Skip to main content

CLI Reference

Applies to:
WindowsLinuxmacOSDocker

Synopsis​

dke-scanner-agent [OPTIONS] <COMMAND>

Description​

Post-Quantum Cryptography readiness scanner. Scan systems, filesystems, and networks for quantum-vulnerable cryptographic assets.

Quick Reference​

Everything the agent can do, in one screen. Each command has its own section below.

# ─── Enrolment ─────────────────────────────────────────────────────────────
dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN>
dke-scanner-agent info # capabilities and available verbs

# ─── Remote TLS ────────────────────────────────────────────────────────────
dke-scanner-agent domain --target example.com # report (default)
dke-scanner-agent domain --target example.com --format table
dke-scanner-agent domain --target example.com --format json -o scan.json
dke-scanner-agent domain --target example.com --pqc --format json -o pqc-scan.json
dke-scanner-agent domain --target "a.com,b.com,10.0.0.0/24" --ports 443,8443 \
--timeout 10 --concurrency 20 --retries 1

# ─── Local inventory ───────────────────────────────────────────────────────
dke-scanner-agent filesystem --path /etc/ssl --format json -o fs.json
dke-scanner-agent filesystem --path . --scan-windows-certstore --certstore-name ALL
dke-scanner-agent ssh --format json -o ssh.json
dke-scanner-agent inventory --format json -o inventory.json # filesystem + ssh + certstore

# ─── CBOM (CycloneDX) ──────────────────────────────────────────────────────
dke-scanner-agent cbom --path /etc/ssl --app-name my-app --app-version 1.0.0 -o cbom.json
dke-scanner-agent cbom --input fs.json --app-name my-app -o cbom.json
dke-scanner-agent cbom --input fs.json --spec-version 1.6 -o cbom-1.6.json

# ─── Source code ───────────────────────────────────────────────────────────
dke-scanner-agent source-code --path ./src -o code-cbom.json
dke-scanner-agent source-code --github-repo org/repo --github-token <TOKEN> --branch main
dke-scanner-agent source-code --gitlab-project <ID> --gitlab-token <TOKEN>
dke-scanner-agent source-code --azdo-org <ORG> --azdo-project <PRJ> --azdo-repo <REPO> --azdo-token <TOKEN>

# ─── Quantum Risk Score ────────────────────────────────────────────────────
dke-scanner-agent qrs --input pqc-scan.json # text
dke-scanner-agent qrs --input pqc-scan.json --format json
dke-scanner-agent qrs --input pqc-scan.json --format html -o qrs.html # -o required
dke-scanner-agent qrs --input pqc-scan.json --jurisdiction ksa

# ─── Infrastructure and cloud ──────────────────────────────────────────────
dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN>
dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> --repos libs-release
dke-scanner-agent terraform --path ./infra -o tf.json
dke-scanner-agent cloud --aws --regions eu-central-1,us-east-1 -o kms.json
dke-scanner-agent vault --vault-id <UUID> --token <USER_JWT>

# ─── CI/CD gate ────────────────────────────────────────────────────────────
dke-scanner-agent ci --source-path ./src --fail-on high # exit 1 above threshold
dke-scanner-agent ci --source-path ./src --format sarif -o results.sarif
dke-scanner-agent ci --source-path ./src --fail-on never # report only

# ─── Send to the cockpit ───────────────────────────────────────────────────
dke-scanner-agent upload-scan --target example.com --app-name my-service
dke-scanner-agent agent # persistent mode

Global Options​

These options are available for all commands:

OptionDescriptionDefault
-h, --helpDisplay help information-
-V, --versionDisplay version information-
-v, --verboseEnable verbose output (can be repeated: -v, -vv, -vvv, -vvvv)Off

Verbosity Levels​

  • No flags: Info and errors only
  • -v: + Warnings
  • -vv: + Progress information
  • -vvv: + Debug information
  • -vvvv: + Trace information (very detailed)

CMDB Context Options​

These options are shared across scanning commands (filesystem, domain, inventory, ci, source-code) and allow linking scan findings to CMDB Configuration Items.

OptionEnv VariableDescriptionDefault
--ci-id <ID>PQC_CI_IDCMDB CI identifier (sys_id)-
--ci-name <NAME>PQC_CI_NAMEHuman-readable application name-
--ci-type <TYPE>PQC_CI_TYPECI type in CMDBApplication
--cmdb-adapter <ADAPTER>PQC_CMDB_ADAPTERCMDB system: servicenow, jira, generic_rest, nonenone
--environment <ENV>PQC_ENVIRONMENTEnvironment classification (production, staging, dev, test)unknown
--business-unit <UNIT>PQC_BUSINESS_UNITBusiness unit owning the application-
--owner <OWNER>PQC_OWNEROwner team or email-
--tags <TAGS>PQC_TAGSComma-separated tags-
--domain-map <PATH>PQC_DOMAIN_MAPPath to domain mapping YAML file-
--auto-push-cmdb-Auto-push findings to CMDB after scanfalse
Tip

When --ci-id and --ci-name are provided, they are automatically attached to every finding in the scan results. When publishing to ServiceNow, ci_id maps to the u_related_ci field (CMDB sys_id) and ci_name maps to u_business_application.

CI Context Precedence​

The CI context is resolved in this order (highest priority first):

  1. CLI flags: --ci-id, --ci-name, etc.
  2. pqc.yaml: Repository-level configuration file (for source code scans)
  3. Domain mapping file: --domain-map YAML file mapping domains to applications
  4. None: No CMDB linking (backward compatible)

pqc.yaml (Repository-Level Config)​

Place a pqc.yaml file at the root of your repository to automatically provide CI context during source code scans:

ci_id: "APP-1234"
ci_name: "My Application"
ci_type: "Application"
cmdb: "servicenow"
environment: "production"
business_unit: "Engineering"
tags:
- "pci-scope"
- "internet-facing"

Domain Mapping File​

Use a domain mapping YAML file to link domains to one or more applications. This is particularly useful for shared infrastructure where multiple applications share the same domain:

domain_mappings:
"api.mybank.com":
apps:
- ci_id: "APP-4421"
ci_name: "e-banking web"
owner: "team-frontend"
- ci_id: "APP-4422"
ci_name: "e-banking mobile backend"
owner: "team-mobile"
shared_infra: true
environment: "production"
business_unit: "Retail Banking"

"auth.mybank.com":
apps:
- ci_id: "APP-4430"
ci_name: "IAM service"
owner: "team-security"
environment: "production"

CMDB Context Examples​

# Filesystem scan with CI linking
dke-scanner-agent filesystem \
--path /etc/ssl/certs \
--ci-id "APP-1234" \
--ci-name "My Application" \
--environment production \
--owner "team-security"

# Domain scan with domain mapping
dke-scanner-agent domain \
--target api.mybank.com \
--ci-id "APP-4421" \
--ci-name "e-banking portal" \
--domain-map ./pqc-domain-map.yaml

# Using environment variables
export PQC_CI_ID="APP-1234"
export PQC_CI_NAME="My App"
export PQC_ENVIRONMENT="production"
dke-scanner-agent filesystem --path /certs

Commands​

dke-scanner-agent filesystem​

Scan filesystem for certificates and keystores.

dke-scanner-agent filesystem [OPTIONS]

Options​

OptionDescriptionDefault
-p, --path <PATH>Root path to scan. (current directory)
--max-depth <N>Maximum directory depth (0 = unlimited)10
--follow-symlinksFollow symbolic linksfalse
--extensions <EXTS>File extensions to scan (comma-separated).jks,.p12,.pfx,.pem,.crt,.cer,.key
--exclude <PATTERNS>Exclude patterns (comma-separated)node_modules,.git,target
--threads <N>Number of parallel threads4
-o, --output <FILE>Output file path (stdout if not specified)-
--format <FMT>Output format: json, yaml, terminal, htmljson
--scan-windows-certstoreScan Windows Certificate Store (Windows only)false
--certstore-name <NAME>Specific Windows cert store: MY, ROOT, CA, TRUST, or ALLALL

Examples​

# Basic filesystem scan
dke-scanner-agent filesystem --path /etc/ssl/certs

# Scan current directory recursively
dke-scanner-agent filesystem

# Scan with depth limit
dke-scanner-agent filesystem --path /opt --max-depth 3

# Scan specific file types only
dke-scanner-agent filesystem --path /certs --extensions .pem,.crt

# Exclude additional patterns
dke-scanner-agent filesystem --path /app --exclude "node_modules,.git,target,*.bak,*.old"

# Save to file with specific format
dke-scanner-agent filesystem --path . --output results.json --format json
dke-scanner-agent filesystem --path . --output results.yaml --format yaml
dke-scanner-agent filesystem --path . --output report.html --format html

# Windows: Scan Windows Certificate Store
dke-scanner-agent filesystem --scan-windows-certstore

# Windows: Scan specific certificate store
dke-scanner-agent filesystem --scan-windows-certstore --certstore-name MY

# Parallel scanning with 8 threads
dke-scanner-agent filesystem --path /large-dir --threads 8

# Follow symbolic links
dke-scanner-agent filesystem --path /data --follow-symlinks

Supported File Formats​

  • Java KeyStore: .jks
  • PKCS#12: .p12, .pfx
  • PEM Certificates: .pem, .crt, .cer
  • Private Keys: .key, .pem
  • Windows Certificate Store: LocalMachine and CurrentUser stores (MY, ROOT, CA, TRUST)
  • Configuration files: Detected by content

dke-scanner-agent domain​

Scan a remote TLS endpoint. Runs a classic SSL/TLS audit by default; add --pqc for the Post-Quantum readiness report and Quantum Risk Score.

dke-scanner-agent domain [OPTIONS] --target <TARGET>

Options​

OptionDescriptionDefault
-t, --target <TARGET>(Required) Target hosts, comma-separated (domain, IP, or CIDR range)-
-p, --ports <PORTS>Ports to scan, comma-separated443
--timeout <SECS>Connection timeout in seconds per target10
--concurrency <N>Maximum number of concurrent TLS connections20
--retries <N>Retry attempts per target on connection failure1
--pqcRun the Post-Quantum readiness scan (live key-exchange probe) instead of the classic SSL auditfalse
-j, --jurisdiction <CODE>Jurisdiction code (eu, us, ae, us_nss, ...) driving the QRS scoring profile. Only applies with --pqcCivilian
-o, --output <FILE>Output file path-
--format <FMT>Classic SSL: report (default), table, json, or summary. PQC (--pqc): report (default), json, or summaryreport

Examples​

# Classic SSL/TLS audit of a single domain
dke-scanner-agent domain --target example.com

# Scan a custom port
dke-scanner-agent domain --target api.bank.com --ports 8443

# Scan multiple ports and an IP address
dke-scanner-agent domain --target 203.0.113.10 --ports 443,8443

# Post-Quantum readiness scan with Quantum Risk Score
dke-scanner-agent domain --target example.com --pqc

# PQC scan with a jurisdiction-specific scoring profile
dke-scanner-agent domain --target example.com --pqc --jurisdiction eu

# Long timeout for slow servers
dke-scanner-agent domain --target slow-server.com --timeout 30

# Save results
dke-scanner-agent domain --target example.com --output scan-results.json --format json
Note

domain replaces the legacy top-level scan command (kept as a hidden alias for backward compatibility). Only domain --pqc produces the algorithm-detection report and Quantum Risk Score; the classic (non---pqc) audit reports certificate, cipher-suite, protocol, and vulnerability information.


dke-scanner-agent agent​

Run as a persistent process connected to a DKE Cockpit server, sending periodic heartbeats. This command does not scan anything by itself — for a one-shot, full local-host cryptographic inventory, use inventory below.

dke-scanner-agent agent [OPTIONS]
Note

Run enroll first to register the host with a cockpit and persist its configuration. Subsequent agent runs read that configuration automatically.

Options​

OptionDescriptionDefault
-s, --server <URL>Override the cockpit URL from the enrollment configurationEnrolled server
--heartbeat-interval <SECS>Heartbeat interval in seconds; overrides the enrollment configurationEnrolled interval
--config <PATH>Custom configuration-file path~/.dke/agent.toml

Examples​

# Enroll the host with a cockpit (one-time)
dke-scanner-agent enroll --server https://cockpit.example.com --token <enrollment-token>

# Start the persistent agent
dke-scanner-agent agent

# Override the cockpit URL and heartbeat interval for this run
dke-scanner-agent agent --server https://cockpit.example.com --heartbeat-interval 60

dke-scanner-agent inventory​

Full local-host cryptographic inventory: filesystem certificate sweep and SSH keys, plus, on Windows, the certificate store, installed-application inventory, and registry crypto policy.

dke-scanner-agent inventory [OPTIONS]

Options​

OptionDescriptionDefault
--no-filesystemSkip the filesystem certificate sweepfalse
--no-appsSkip the installed-application inventory (Windows only)false
--no-registrySkip the registry crypto-policy sweep (Windows only)false
--no-sshSkip the SSH key sweepfalse
--no-browser-storesSkip the browser certificate store (Windows only)false
--path <PATH>Restrict the filesystem sweep to this path (repeatable)OS-default cert directories
-o, --output <FILE>Output file path-
--format <FMT>Output format: json, summaryjson

Examples​

# Full host inventory
sudo dke-scanner-agent inventory

# Skip the SSH key sweep
sudo dke-scanner-agent inventory --no-ssh

# Skip all Windows-only components
dke-scanner-agent inventory --no-apps --no-registry --no-browser-stores

# Save to file
sudo dke-scanner-agent inventory --output system-scan.json

# Verbose output
sudo dke-scanner-agent inventory -vvv --output scan.json

Platform-Specific Requirements​

# Elevated permissions recommended for full filesystem/SSH access
sudo dke-scanner-agent inventory

dke-scanner-agent packet-capture​

Analyze a .pcap/.pcapng file offline for quantum-vulnerable cryptographic handshakes (TLS and SSH). Requires the scanner to be built with the pcap feature.

dke-scanner-agent packet-capture [OPTIONS] --pcap-file <FILE>

Options​

OptionDescriptionDefault
--pcap-file <FILE>(Required) Path to the .pcap / .pcapng file-
--max-packets <N>Maximum packets to process (0 = unlimited)Unlimited
--pqc-onlyKeep only PQC-relevant findingsfalse
-o, --output <FILE>Output file path (stdout if not specified)-
--format <FMT>Output format: json, summaryjson

It does not capture live traffic. Instead, it reconstructs network flows from the capture file and parses cryptographic handshakes to assess PQC readiness:

  • TLS 1.2/1.3: Parses ClientHello and ServerHello messages, extracts supported groups, key share extensions, and SNI
  • SSH 2.0: Parses KEXINIT messages for key exchange algorithm negotiation

Examples​

# Analyze a PCAP file
dke-scanner-agent packet-capture --pcap-file capture.pcap

# Analyze a PcapNG file (Wireshark export)
dke-scanner-agent packet-capture --pcap-file traffic.pcapng --output results.json

# Keep only PQC-relevant findings
dke-scanner-agent packet-capture --pcap-file capture.pcap --pqc-only

# Limit packets processed for large captures
dke-scanner-agent packet-capture --pcap-file large_capture.pcap --max-packets 500000
Tip

Use Wireshark or tcpdump to capture traffic first, then analyze the resulting file with the scanner:
tcpdump -i eth0 -w capture.pcap "tcp port 443 or tcp port 22"


dke-scanner-agent network​

Live-captures from a network interface (libpcap/Npcap) and detects quantum-vulnerable TLS handshakes in real time. Requires the scanner to be built with the pcap-live feature and the system capture library.

dke-scanner-agent network [OPTIONS] --interface <IF>

Options​

OptionDescriptionDefault
-i, --interface <IF>(Required) Interface to capture from (e.g. eth0)-
--capture-duration-secs <SECS>Capture duration in secondsUnbounded
--max-flows <N>Maximum number of flows to trackUnbounded
--bpf-filter <FILTER>Optional BPF filter (e.g. "tcp port 443")-
--pqc-onlyKeep only PQC-relevant findingsfalse
-o, --output <FILE>Output file path (stdout if not specified)-
--format <FMT>Output format: json, summaryjson

Examples​

# Live capture on eth0
sudo dke-scanner-agent network --interface eth0

# Bound the capture duration
sudo dke-scanner-agent network --interface eth0 --capture-duration-secs 300

# Filter to TLS traffic only
sudo dke-scanner-agent network --interface eth0 --bpf-filter "tcp port 443"

# Save results
sudo dke-scanner-agent network --interface eth0 --output network-scan.json
Note

Live capture typically requires elevated privileges (root / Administrator) to open the network interface.


dke-scanner-agent ci​

CI/CD mode - scan source code and generate CBOM.

dke-scanner-agent ci [OPTIONS]

Options​

OptionDescriptionDefault
--source-path <PATH>Source code path to scan.
--max-depth <N>Maximum directory depth10
-o, --output <FILE>Output file path-
--format <FMT>Output format: json, sarifjson
--fail-on <LEVEL>Fail CI on severity level: critical, high, medium, neverhigh

Examples​

# Scan current directory
dke-scanner-agent ci

# Scan specific directory
dke-scanner-agent ci --source-path /path/to/code

# Generate SARIF for GitHub/GitLab integration
dke-scanner-agent ci --format sarif --output results.sarif

# Fail on critical findings only
dke-scanner-agent ci --fail-on critical

# Never fail the build
dke-scanner-agent ci --fail-on never

# Save to file
dke-scanner-agent ci --output ci-results.json

# Limit scan depth
dke-scanner-agent ci --source-path . --max-depth 5

Exit Codes​

CodeMeaning
0Success (no issues or severity below threshold)
1Findings at or above --fail-on threshold
2Scan error

CI/CD Integration Examples​

- name: PQC Security Scan
run: |
dke-scanner-agent ci --format sarif --output results.sarif

- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: results.sarif

dke-scanner-agent source-code​

Source code crypto scanner with Git provider integrations.

dke-scanner-agent source-code [OPTIONS]

Options​

OptionDescriptionDefault
-p, --path <PATH>Local path to scan-
--gitlab-project <PROJECT>GitLab project (group/project)-
--gitlab-token <TOKEN>GitLab tokenGITLAB_TOKEN env var
--gitlab-url <URL>GitLab base URLhttps://gitlab.com
--github-repo <REPO>GitHub repository (owner/repo)-
--github-token <TOKEN>GitHub tokenGITHUB_TOKEN env var
--github-url <URL>GitHub base URLhttps://api.github.com
--azdo-org <ORG>Azure DevOps organization-
--azdo-project <PROJECT>Azure DevOps project-
--azdo-repo <REPO>Azure DevOps repository-
--azdo-token <TOKEN>Azure DevOps PAT tokenAZDO_TOKEN env var
--azdo-url <URL>Azure DevOps base URLhttps://dev.azure.com
--branch <BRANCH>Branch to scanmain/master
--languages <LANGS>Languages to scan (comma-separated)Auto-detect
--max-depth <N>Maximum directory depth10
-o, --output <FILE>Output file path-
--format <FMT>Output format: json, yaml, terminal, htmljson

Examples​

# Scan local directory
dke-scanner-agent source-code --path /path/to/code

# Scan GitLab project
dke-scanner-agent source-code \
--gitlab-project mygroup/myproject \
--gitlab-token $GITLAB_TOKEN

# Scan GitHub repository
dke-scanner-agent source-code \
--github-repo owner/repo \
--github-token $GITHUB_TOKEN

# Scan Azure DevOps repository
dke-scanner-agent source-code \
--azdo-org myorg \
--azdo-project myproject \
--azdo-repo myrepo \
--azdo-token $AZDO_TOKEN

# Scan specific branch
dke-scanner-agent source-code \
--github-repo owner/repo \
--github-token $GITHUB_TOKEN \
--branch develop

# Scan specific languages
dke-scanner-agent source-code \
--path . \
--languages "java,python,go"

# Self-hosted GitLab
dke-scanner-agent source-code \
--gitlab-project group/project \
--gitlab-url https://gitlab.company.com \
--gitlab-token $TOKEN

# GitHub Enterprise
dke-scanner-agent source-code \
--github-repo org/repo \
--github-url https://github.company.com/api/v3 \
--github-token $TOKEN

# Save results
dke-scanner-agent source-code --path . --output scan.json --format json

Environment Variables​

  • GITLAB_TOKEN: GitLab personal access token
  • GITHUB_TOKEN: GitHub personal access token
  • AZDO_TOKEN: Azure DevOps personal access token (PAT)

Supported Languages​

The scanner auto-detects and analyzes cryptographic usage in:

Languages

  • Java
  • Python
  • Go
  • JavaScript/TypeScript
  • C/C++
  • C#
  • Ruby
  • PHP
  • And more...

Note

Compliance-framework checking and ServiceNow publishing are available in DuoKey CPM, but are not standalone dke-scanner-agent CLI commands. Compliance checking runs against saved scan results inside the product; ServiceNow integration is configured server-side. See ServiceNow Integration for details.


dke-scanner-agent cbom​

Export scan results as CBOM (Cryptography Bill of Materials).

dke-scanner-agent cbom [OPTIONS] --input <FILE>

Options​

OptionDescriptionDefault
-i, --input <FILE>(Required) Scan results file (JSON) to convert-
-o, --output <FILE>Output file for CBOM<input>-cbom.json
--app-name <NAME>Application name for CBOM metadataFrom scan
--app-version <VER>Application version for CBOM metadata1.0
--prettyPretty-print JSON outputtrue

Description​

Generates a CycloneDX 1.7 CBOM (Cryptography Bill of Materials) from scan results. The CBOM format provides:

  • Standardized cryptographic asset inventory
  • Component relationships and dependencies
  • Compliance with CycloneDX specification
  • Integration with SBOM tools and workflows

Examples​

# Basic CBOM generation
dke-scanner-agent cbom --input scan-results.json

# Custom output file
dke-scanner-agent cbom \
--input scan-results.json \
--output app-cbom.json

# With application metadata
dke-scanner-agent cbom \
--input scan.json \
--app-name "Payment Gateway" \
--app-version "2.5.1" \
--output payment-gateway-cbom.json

# Compact JSON (no pretty print)
dke-scanner-agent cbom \
--input scan.json \
--pretty false

# Complete workflow
dke-scanner-agent filesystem --path /app --output scan.json
dke-scanner-agent cbom --input scan.json --app-name "MyApp" --app-version "1.0"

CBOM Output​

The generated CBOM includes:

  • Components: Cryptographic assets (algorithms, certificates, keys, protocols)
  • Dependencies: Relationships between components
  • Metadata: Timestamps, tool information, application details
  • Properties: Risk scores, quantum vulnerability status, compliance info

Validation​

The tool automatically validates the generated CBOM against CycloneDX 1.7 specification:

  • Format and version compliance
  • Component structure validation
  • Cryptographic properties validation
  • Asset type consistency

dke-scanner-agent ssh​

Discover SSH keys from the ssh-agent, ~/.ssh, /etc/ssh host keys and the Cockpit-managed key directory, classifying each by algorithm and quantum vulnerability.

dke-scanner-agent ssh [OPTIONS]

Options​

OptionDescriptionDefault
--no-agentSkip keys held by a running ssh-agentfalse
--no-user-keysSkip user keys under ~/.sshfalse
--no-server-keysSkip host keys under /etc/sshfalse
--format <FMT>json or summaryjson
-o, --output <FILE>Write to a file instead of stdout-

Examples​

# Every source
dke-scanner-agent ssh --format json -o ssh.json

# Host keys only, on a server where no user logs in interactively
dke-scanner-agent ssh --no-agent --no-user-keys --format summary

dke-scanner-agent qrs​

Compute the Quantum Risk Score from a scan JSON produced by any other verb: the 0-100 composite, its band, the four weighted signals, and optionally the full editorial HTML report the cockpit UI exports.

dke-scanner-agent qrs --input <FILE> [OPTIONS]

Options​

OptionDescriptionDefault
--input <FILE>(Required) A scan JSON written earlier by filesystem, domain, source-code, …-
--format <FMT>text, json or htmltext
-o, --output <FILE>Output file. Required when --format html-
-j, --jurisdiction <CODE>Scoring profile: ae|uae, ksa|sa, eu|eea, uk|gb, ch, us, us_nss|cnsa20, jp|japan, ca|canada, au|australia, ma|morocco, dz|algeriaglobal
--scan-number <N>Which scan to read when the input holds several1

Examples​

# Score a PQC scan
dke-scanner-agent domain --target example.com --pqc --format json -o pqc-scan.json
dke-scanner-agent qrs --input pqc-scan.json

# Machine-readable, for a dashboard
dke-scanner-agent qrs --input pqc-scan.json --format json

# Full editorial report, then print to PDF from the browser
dke-scanner-agent qrs --input pqc-scan.json --format html -o qrs.html

# Score against a national profile rather than the global default
dke-scanner-agent qrs --input pqc-scan.json --jurisdiction ksa
Note

The HTML report is too large for stdout, so --format html refuses to run without -o. The jurisdiction changes the scoring profile and the regulatory framing of the report — us_nss (equivalently cnsa20) applies the NSA CNSA 2.0 mandate rather than the civilian profile.


dke-scanner-agent fortinet​

Scan a FortiGate / FortiOS device through its REST API: installed certificates, CA certificates, IPSec VPN and SSL-VPN profiles.

dke-scanner-agent fortinet --target <URL> --api-token <TOKEN> [OPTIONS]

Options​

OptionDescriptionDefault
--target <URL>(Required) Device base URL-
--api-token <TOKEN>(Required) FortiOS REST API token-
--verify-tlsVerify the device certificatefalse
--timeout-secs <SECS>Per-request timeout-
--format <FMT>json or summaryjson
-o, --output <FILE>Write to a file instead of stdout-

Examples​

dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN> -o fw.json

# Enforce certificate verification against a device with a trusted certificate
dke-scanner-agent fortinet --target https://fw.example.com --api-token <TOKEN> --verify-tls

dke-scanner-agent jfrog​

Scan a JFrog Artifactory instance — optionally with Xray — for cryptographic material inside published artifacts.

dke-scanner-agent jfrog --base-url <URL> --api-key <KEY> [OPTIONS]

Options​

OptionDescriptionDefault
--base-url <URL>(Required) Artifactory base URL-
--api-key <KEY>(Required) Artifactory API key-
--repos <REPO>Repository to scan; repeat the flag for severalall
--max-artifacts-per-repo <N>Cap the artifacts inspected per repository-
--no-verify-tlsSkip TLS verificationfalse
--xray-url <URL>Xray base URL, to enrich findings-
--format <FMT>json or summaryjson
-o, --output <FILE>Write to a file instead of stdout-

Examples​

dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> -o jfrog.json

# Two repositories, bounded so a first run finishes quickly
dke-scanner-agent jfrog --base-url https://art.example.com --api-key <KEY> \
--repos libs-release --repos docker-local \
--max-artifacts-per-repo 200

dke-scanner-agent terraform​

Scan Terraform state files and HCL for cryptographic resources: KMS keys, TLS certificates and provider configuration.

dke-scanner-agent terraform --path <DIR> [OPTIONS]

Options​

OptionDescriptionDefault
--path <DIR>(Required) Directory to scan; repeat the flag for several-
--no-recurseDo not descend into subdirectoriesfalse
--no-stateSkip .tfstate filesfalse
--no-hclSkip .tf source filesfalse
--format <FMT>json or summaryjson
-o, --output <FILE>Write to a file instead of stdout-

Examples​

dke-scanner-agent terraform --path ./infra -o tf.json

# State only — useful when the HCL lives in another repository
dke-scanner-agent terraform --path ./infra --no-hcl --format summary

dke-scanner-agent cloud​

Scan a cloud KMS for key material.

dke-scanner-agent cloud --aws [OPTIONS]

Options​

OptionDescriptionDefault
--awsScan AWS KMSfalse
--regions <REGION>Region to scan; repeat the flag for severalaccount default
--credentials-file <FILE>Credentials file instead of the ambient chain-
--access-key-id <ID>Explicit access key ID-
--secret-access-key <KEY>Explicit secret access key-
--format <FMT>json or summaryjson
-o, --output <FILE>Write to a file instead of stdout-

Examples​

# Ambient credentials (instance role, profile, environment)
dke-scanner-agent cloud --aws --regions eu-central-1,us-east-1 -o kms.json
Note

AWS KMS is fully implemented. Azure Key Vault and GCP KMS currently emit a placeholder finding rather than a real inventory — treat their output as a stub, not as coverage.


dke-scanner-agent vault​

Scan a cockpit-managed vault for quantum-vulnerable keys. This verb is a thin client: the scan runs server-side, because it needs the cockpit database and tenant context.

dke-scanner-agent vault --vault-id <UUID> --token <USER_JWT> [OPTIONS]

Options​

OptionDescriptionDefault
--vault-id <UUID>(Required) Vault to scan-
--token <JWT>(Required) User session JWT — not the agent API key-
--server <URL>Cockpit URL, when it differs from the enrolled onefrom config
--include-metadataInclude key metadata in the responsefalse
--config <FILE>Alternate agent config file~/.dke/agent.toml

Examples​

dke-scanner-agent vault --vault-id 0f1c2d3e-4a5b-6c7d-8e9f-0a1b2c3d4e5f --token <USER_JWT>
Note

This is the one verb that authenticates with a user JWT rather than the enrolled agent key: the scan API is gated by the Operations.Pqc.Scan.Create permission, which belongs to a user, not to an agent.


dke-scanner-agent enroll​

Register the agent with a cockpit and persist the issued API key to ~/.dke/agent.toml (mode 0600 on Unix). Run this once before agent or upload-scan.

dke-scanner-agent enroll --server <URL> --token <ENROLL_TOKEN>

Options​

OptionDescriptionDefault
--server <URL>(Required) Cockpit base URL-
--token <TOKEN>Single-use bundle token from the cockpit Generate-installer flow. Tenant-bound, platform-bound, expires in 1 hour-
--user-token <JWT>Legacy path: a full user session JWT-
--pin-spki-sha256 <HASH>Pin the cockpit certificate by SPKI SHA-256-
--expected-sha256 <HASH>Expected hash of the downloaded bundle-
--config <FILE>Write the config somewhere other than ~/.dke/agent.toml~/.dke/agent.toml
--forceOverwrite an existing enrolmentfalse

Examples​

dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN>

# Re-enrol a host that already has a config
dke-scanner-agent enroll --server https://cockpit.example.com --token <ENROLL_TOKEN> --force
Note

Exactly one of --token and --user-token must be given. Prefer the bundle token: it is single-use and short-lived, where a session JWT carries the full rights of the user who minted it.


dke-scanner-agent upload-scan​

Run a one-shot TLS scan and post the result to the cockpit instead of printing it. Targets appear on the CBOMs page tagged with this agent as their creator.

dke-scanner-agent upload-scan --target <TARGET> [OPTIONS]

Options​

OptionDescriptionDefault
--target <TARGET>(Required) Target hosts, comma-separated-
--ports <PORTS>Ports to scan, comma-separated443
--timeout <SECS>Connection timeout per target10
--concurrency <N>Maximum concurrent connections20
--retries <N>Retries per target1
--app-name <NAME>Application name recorded against the findings-
--server <URL>Cockpit URL, when it differs from the enrolled onefrom config
--config <FILE>Alternate agent config file~/.dke/agent.toml

Examples​

dke-scanner-agent upload-scan --target example.com --app-name my-service

# Point a one-off run at another cockpit without re-enrolling
dke-scanner-agent upload-scan --target example.com --server https://cockpit-test.example.com
Note

Requires a prior enroll: the agent ID and API key are read from the config, not passed on the command line.


dke-scanner-agent info​

Print the agent build, its capabilities and the verbs available in this build. Useful when a command is missing: several scanners sit behind build features.

dke-scanner-agent info

Options​

OptionDescriptionDefault

Examples​

dke-scanner-agent info

Output Formats​

All scanning commands support multiple output formats:

FormatCommandDescription
JSON (Default)--format jsonStructured JSON output for programmatic processing
YAML--format yamlHuman-readable YAML format
HTML--format htmlInteractive HTML report with visualizations
Terminal--format terminalPretty-printed terminal output with colors (interactive use)
SARIF (CI Only)--format sarifStatic Analysis Results Interchange Format for CI/CD

Common Workflows​

# Step 1: Host inventory scan on each server
ssh server1 "sudo dke-scanner-agent inventory --output server1.json"
ssh server2 "sudo dke-scanner-agent inventory --output server2.json"

# Step 2: Filesystem scan on shared storage
dke-scanner-agent filesystem --path /mnt/shared --output shared.json

# Step 3: Domain scan for external endpoints
dke-scanner-agent domain --target api.example.com --pqc --output api-scan.json

Review the combined results in the DuoKey Cockpit's PQC Readiness module.


Exit Codes​

CodeMeaning
0Success
1General error or findings above threshold (CI mode)
2Scan error or invalid arguments
3Permission denied

Troubleshooting​


Environment Variables​

Global environment variables that affect scanner behavior:

VariableDescriptionDefault
GITLAB_TOKENGitLab personal access token-
GITHUB_TOKENGitHub personal access token-
AZDO_TOKENAzure DevOps PAT token-
PQC_CI_IDCMDB CI identifier (sys_id)-
PQC_CI_NAMECMDB CI human-readable name-
PQC_CI_TYPECI type in CMDBApplication
PQC_CMDB_ADAPTERCMDB system (servicenow, jira, generic_rest, none)none
PQC_ENVIRONMENTEnvironment classificationunknown
PQC_BUSINESS_UNITBusiness unit-
PQC_OWNEROwner team or email-
PQC_TAGSComma-separated tags-
PQC_DOMAIN_MAPPath to domain mapping YAML-

Examples​

# Set GitLab token
export GITLAB_TOKEN="glpat-xxxxxxxxxxxxxxxxxxxx"

# Set CMDB context
export PQC_CI_ID="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6"
export PQC_CI_NAME="Payment Gateway"
export PQC_ENVIRONMENT="production"

# Use environment variables
dke-scanner-agent source-code --gitlab-project mygroup/myproject

Best Practices​

Recommended Practices

Regular Scanning

Schedule daily inventory scans via cron

Secure Credentials

Use environment variables, not command-line arguments

CI/CD Integration

Add scans to your deployment pipeline

Compliance Reporting

Generate quarterly compliance reports


Performance Tips​



Note

This documentation reflects the current version of the PQC Scanner CLI. For version-specific changes, see the project changelog. Last Updated: January 2025 | Scanner Version: 1.0+ | API Version: v1