Open-source post-quantum migration inventory and CycloneDX 1.6 CBOM toolkit. Collect certificates, SSH keys, crypto libraries and config files from osquery, endpoint connectors and CT logs, grade them against 40 deterministic rules, and export a signed CBOM. No calls home, no telemetry, one docker compose up -d.
$ git clone https://github.com/net4n6-dev/cipherflag.git && cd cipherflag && docker compose up -d
Two containers: postgres:16 and cipherflag. Console and API on port 8443.
PKI Constellation — your CA hierarchy in 3D, with an automatic 2D fallback
# distributed by Tanium, SentinelOne (RSO) # or Absolute (Reach); the matching connector # collects and parses their NDJSON output bash PowerShell discover-certs.sh discover-certs.ps1 discover-configs.sh discover-configs.ps1 discover-libraries.sh discover-libraries.ps1 discover-ssh-keys.sh discover-ssh-keys.ps1
# generate an Ed25519 key pair $ cipherflag generate-signing-key --out cbom-signing # writes cbom-signing.key and cbom-signing.pub $ cipherflag sign-cbom --bom estate.cdx.json \ --key cbom-signing.key $ cipherflag verify-cbom --bom estate.cdx.json \ --trusted-key cbom-signing.pub
CipherFlag CE brings certificates, SSH keys, crypto libraries and crypto-relevant config files into one asset model, whether they arrive from osquery, an endpoint connector, a CT log, a trust-store scan or the ingest API.
One ingest API, POST /api/v1/ingest, for X.509 certificates, SSH keys, crypto libraries and config files. Hosts are resolved and deduplicated with provenance kept, and bearer agent tokens cover unattended ingest.
POST /api/v1/ingest/osquery takes results from a five-query pack: certificates, user SSH keys, authorized keys, and crypto packages from deb and rpm package databases.
Microsoft Defender for Endpoint, SentinelOne, Tanium and Absolute, plus Netwrix for AD CS events. Each connector is off by default and enabled in the config file.
Four bash and four PowerShell scripts for certificates, SSH keys, crypto libraries and config files, distributed by Tanium, SentinelOne (RSO) or Absolute (Reach). The matching connector collects and parses their output.
cipherflag scan-truststore --host-id <uuid> runs a one-shot scan of the local host's OS CA bundles, JVM cacerts and language-runtime CA stores, attributed to a host in the inventory.
Watch your domains in crt.sh, Static CT API / Sunlight logs or SSLMate CertSpotter, or run a multi-provider mode that unions all three with per-source provenance. Off by default; set up in the config file.
Every certificate, SSH key, crypto library and crypto config is scored from 0 to 100 and given a letter grade. Findings carry severity, category, point deduction and remediation guidance. Library CVEs are matched against NVD/OSV data, with a seed catalog of 37 crypto-library CVEs such as Heartbleed and DROWN; end-of-life and FIPS-validation findings link to their source.
Each asset is classified for post-quantum readiness, checked against four compliance frameworks, and exported as a CycloneDX 1.6 CBOM you can sign, verify and push to the tools you already run.
Algorithms are sorted into eight categories (asymmetric, symmetric, hash, signature, KEX, KDF, PQC-KEM, PQC-SIG) and each is classified as vulnerable, weakened, hybrid or quantum-safe.
Per-asset status against NIST SP 800-131A Rev 2, NSA CNSA 2.0, FIPS 140-3 (algorithm allowlist) and EU NIS2, with framework-specific findings.
Export a CBOM for the whole estate, or for a scope filtered by hostname pattern, host or asset type. An admin-only import takes foreign CycloneDX BOMs and re-classifies their algorithms against the same taxonomy.
Sign CBOMs with Ed25519 (JSF) and check them with verify-cbom. Push on a schedule to a file, an HTTP endpoint, S3 (AWS or S3-compatible), Splunk HEC, or syslog (RFC 5424 + CEF, over TLS).
Push the inventory to Venafi TPP or Venafi Cloud. Configuration changes, including credentials and interval, apply without a restart.
Sidebar and top-bar shell with dark, light and system themes. A 3D PKI Constellation with automatic 2D fallback, a CVE-colored library treemap and SSH key analytics, all updated live over Server-Sent Events.
Two containers, postgres:16 and cipherflag, and nothing beyond Docker. The image, ghcr.io/net4n6-dev/cipherflag-ce, is tagged by version and latest; compose can also build it from source (Go 1.25+). Local accounts with admin and viewer roles, plus agent tokens for unattended ingest. No calls home, no telemetry.
CipherFlag EE is the commercial edition from Cyber Flag Inc. It adds discovery sources, scoring, compliance frameworks and program tooling that CE does not include.
Three commands to a running console. Apache 2.0, no telemetry, no commercial license required.