Community Edition · v2.3.0 · Apache 2.0

Know your cryptography before you migrate it

Open-source post-quantum migration inventory and CycloneDX 1.6 CBOM toolkit. Collect certificates, SSH keys, crypto libraries and config files from osquery, endpoint connectors and CT logs, grade them against 40 deterministic rules, and export a signed CBOM. No calls home, no telemetry, one docker compose up -d.

Get Started View on GitHub
$ git clone https://github.com/net4n6-dev/cipherflag.git && cd cipherflag && docker compose up -d

Two containers: postgres:16 and cipherflag. Console and API on port 8443.

PKI Root DigiCert Amazon Let's Encrypt Internal CA GlobalSign Sectigo

PKI Constellation — your CA hierarchy in 3D, with an automatic 2D fallback

See It In Action
Scripts in. Signed CBOM out.
discovery-packs/scripts
# distributed by Tanium, SentinelOne (RSO)
# or Absolute (Reach); the matching connector
# collects and parses their NDJSON output

bash                    PowerShell
discover-certs.sh       discover-certs.ps1
discover-configs.sh     discover-configs.ps1
discover-libraries.sh   discover-libraries.ps1
discover-ssh-keys.sh    discover-ssh-keys.ps1
cbom signing
# generate an Ed25519 key pair
$ cipherflag generate-signing-key --out cbom-signing
# writes cbom-signing.key and cbom-signing.pub

$ cipherflag sign-cbom --bom estate.cdx.json \
    --key cbom-signing.key
$ cipherflag verify-cbom --bom estate.cdx.json \
    --trusted-key cbom-signing.pub
Discovery
One inventory for every crypto asset

CipherFlag CE brings certificates, SSH keys, crypto libraries and crypto-relevant config files into one asset model, whether they arrive from osquery, an endpoint connector, a CT log, a trust-store scan or the ingest API.

Unified Asset Model

One ingest API, POST /api/v1/ingest, for X.509 certificates, SSH keys, crypto libraries and config files. Hosts are resolved and deduplicated with provenance kept, and bearer agent tokens cover unattended ingest.

osquery Webhook

POST /api/v1/ingest/osquery takes results from a five-query pack: certificates, user SSH keys, authorized keys, and crypto packages from deb and rpm package databases.

Endpoint & Directory Connectors

Microsoft Defender for Endpoint, SentinelOne, Tanium and Absolute, plus Netwrix for AD CS events. Each connector is off by default and enabled in the config file.

Discovery Scripts

Four bash and four PowerShell scripts for certificates, SSH keys, crypto libraries and config files, distributed by Tanium, SentinelOne (RSO) or Absolute (Reach). The matching connector collects and parses their output.

Trust-Store Scan

cipherflag scan-truststore --host-id <uuid> runs a one-shot scan of the local host's OS CA bundles, JVM cacerts and language-runtime CA stores, attributed to a host in the inventory.

Certificate Transparency

Watch your domains in crt.sh, Static CT API / Sunlight logs or SSLMate CertSpotter, or run a multi-provider mode that unions all three with per-source provenance. Off by default; set up in the config file.

40 rules. One grade.

Every certificate, SSH key, crypto library and crypto config is scored from 0 to 100 and given a letter grade. Findings carry severity, category, point deduction and remediation guidance. Library CVEs are matched against NVD/OSV data, with a seed catalog of 37 crypto-library CVEs such as Heartbleed and DROWN; end-of-life and FIPS-validation findings link to their source.

A+ 95–100 A 85–94 B 70–84 C 50–69 D 20–49 F <20
23 certificate 8 SSH key 5 crypto library 4 crypto config
Expiry and validity period
Certificate key size (RSA, ECDSA)
SHA-1 and MD5 signatures
Self-signed end-entity certs
Revocation (CRL, OCSP)
Signed Certificate Timestamps
Wildcard scope
Automated issuance (ACME)
SSH key type, size and age
SSH passphrase and root access
Library CVEs, end-of-life, FIPS, PQC support
OpenSSL, sshd and Java algorithm config
Classify, Evaluate, Export
From inventory to evidence

Each asset is classified for post-quantum readiness, checked against four compliance frameworks, and exported as a CycloneDX 1.6 CBOM you can sign, verify and push to the tools you already run.

PQC Taxonomy

Algorithms are sorted into eight categories (asymmetric, symmetric, hash, signature, KEX, KDF, PQC-KEM, PQC-SIG) and each is classified as vulnerable, weakened, hybrid or quantum-safe.

Compliance Evaluation

Per-asset status against NIST SP 800-131A Rev 2, NSA CNSA 2.0, FIPS 140-3 (algorithm allowlist) and EU NIS2, with framework-specific findings.

CycloneDX 1.6 CBOM

Export a CBOM for the whole estate, or for a scope filtered by hostname pattern, host or asset type. An admin-only import takes foreign CycloneDX BOMs and re-classifies their algorithms against the same taxonomy.

Signing & Scheduled Push

Sign CBOMs with Ed25519 (JSF) and check them with verify-cbom. Push on a schedule to a file, an HTTP endpoint, S3 (AWS or S3-compatible), Splunk HEC, or syslog (RFC 5424 + CEF, over TLS).

Venafi Export

Push the inventory to Venafi TPP or Venafi Cloud. Configuration changes, including credentials and interval, apply without a restart.

Operator Console

Sidebar and top-bar shell with dark, light and system themes. A 3D PKI Constellation with automatic 2D fallback, a CVE-colored library treemap and SSH key analytics, all updated live over Server-Sent Events.

Under the Hood
Built for operators

Two containers, postgres:16 and cipherflag, and nothing beyond Docker. The image, ghcr.io/net4n6-dev/cipherflag-ce, is tagged by version and latest; compose can also build it from source (Go 1.25+). Local accounts with admin and viewer roles, plus agent tokens for unattended ingest. No calls home, no telemetry.

Go 1.25 PostgreSQL 16 SvelteKit 2 three.js + Threlte D3.js Cytoscape.js Server-Sent Events CycloneDX 1.6 Docker Compose
CipherFlag EE

CipherFlag EE is the commercial edition from Cyber Flag Inc. It adds discovery sources, scoring, compliance frameworks and program tooling that CE does not include.

Passive network discovery with Zeek and Corelight
Active TLS scanning
AWS, Azure and Azure Key Vault
Container image scanning
CrowdStrike Falcon, Velociraptor, Forescout, Rapid7
Infoblox, BlueCat, Saviynt
Prisma Cloud and Wiz CNAPP enrichment
Microsoft Purview data-sensitivity ranking
49 rules across five asset types plus CNAPP
Eight frameworks, adding PCI DSS 4.0 and FIPS 203/204/205
Blast-radius risk prioritization
PQC dispositions, waivers and migration waves
Jira and ServiceNow ticketing
55-tool MCP server for AI agents
Hash-chained audit log with SIEM forwarding
SSO, TOTP and WebAuthn MFA
Air-gapped install
Commercial support

Build your crypto inventory

Three commands to a running console. Apache 2.0, no telemetry, no commercial license required.

Get Started Browse Source