Skip to content

TLSX

Purpose

TLSX collects TLS certificate information and emits certificate assets.

Plugin Information

Plugin ID: tlsx

Category: TLS Discovery

Plugin Type: custom

Execution: active CLI TLS probe

Default State: enabled

Default Profiles:

  • deep
  • tls_audit
  • recon_expanded

Input Scope

Accepted asset types:

  • webapp
  • domain
  • subdomain
  • service
  • ip

Required metadata:

  • None

Produces targets:

  • Newline-delimited scope values on stdin.

Output

Creates assets:

  • certificate

Creates vulnerabilities:

  • None

May enrich:

  • Certificate assets with fingerprint, serial number, subject, issuer, SAN, validity, host, IP, port, and scheme metadata.
  • Service assets with observed negotiated TLS version when TLSX reports a TLS version and a concrete IP/port is available.

Metadata:

  • subject_cn: certificate subject common name.
  • issuer_cn: issuer common name.
  • serial_number: certificate serial number when emitted.
  • san: subject alternative names.
  • not_before: certificate start time from TLSX.
  • not_after: certificate expiry time from TLSX.
  • expired: expiry flag.
  • host: parsed host.
  • ip: reported or inferred IP.
  • port: parsed or inferred port.
  • scheme: parsed URL scheme.
  • source: tlsx.

Canonical observed state:

  • metadata.asset_info.certificate.fingerprint_sha256.
  • metadata.asset_info.certificate.serial_number.
  • metadata.asset_info.certificate.subject.common_name.
  • metadata.asset_info.certificate.subject.organization, organizational_unit, country, locality, and province when emitted by TLSX.
  • metadata.asset_info.certificate.issuer.common_name.
  • metadata.asset_info.certificate.issuer.organization, organizational_unit, country, locality, and province when emitted by TLSX.
  • metadata.asset_info.certificate.sans.
  • metadata.asset_info.certificate.validity.not_before.
  • metadata.asset_info.certificate.validity.not_after.
  • metadata.asset_info.certificate.validity.expired.
  • metadata.asset_info.tls.observed_version on Service assets when IP and port are known.

TLSX does not currently populate metadata.asset_info.tls.supported_versions; that requires explicit version enumeration and is intentionally out of scope for this enrichment pass.

TLSX also does not currently populate normalized signature algorithm, public key algorithm/size, or certificate extension identifiers in hxEASM observed state. Raw PEM/DER certificates are not stored in asset_info.

Graph Relations

The worker links certificates to the best matching asset:

webapp/service/subdomain/domain/ip -> has_certificate -> certificate

WebApp match is preferred when host and effective port are available; service is used as the fallback parent.

Files / Artifacts

Produces:

  • None

Dependencies

Required binary: tlsx

Required installer entry: tools.tlsx

Command model:

TLSX probe flags are grouped because the installed TLSX rejects some probe combinations:

tlsx -json -silent -san -cn
tlsx -json -silent -serial -hash sha256
tlsx -json -silent -so -hash sha256
tlsx -json -silent -tls-version

Example Flow

webapp or service
  -> tlsx
certificate

Notes

The certificate asset value remains the SHA-256 fingerprint. Subject, issuer, serial, SAN, validity, and endpoint context are observed metadata and do not change Certificate identity.