Filesystem Mode - File & Keystore Scanner
Filesystem Mode - File & Keystore Scanner
Recursive discovery of certificates, keystores, and private keys across directories and OS certificate stores
Implemented - Available in v1.0.0. Built in Rust using walkdir + rayon for parallel traversal and x509-parser for certificate parsing.
Overview
Filesystem mode performs recursive scanning of directories to discover certificates, keystores, and private keys. It uses parallel file traversal powered by walkdir and rayon, and parses certificates with the x509-parser crate. In addition to file-based scanning, it can optionally enumerate the Windows Certificate Store (via the schannel crate, covering LocalMachine and CurrentUser stores).
How It Works
Filesystem Mode Flow
Directory Traversal
Recursively walks directories using walkdir with configurable max depth
Extension Filtering
Filters files by extension (.jks, .p12, .pfx, .pem, .crt, .cer, .key) and excludes configured paths
Parallel Processing
Processes discovered files in parallel using rayon (default 4 threads)
Format-Specific Parsing
Selects appropriate parser: PEM, DER, PKCS#12/PFX, JKS/JCEKS, or private key
Certificate Analysis
Parses X.509 certificates via x509-parser to extract algorithms, key sizes, and expiry
Risk Scoring
Calculates quantum vulnerability scores for each discovered asset
Supported Formats
PEM Format
- X.509 certificates (.pem, .crt, .cer)
- Private keys (RSA, EC, generic PKCS#8)
- Public keys
- Multiple PEM blocks per file
DER Format
- Binary-encoded X.509 certificates (.der, .cer)
- Binary-encoded private keys
- Parsed via x509-parser from_der
PKCS#12 / PFX
- .p12 and .pfx files
- Certificate extraction
- Private key detection
- Password-protected bundles
Java Keystores
- JKS (Java KeyStore)
- JCEKS (Java Cryptography Extension KeyStore)
- Alias enumeration
- Password-protected keystore support
Private Keys
- RSA private keys
- EC private keys
- PKCS#8 wrapped keys
- Standalone .key files
OS Certificate Stores
- Windows Certificate Store (schannel crate): LocalMachine & CurrentUser stores
- Enabled via --scan-windows-certstore (choose the store with --certstore-name: MY, ROOT, CA, TRUST, or ALL)
Usage
Basic Scanning
# Scan current directory (default --path is .; scans are recursive with no --recursive flag)
dke-scanner-agent filesystem
# Scan a specific directory
dke-scanner-agent filesystem --path /opt/applications
# Scan with output to a file
dke-scanner-agent filesystem --path /etc/ssl --output certs-report.json
# Scan and output in YAML format
dke-scanner-agent filesystem --path /srv --format yaml
Command-Line Options
| Flag | Description | Default | Required |
|---|---|---|---|
| --path <PATH> | Directory path to scan (recursive by default; there is no --recursive flag) | . (current directory) | No |
| --max-depth <N> | Maximum recursion depth (0 = unlimited) | 10 | No |
| --follow-symlinks | Follow symbolic links during the walk | false | No |
| --extensions <EXT> | File extensions to scan (comma-separated) | .jks,.p12,.pfx,.pem,.crt,.cer,.key | No |
| --exclude <PATHS> | Directories to exclude (comma-separated) | node_modules,.git,target | No |
| --threads <N> | Number of parallel processing threads | 4 | No |
| --scan-windows-certstore | Scan Windows Certificate Store (LocalMachine and CurrentUser) | false | No |
| --certstore-name <NAME> | Windows certstore to scan: MY, ROOT, CA, TRUST, or ALL | ALL | No |
| --output <FILE> | Output file path | stdout | No |
| --format <FMT> | Output format: json, yaml, terminal, or html | json | No |
Advanced Examples
Architecture
Filesystem mode uses walkdir for recursive directory traversal and rayon for parallel file processing:
- Walk the directory tree up to the configured max depth (default 10), keeping files that match the configured extensions and are not in an excluded path.
- Parse the matching files in parallel across the configured thread count.
- Optionally enumerate the Windows certificate store (LocalMachine + CurrentUser) when
--scan-windows-certstoreis set.
Certificate parsing is handled by the x509-parser crate, which provides full X.509 certificate decoding from both PEM and DER formats.
Example Output
{
"scan_metadata": {
"scanner_version": "1.0.0",
"scan_mode": "filesystem",
"scan_date": "2025-01-30T15:45:22Z",
"scan_path": "/opt/applications",
"recursive": true,
"max_depth": 10
},
"summary": {
"files_scanned": 45678,
"keystores_found": 23,
"certificates_found": 156,
"private_keys_found": 67,
"total_findings": 246
},
"findings": [
{
"id": "fs-001",
"type": "keystore",
"file_path": "/opt/tomcat/conf/keystore.jks",
"format": "JKS",
"password_protected": true,
"certificates": [
{
"alias": "tomcat-ssl",
"subject": "CN=app.example.com",
"issuer": "CN=Example CA",
"not_after": "2025-12-31T23:59:59Z",
"algorithm": "RSA",
"key_size": 2048,
"has_private_key": true,
"quantum_vulnerable": true
}
],
"risk_assessment": {
"quantum_risk_score": 8.0,
"priority": "P1",
"severity": "HIGH"
}
},
{
"id": "fs-002",
"type": "certificate",
"file_path": "/etc/ssl/certs/server.crt",
"format": "PEM",
"certificate": {
"subject": "CN=www.example.com",
"algorithm": "ECDSA",
"curve": "P-256",
"quantum_vulnerable": true
},
"risk_assessment": {
"quantum_risk_score": 8.0,
"priority": "P1",
"severity": "HIGH"
}
}
]
}
Default Behavior
By default, filesystem mode scans the current directory (.) recursively up to 10 levels deep with 4 threads. It looks for files with extensions .jks, .p12, .pfx, .pem, .crt, .cer, and .key, while automatically excluding node_modules, .git, and target directories.