zgrab2-tls
Fast Go Application Scanner
Name:zgrab2-tls
Category:Recon
Publisher:trickest-mhmdiaa
Created:5/24/2023
Container:
quay.io/trickest/zgrab2-tls:911c86f-patch-2
Output Type:
License:Unknown
Source:View Source
Parameters
--sct
Request Signed Certificate Timestamps during TLS Handshake--port
Specify port to grab on (default: 80)--time
Explicit request time to use, instead of clock. YYYYMMDDhhmmss format.--debug
Include debug fields in the output.--flush
Flush after each line of output.
Input target--no-sni
Do not send domain name in TLS Handshake regardless of whether known--senders
Number of send goroutines to use (default: 1000)--timeout
Set connection timeout (0 = no timeout) (default: 10s)--trigger
Invoke only on targets with specified tag--maxbytes
Maximum byte read limit per scan (0 = defaults)--no-ecdhe
Do not allow ECDHE handshakes--root-cas
Set of certificates to use when verifying server certificates--gomaxprocs
Set GOMAXPROCS (default: 0)--heartbleed
Check if server is vulnerable to Heartbleed
Input file--prometheus
Address to use for Prometheus server (e.g. localhost:8080). If empty, Prometheus is disabled--dsa-enabled
Accept server DSA keys--max-version
The maximum SSL/TLS version that is acceptable. 0 means use the highest supported value.--min-version
The minimum SSL/TLS version that is acceptable. 0 means that SSLv3 is the minimum.--next-protos
A list of supported application-level protocols--server-name
Server name used for certificate verification and (optionally) SNI--certificates
Set of certificates to present to the server--cipher-suite
A comma-delimited list of hex cipher suites to advertise.--client-hello
Set an explicit ClientHello (base64 encoded)--client-random
Set an explicit Client Random (base64 encoded)--session-ticket
Send support for TLS Session Tickets and output ticket if presented--certificate-map
A file mapping server names to certificates--extended-random
Send TLS Extended Random Extension--keep-client-logs
Include the client-side logs in the TLS handshake--curve-preferences
A list of elliptic curves used in an ECDHE handshake, in order of preference.--heartbeat-enabled
If set, include the heartbeat extension--read-limit-per-host
Maximum total kilobytes to read for a single host (default 96kb) (default: 96)--connections-per-host
Number of times to connect to each host (results in more output) (default: 1)--signature-algorithms
Signature and hash algorithms that are acceptable--extended-master-secret
Offer RFC 7627 Extended Master Secret extension--verify-server-certificate
ail if the server certificate does not match the server-name, or does not chain to a trusted root.