tlsx
Fast and configurable TLS grabber focused on TLS based data collection.
Name:tlsx
Category:Recon
Publisher:trickest-mhmdiaa
Created:6/29/2022
Container:
quay.io/trickest/tlsx:v1.1.7
Output Type:
License:Unknown
Source:View Source
Parameters
-dns
display unique hostname from SSL certificate response-ja3
display ja3 fingerprint hash (using ztls)-sni
tls sni hostname to use-hash
display certificate fingerprint hashes (md5,sha1,sha256)-host
target host(s) to scan (comma-separated)-jarm
display jarm fingerprint hash-json
json format output-list
target list to scan-port
target port to connect (default 443)-delay
duration to wait between each connection per thread (eg: 200ms, 1s)-retry
number of retries to perform for failures (default 3)-cacert
client certificate authority file-cipher
display used cipher-config
tlsx configuration file-serial
display certificate serial number-silent
display silent output-expired
display validity status of certificate-revoked
display host with revoked certificate-timeout
tls connection timeout in seconds (default 5)-verbose
display verbose output-hardfail
strategy to use if encountered errors while checking revocation status-resolvers
list of resolvers to use-resp-only
display tls response only-scan-mode
tls connection mode to use (ctls, ztls, openssl, auto) (default auto)-tls-chain
display tls chain in json output-untrusted
display host with untrusted certificate-ip-version
ip version to use (4, 6) (default 4)-mismatched
display host with mismatched certificate-random-sni
use random sni when empty-all-ciphers
send all ciphers as accepted inputs (default true)-certificate
include certificates in json output (PEM format)-cipher-enum
enumerate and display supported cipher-cipher-type
ciphers types to enumerate. possible values: all/secure/insecure/weak (comma-separated) (default all)-concurrency
number of concurrent threads to process (default 300)-max-version
maximum tls version to accept (ssl30,tls10,tls11,tls12,tls13)-min-version
minimum tls version to accept (ssl30,tls10,tls11,tls12,tls13)-self-signed
display status of self-signed certificate-tls-version
display used tls version-verify-cert
enable verification of server certificate-cipher-input
ciphers to use with tls connection-client-hello
include client hello in json output (ztls mode only)-cn
display subject common names-health-check
run diagnostic check up-probe-status
display tls probe status-scan-all-ips
scan all ips for a host (default false)-server-hello
include server hello in json output (ztls mode only)-version-enum
enumerate and display supported tls versions-pre-handshake
enable pre-handshake tls connection (early termination) using ztls-wildcard-cert
display host with wildcard ssl certificate-openssl-binary
OpenSSL Binary Path-cipher-concurrency
cipher enum concurrency for each target (default 10)-san
display subject alternative names-so
display subject organization name