Skip to main content

TLS Probe

Applies to:
Single Host + PortTLS 1.2 / TLS 1.3Cipher Suite & Key ExchangeCertificate Chain Inspection

Overview​

The TLS Probe source targets one specific TLS endpoint defined by a host and port. It performs the TLS handshake and inspects the negotiated protocol version, cipher suite, and key exchange algorithm, then extracts and analyzes the full certificate chain. It is a fast, focused alternative to Domain mode when you only need to assess a single endpoint and do not require sub-domain discovery.

What It Scans​

ItemDetails
Protocol versionNegotiated TLS version (TLS 1.2 / TLS 1.3)
Cipher suiteThe cipher suite agreed during the handshake
Key exchangeThe key exchange / named group used for the session
Certificate chainLeaf, intermediate, and root certificates with algorithm, key size, and validity
Quantum riskPer-certificate quantum vulnerability assessment

When to Use​

🎯

Single Endpoint Check

Quickly assess one specific host and port without scanning a whole domain

⚡

Fast Spot Checks

Validate a TLS configuration change on a known service immediately

Tip

Use TLS Probe when you already know the exact endpoint to check. If you also need to discover and scan sub-domains of a domain, use Domain mode instead.

How to Run​

Run a TLS Probe from the Cockpit scan wizard:

1

Open Run a Scan

In the Cockpit, go to Run a Scan.

2

Select the source

In Step 1 (Source), choose TLS Probe.

3

Enter the endpoint

Provide the target host and port, then start the scan and review the findings.