Name:zgrab2-tls
Category:Recon
Publisher:trickest-mhmdiaa
Created:5/24/2023
Container:
quay.io/trickest/zgrab2-tls:911c86f-patch-2Output Type:
License:Unknown
Source:View Source
Parameters
--sctRequest Signed Certificate Timestamps during TLS Handshake--portSpecify port to grab on (default: 80)--timeExplicit request time to use, instead of clock. YYYYMMDDhhmmss format.--debugInclude debug fields in the output.--flushFlush after each line of output.Input target--no-sniDo not send domain name in TLS Handshake regardless of whether known--sendersNumber of send goroutines to use (default: 1000)--timeoutSet connection timeout (0 = no timeout) (default: 10s)--triggerInvoke only on targets with specified tag--maxbytesMaximum byte read limit per scan (0 = defaults)--no-ecdheDo not allow ECDHE handshakes--root-casSet of certificates to use when verifying server certificates--gomaxprocsSet GOMAXPROCS (default: 0)--heartbleedCheck if server is vulnerable to HeartbleedInput file--prometheusAddress to use for Prometheus server (e.g. localhost:8080). If empty, Prometheus is disabled--dsa-enabledAccept server DSA keys--max-versionThe maximum SSL/TLS version that is acceptable. 0 means use the highest supported value.--min-versionThe minimum SSL/TLS version that is acceptable. 0 means that SSLv3 is the minimum.--next-protosA list of supported application-level protocols--server-nameServer name used for certificate verification and (optionally) SNI--certificatesSet of certificates to present to the server--cipher-suiteA comma-delimited list of hex cipher suites to advertise.--client-helloSet an explicit ClientHello (base64 encoded)--client-randomSet an explicit Client Random (base64 encoded)--session-ticketSend support for TLS Session Tickets and output ticket if presented--certificate-mapA file mapping server names to certificates--extended-randomSend TLS Extended Random Extension--keep-client-logsInclude the client-side logs in the TLS handshake--curve-preferencesA list of elliptic curves used in an ECDHE handshake, in order of preference.--heartbeat-enabledIf set, include the heartbeat extension--read-limit-per-hostMaximum total kilobytes to read for a single host (default 96kb) (default: 96)--connections-per-hostNumber of times to connect to each host (results in more output) (default: 1)--signature-algorithmsSignature and hash algorithms that are acceptable--extended-master-secretOffer RFC 7627 Extended Master Secret extension--verify-server-certificateail if the server certificate does not match the server-name, or does not chain to a trusted root.