Cryptographic discovery: see the legacy cryptography your critical systems still run
QuProtect Reconnaissance builds a live inventory of the algorithms, protocols, certificates and key sizes your systems negotiate. Findings feed remediation on the same platform.
Each links to its definition, with the source it came from.
All termsWhat the inventory covers
What a system negotiates on the wire, read passively from live traffic and kept current as the traffic changes.
Source code tells you what an application might negotiate. The network tells you what it did negotiate this morning. That is why a scan of a repository and an inventory of a network return different answers, and why the network answer is the one you can act on. A weak cipher on a live connection carrying regulated data is a finding with an owner, a time and a fix attached.
-
Algorithms and key sizes
Which algorithms are negotiated and at what key sizes, including RSA and elliptic curve still in use.
-
Protocols and versions
TLS and SSL versions in use.
-
Certificates
Issuers, expiry, self-signed and vendor certificates, and chains of trust.
-
Client fingerprints
JA3 and JA4, so a connection can be attributed to the client that made it.
Passive sensors, nothing changed
Sensors are software, under the same Orchestrator that runs the rest of QuProtect R3. They read what systems negotiate on the wire: TLS versions, key exchange, signatures, ciphers, certificates and key sizes, plus JA3 and JA4 client fingerprints.
-
No decryption
Payloads are never opened or stored.
-
Nothing installed inside your applications
No application owner needs to be scheduled.
-
Self-managed
The inventory lives in your environment, cloud, on-premises or air-gapped, under your control.
-
Live
The inventory updates as traffic changes, so it reflects today rather than last quarter.
From finding to fix on one platform
Discovery point tools produce a report and leave the remediation program to you. Reconnaissance feeds the Orchestrator that changes the cryptography.
- A discovery point tool finds TLS 1.0 on a payment path
- The finding enters a backlog. An upgrade project is scoped per application, owners are scheduled, and the connection stays on TLS 1.0 while the program runs.
- Reconnaissance finds TLS 1.0 on a payment path
- An administrator sets a policy in the Orchestrator. Encryptors carry the connection over post-quantum TLS 1.3 at the network layer, with no application code change, and the inventory records the fix in the next CBOM export.
Built for security leaders and compliance-driven teams
-
CISOs
A current view of cryptographic risk and post-quantum readiness across the systems that matter most.
-
Security architects
The algorithms actually in production, so migration is prioritized by exposure rather than by guesswork.
-
Compliance teams
Evidence for federal, industry and internal requirements, exportable on demand.
-
Network engineers
Configuration drift, self-signed and vendor certificates, found before they become incidents.
Frequently asked questions
-
How do you inventory all the cryptography across an organization?
QuProtect sensors observe live network traffic passively and build an inventory of the algorithms, protocols, certificates and key sizes in use.
-
Does discovery require anything installed inside my applications?
No. Sensors deploy alongside your infrastructure and read what systems negotiate on the wire. Application code, libraries and configuration stay as they are.
-
Does the sensor decrypt my traffic?
No. Sensors read handshake and negotiation metadata, including JA3 and JA4 TLS client fingerprints. Payload data is never decrypted or stored.
-
Is the inventory a one-time snapshot?
No. The inventory updates continuously from live traffic, so it reflects what is on the wire today rather than what an audit found last quarter. PCI DSS 12.3.3 requires the inventory to be reviewed at least every 12 months; a live inventory makes that review a read rather than a project.
-
Can QuProtect scan air-gapped and legacy systems for cryptography?
Yes. QuProtect R3 is self-managed and runs entirely inside your environment, including air-gapped networks, with no outbound connection required. Legacy systems are read the same way as modern ones, because the sensor observes the connection rather than the host.
-
Does discovery work in cloud environments?
Yes. Sensors run in cloud, hybrid and on-premises environments under the same Orchestrator, and the inventory covers what a workload negotiates wherever it runs.
-
How do you generate a CBOM automatically?
QuProtect Reporting generates a CycloneDX v1.6 cryptographic bill of materials from the live inventory the sensors build, on demand and in machine-readable form. A CBOM is to cryptography what an SBOM is to software components: a list of what is present in the environment, exportable for an auditor or a federal cryptographic inventory submission.
-
Who holds the inventory data?
You do. QuProtect R3 is self-managed: the platform runs in your environment, cloud, on-premises or air-gapped, and the inventory, like your CA keys, stays under your control.
-
What happens after discovery finds a problem?
Remediation runs on the same platform. An administrator sets a policy in the Orchestrator, and encryptors apply the new cryptography at the network layer without application code changes. Discovery findings become policy changes rather than a project backlog.
Terms on this page
-
CBOM Cryptographic Bill of Materials
A structured inventory of the cryptographic assets in a system: the algorithms, keys and certificates in use, and how they relate to the software components that use them. CycloneDX, which publishes the format, calls it a Cryptography Bill of Materials.
Source: OWASP CycloneDX , CycloneDX v1.6 (cyclonedx.org)
-
CEM Cryptographic exposure management
The practice of identifying, prioritizing and reducing cryptographic risk across systems before vulnerabilities are exploited. It is the discipline a CBOM exists to serve: an inventory is the input, and the exposure it reveals is what gets worked down.
Source: QuSecure , What is cryptographic exposure management?
-
IoT Internet of Things
The network of devices containing the hardware, software, firmware and actuators that allow them to connect, interact and exchange data. IoT devices are often the hardest part of an estate to migrate, because many cannot be updated in place.
Source: NIST , NIST SP 800-172r3 (csrc.nist.gov)
-
PKI Public key infrastructure
A framework that is established to issue, maintain and revoke public key certificates. A PKI is what makes a certificate trustworthy, so an inventory of an organization’s cryptography is largely an inventory of what its PKI has issued.
Source: NIST , FIPS 186-5 (csrc.nist.gov)
-
SBOM Software Bill of Materials
A formal record containing the details and supply chain relationships of the various components used in building software. An SBOM answers what software you are running; a CBOM answers what cryptography it uses.
Source: NIST , NIST SP 800-161r1-upd1 (csrc.nist.gov)
-
SIEM Security information and event management
A program that provides centralized logging capabilities for a variety of log types. A SIEM is usually where a security team already looks, which is why cryptographic findings are worth sending to one rather than to a separate console.
Source: NIST , NIST SP 800-92 (csrc.nist.gov)
See your own inventory first.
Book a technical session and walk through discovery against your own architecture.