Agentless Scanning

Agentless Scanning discovers cryptographic assets without deploying software agents on target systems. It supports multiple discovery methods that collect cryptographic assets from network services, integrated platforms, public certificate sources, managed devices, and imported certificates. Discovered assets are consolidated into the Crypto Inventory and evaluated for Post-Quantum Cryptography (PQC) readiness.

The following table describes the available discovery methods to help you select the option that best fits the cryptographic assets you want to inventory.
Discovery method Best Used For Crypto Assets Collected
Network Scan Discovering live cryptographic configurations exposed by network services Protocols, cipher suites, key exchange algorithms, certificates
Vulnerability Management Tool – Tenable Reusing cryptographic discovery data from supported vulnerability management platforms Protocols, cipher suites, key exchange algorithms, certificates, cryptographic libraries (limited, based on tool data availability)
Certificate Authority Discovery Inventorying certificates issued by enterprise Certificate Authorities Certificates
URL Discovery Retrieving certificates presented by HTTPS endpoints Certificates
Certificate Transparency (CT) Log Discovery Discovering publicly trusted certificates associated with internet-facing domains Certificates
Managed Device Scan Retrieving certificates from integrated managed devices Certificates
Manual Certificate Upload Importing certificates into the platform for inventory and analysis Certificates