Network Capture Analyzer
Extracts endpoints, protocols and cryptographic handshakes from approved PCAP/PCAPNG captures without decrypting protected traffic.
PASSIVE ANALYSISPRODUCT MANUAL
Discover cryptographic exposure from packet captures, certificates, software dependencies and declared CBOM data—then turn findings into an owned migration backlog.
OVERVIEW
Organizations cannot prioritize PQC migration when algorithm use is hidden inside networks, certificate stores, code, appliances and supplier declarations.
WORKFLOW
COMPONENT REFERENCE
COMPONENT ARCHITECTURE
Three discovery engines run in parallel, then correlation, risk scoring and accountable remediation turn observations into governed action.
Extracts endpoints, protocols and cryptographic handshakes from approved PCAP/PCAPNG captures without decrypting protected traffic.
PASSIVE ANALYSISInventories certificate chains, algorithms, validity, SAN/EKU facts and trust-store placement across approved sources.
TRUST INVENTORYMaps libraries, providers, packages and configuration references into a versioned cryptographic bill of materials.
SOFTWARE INSPECTIONCompares operational observations with declared inventories and highlights unsupported, missing or stale cryptographic facts.
EVIDENCE CORRELATIONPrioritizes findings using secrecy horizon, verification lifetime, replacement lead time and external dependency.
POLICY ENGINEAssigns owners, remediation waves, exception dates, evidence requirements and closure criteria.
GOVERNED OUTPUTINTERFACES
LIMITATIONS & ACCEPTANCE