file
dke-scanner-agent cbom \
--input scan-results.json \
--output app-cbom.json
# With application metadata
dke-scanner-agent cbom \
--input scan.json \
--app-name "Payment Gateway" \
--app-version "2.5.1" \
--output payment-gateway-cbom.json
# Compact JSON (no pretty print)
dke-scanner-agent cbom \
--input scan.json \
--pretty false
# Complete workflow
dke-scanner-agent filesystem --path /app --output scan.json
dke-scanner-agent cbom --input scan.json --app-name "MyApp" --app-version "1.0"
CBOM Output
The generated CBOM includes:
- Components: Cryptographic assets (algorithms, certificates, keys, protocols)
- Dependencies: Relationships between components
- Metadata: Timestamps, tool information, application details
- Properties: Risk scores, quantum vulnerability status, compliance info
Validation
The tool automatically validates the generated CBOM against CycloneDX 1.7 specification:
- Format and version compliance
- Component structure validation
- Cryptographic properties validation
- Asset type consistency
dke-scanner-agent ssh
Discover SSH keys from the ssh-agent, ~/.ssh, /etc/ssh host keys and the Cockpit-managed key directory, classifying each by algorithm and quantum vulnerability.
dke-scanner-agent ssh [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --no-agent | Skip keys held by a running ssh-agent | false |
| --no-user-keys | Skip user keys under ~/.ssh | false |
| --no-server-keys | Skip host keys under /etc/ssh | false |
| --format <FMT> | json or summary | json |
| -o, --output <FILE> | Write to a file instead of stdout | - |
Examples
# Every source
dke-scanner-agent ssh --format json -o ssh.json
# Host keys only, on a server where no user logs in interactively
dke-scanner-agent ssh --no-agent --no-user-keys --format summary
dke-scanner-agent qrs
Compute the Quantum Risk Score from a scan JSON produced by any other verb: the 0-100 composite, its band, the four weighted signals, and optionally the full editorial HTML report the cockpit UI exports.
dke-scanner-agent qrs --input <FILE> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --input <FILE> | (Required) A scan JSON written earlier by filesystem, domain, source-code, … | - |
| --format <FMT> | text, json or html | text |
| -o, --output <FILE> | Output file. Required when --format html | - |
| -j, --jurisdiction <CODE> | Scoring profile: ae|uae, ksa|sa, eu|eea, uk|gb, ch, us, us_nss|cnsa20, jp|japan, ca|canada, au|australia, ma|morocco, dz|algeria | global |
| --scan-number <N> | Which scan to read when the input holds several | 1 |
Examples
# Score a PQC scan
dke-scanner-agent domain --target example.com --pqc --format json -o pqc-scan.json
dke-scanner-agent qrs --input pqc-scan.json
# Machine-readable, for a dashboard
dke-scanner-agent qrs --input pqc-scan.json --format json
# Full editorial report, then print to PDF from the browser
dke-scanner-agent qrs --input pqc-scan.json --format html -o qrs.html
# Score against a national profile rather than the global default
dke-scanner-agent qrs --input pqc-scan.json --jurisdiction ksa
The HTML report is too large for stdout, so --format html refuses to run without -o. The jurisdiction changes the scoring profile and the regulatory framing of the report — us_nss (equivalently cnsa20) applies the NSA CNSA 2.0 mandate rather than the civilian profile.
dke-scanner-agent fortinet
Scan a FortiGate / FortiOS device through its REST API: installed certificates, CA certificates, IPSec VPN and SSL-VPN profiles.
dke-scanner-agent fortinet --target <URL> --api-token <TOKEN> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --target <URL> | (Required) Device base URL | - |
| --api-token <TOKEN> | (Required) FortiOS REST API token | - |
| --verify-tls | Verify the device certificate | false |
| --timeout-secs <SECS> | Per-request timeout | - |
| --format <FMT> | json or summary | json |
| -o, --output <FILE> | Write to a file instead of stdout | - |
Examples
dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN> -o fw.json
# Enforce certificate verification against a device with a trusted certificate
dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN> --verify-tls
dke-scanner-agent jfrog
Scan a JFrog Artifactory instance — optionally with Xray — for cryptographic material inside published artifacts.
dke-scanner-agent jfrog --base-url <URL> --api-key <KEY> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --base-url <URL> | (Required) Artifactory base URL | - |
| --api-key <KEY> | (Required) Artifactory API key | - |
| --repos <REPO> | Repository to scan; repeat the flag for several | all |
| --max-artifacts-per-repo <N> | Cap the artifacts inspected per repository | - |
| --no-verify-tls | Skip TLS verification | false |
| --xray-url <URL> | Xray base URL, to enrich findings | - |
| --format <FMT> | json or summary | json |
| -o, --output <FILE> | Write to a file instead of stdout | - |
Examples
dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> -o jfrog.json
# Two repositories, bounded so a first run finishes quickly
dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> \
--repos libs-release --repos docker-local \
--max-artifacts-per-repo 200
dke-scanner-agent terraform
Scan Terraform state files and HCL for cryptographic resources: KMS keys, TLS certificates and provider configuration.
dke-scanner-agent terraform --path <DIR> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --path <DIR> | (Required) Directory to scan; repeat the flag for several | - |
| --no-recurse | Do not descend into subdirectories | false |
| --no-state | Skip .tfstate files | false |
| --no-hcl | Skip .tf source files | false |
| --format <FMT> | json or summary | json |
| -o, --output <FILE> | Write to a file instead of stdout | - |
Examples
dke-scanner-agent terraform --path ./infra -o tf.json
# State only — useful when the HCL lives in another repository
dke-scanner-agent terraform --path ./infra --no-hcl --format summary
dke-scanner-agent cloud
Scan a cloud KMS for key material.
dke-scanner-agent cloud --aws [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --aws | Scan AWS KMS | false |
| --regions <REGION> | Region to scan; repeat the flag for several | account default |
| --credentials-file <FILE> | Credentials file instead of the ambient chain | - |
| --access-key-id <ID> | Explicit access key ID | - |
| --secret-access-key <KEY> | Explicit secret access key | - |
| --format <FMT> | json or summary | json |
| -o, --output <FILE> | Write to a file instead of stdout | - |
Examples
# Ambient credentials (instance role, profile, environment)
dke-scanner-agent cloud --aws --regions eu-central-1,us-east-1 -o kms.json
AWS KMS is fully implemented. Azure Key Vault and GCP KMS currently emit a placeholder finding rather than a real inventory — treat their output as a stub, not as coverage.
dke-scanner-agent vault
Scan a cockpit-managed vault for quantum-vulnerable keys. This verb is a thin client: the scan runs server-side, because it needs the cockpit database and tenant context.
dke-scanner-agent vault --vault-id <UUID> --token <USER_JWT> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --vault-id <UUID> | (Required) Vault to scan | - |
| --token <JWT> | (Required) User session JWT — not the agent API key | - |
| --server <URL> | Cockpit URL, when it differs from the enrolled one | from config |
| --include-metadata | Include key metadata in the response | false |
| --config <FILE> | Alternate agent config file | ~/.dke/agent.toml |
Examples
dke-scanner-agent vault --vault-id 0f1c2d3e-4a5b-6c7d-8e9f-0a1b2c3d4e5f --token <USER_JWT>
This is the one verb that authenticates with a user JWT rather than the enrolled agent key: the scan API is gated by the Operations.Pqc.Scan.Create permission, which belongs to a user, not to an agent.
dke-scanner-agent enroll
Register the agent with a cockpit and persist the issued API key to ~/.dke/agent.toml (mode 0600 on Unix). Run this once before agent or upload-scan.
dke-scanner-agent enroll --server <URL> --token <ENROLL_TOKEN>
Options
| Option | Description | Default |
|---|---|---|
| --server <URL> | (Required) Cockpit base URL | - |
| --token <TOKEN> | Single-use bundle token from the cockpit Generate-installer flow. Tenant-bound, platform-bound, expires in 1 hour | - |
| --user-token <JWT> | Legacy path: a full user session JWT | - |
| --pin-spki-sha256 <HASH> | Pin the cockpit certificate by SPKI SHA-256 | - |
| --expected-sha256 <HASH> | Expected hash of the downloaded bundle | - |
| --config <FILE> | Write the config somewhere other than ~/.dke/agent.toml | ~/.dke/agent.toml |
| --force | Overwrite an existing enrolment | false |
Examples
dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN>
# Re-enrol a host that already has a config
dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN> --force
Exactly one of --token and --user-token must be given. Prefer the bundle token: it is single-use and short-lived, where a session JWT carries the full rights of the user who minted it.
dke-scanner-agent upload-scan
Run a one-shot TLS scan and post the result to the cockpit instead of printing it. Targets appear on the CBOMs page tagged with this agent as their creator.
dke-scanner-agent upload-scan --target <TARGET> [OPTIONS]
Options
| Option | Description | Default |
|---|---|---|
| --target <TARGET> | (Required) Target hosts, comma-separated | - |
| --ports <PORTS> | Ports to scan, comma-separated | 443 |
| --timeout <SECS> | Connection timeout per target | 10 |
| --concurrency <N> | Maximum concurrent connections | 20 |
| --retries <N> | Retries per target | 1 |
| --app-name <NAME> | Application name recorded against the findings | - |
| --server <URL> | Cockpit URL, when it differs from the enrolled one | from config |
| --config <FILE> | Alternate agent config file | ~/.dke/agent.toml |
Examples
dke-scanner-agent upload-scan --target example.com --app-name my-service
# Point a one-off run at another cockpit without re-enrolling
dke-scanner-agent upload-scan --target example.com --server https://cockpit-test.example.com
Requires a prior enroll: the agent ID and API key are read from the config, not passed on the command line.
dke-scanner-agent info
Print the agent build, its capabilities and the verbs available in this build. Useful when a command is missing: several scanners sit behind build features.
dke-scanner-agent info
Options
| Option | Description | Default |
|---|
Examples
dke-scanner-agent info
Output Formats
All scanning commands support multiple output formats:
| Format | Command | Description |
|---|---|---|
| JSON (Default) | --format json | Structured JSON output for programmatic processing |
| YAML | --format yaml | Human-readable YAML format |
| HTML | --format html | Interactive HTML report with visualizations |
| Terminal | --format terminal | Pretty-printed terminal output with colors (interactive use) |
| SARIF (CI Only) | --format sarif | Static Analysis Results Interchange Format for CI/CD |
Common Workflows
# Step 1: Host inventory scan on each server
ssh server1 "sudo dke-scanner-agent inventory --output server1.json"
ssh server2 "sudo dke-scanner-agent inventory --output server2.json"
# Step 2: Filesystem scan on shared storage
dke-scanner-agent filesystem --path /mnt/shared --output shared.json
# Step 3: Domain scan for external endpoints
dke-scanner-agent domain --target api.example.com --pqc --output api-scan.json
Review the combined results in the DuoKey Cockpit's PQC Readiness module.
Exit Codes
| Code | Meaning |
|---|---|
| 0 | Success |
| 1 | General error or findings above threshold (CI mode) |
| 2 | Scan error or invalid arguments |
| 3 | Permission denied |
Troubleshooting
Environment Variables
Global environment variables that affect scanner behavior:
| Variable | Description | Default |
|---|---|---|
| GITLAB_TOKEN | GitLab personal access token | - |
| GITHUB_TOKEN | GitHub personal access token | - |
| AZDO_TOKEN | Azure DevOps PAT token | - |
| PQC_CI_ID | CMDB CI identifier (sys_id) | - |
| PQC_CI_NAME | CMDB CI human-readable name | - |
| PQC_CI_TYPE | CI type in CMDB | Application |
| PQC_CMDB_ADAPTER | CMDB system (servicenow, jira, generic_rest, none) | none |
| PQC_ENVIRONMENT | Environment classification | unknown |
| PQC_BUSINESS_UNIT | Business unit | - |
| PQC_OWNER | Owner team or email | - |
| PQC_TAGS | Comma-separated tags | - |
| PQC_DOMAIN_MAP | Path to domain mapping YAML | - |
Examples
# Set GitLab token
export GITLAB_TOKEN="glpat-xxxxxxxxxxxxxxxxxxxx"
# Set CMDB context
export PQC_CI_ID="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6"
export PQC_CI_NAME="Payment Gateway"
export PQC_ENVIRONMENT="production"
# Use environment variables
dke-scanner-agent source-code --gitlab-project mygroup/myproject
Best Practices
Recommended Practices
Regular Scanning
Schedule daily inventory scans via cron
Secure Credentials
Use environment variables, not command-line arguments
CI/CD Integration
Add scans to your deployment pipeline
Compliance Reporting
Generate quarterly compliance reports
Performance Tips
See Also
This documentation reflects the current version of the PQC Scanner CLI. For version-specific changes, see the project changelog. Last Updated: January 2025 | Scanner Version: 1.0+ | API Version: v1