TLSX
Purpose
TLSX collects TLS certificate information and emits certificate assets.
Plugin Information
Plugin ID: tlsx
Category: TLS Discovery
Plugin Type: custom
Execution: active CLI TLS probe
Default State: enabled
Default Profiles:
deeptls_auditrecon_expanded
Input Scope
Accepted asset types:
webappdomainsubdomainserviceip
Required metadata:
- None
Produces targets:
- Newline-delimited scope values on stdin.
Output
Creates assets:
certificate
Creates vulnerabilities:
- None
May enrich:
- Certificate assets with fingerprint, serial number, subject, issuer, SAN, validity, host, IP, port, and scheme metadata.
- Service assets with observed negotiated TLS version when TLSX reports a TLS version and a concrete IP/port is available.
Metadata:
subject_cn: certificate subject common name.issuer_cn: issuer common name.serial_number: certificate serial number when emitted.san: subject alternative names.not_before: certificate start time from TLSX.not_after: certificate expiry time from TLSX.expired: expiry flag.host: parsed host.ip: reported or inferred IP.port: parsed or inferred port.scheme: parsed URL scheme.source:tlsx.
Canonical observed state:
metadata.asset_info.certificate.fingerprint_sha256.metadata.asset_info.certificate.serial_number.metadata.asset_info.certificate.subject.common_name.metadata.asset_info.certificate.subject.organization,organizational_unit,country,locality, andprovincewhen emitted by TLSX.metadata.asset_info.certificate.issuer.common_name.metadata.asset_info.certificate.issuer.organization,organizational_unit,country,locality, andprovincewhen emitted by TLSX.metadata.asset_info.certificate.sans.metadata.asset_info.certificate.validity.not_before.metadata.asset_info.certificate.validity.not_after.metadata.asset_info.certificate.validity.expired.metadata.asset_info.tls.observed_versionon Service assets when IP and port are known.
TLSX does not currently populate metadata.asset_info.tls.supported_versions; that requires explicit version enumeration and is intentionally out of scope for this enrichment pass.
TLSX also does not currently populate normalized signature algorithm, public key algorithm/size, or certificate extension identifiers in hxEASM observed state. Raw PEM/DER certificates are not stored in asset_info.
Graph Relations
The worker links certificates to the best matching asset:
webapp/service/subdomain/domain/ip -> has_certificate -> certificate
WebApp match is preferred when host and effective port are available; service is used as the fallback parent.
Files / Artifacts
Produces:
- None
Dependencies
Required binary: tlsx
Required installer entry: tools.tlsx
Command model:
TLSX probe flags are grouped because the installed TLSX rejects some probe combinations:
tlsx -json -silent -san -cn
tlsx -json -silent -serial -hash sha256
tlsx -json -silent -so -hash sha256
tlsx -json -silent -tls-version
Example Flow
webapp or service
-> tlsx
certificate
Notes
The certificate asset value remains the SHA-256 fingerprint. Subject, issuer, serial, SAN, validity, and endpoint context are observed metadata and do not change Certificate identity.