This message was deleted.
# _general
s
This message was deleted.
b
r
Thank you, I have that, I did not explain well. Looking for a scanner to help me analyze things
d
r
Thanks @Deyda I have that too. I looking to scan my lab (internal domain) none internet facing.
d
ah ok sry
r
no worries, I did not explain it well.
maybe security onion
b
I've found a repository from SSLLabs. https://github.com/ssllabs/research/wiki/Assessment-Tools. TestSSLServer seems promising. https://github.com/pornin/TestSSLServer/
r
Thank you, I will check that out. Looks nice
r
you can also use openssl for this.
openssl s_client -showcerts -connect site.domain.com:443
👍 1
and probably a ton of other options in there to dig deeper
Copy code
SSL-Session:
    Protocol  : TLSv1.3
    Cipher    : TLS_AES_256_GCM_SHA384
j
You're looking for a free internal Qualys/Nessus type of scan Ray?
r
Yes sir,
j
all windows? all 443? or something that will portscan and then see if terminated in tls?
r
Mostly windows, and Free BSOD, AHV. Just looking to capture what is considered weak ciphers now. Like a internal scan of Nexpos, Qualys type software. I see a free tool on Qualys. I need to check it out. I see security onion has things as well. Really just more me to make sure what I think is weak is actually true.
All the others, I need to look at as well that other sent.
r
Free BSOD? Isn't that... Windows? 😄🤣
r
HAHA. Yea, Meant BSD
r
i know. 🙂
👍 1
that's a good one though, I may use that somewhere. LOL
j
What thread am I in? the hotfix one or....
For Windows, I've had this in my bookmarks, it's dated... but I've used it in the past https://www.cyberdrain.com/monitoring-with-powershell-monitoring-cipher-suites-and-get-a-ssllabs-a-rank/
👍 1
r
Thats neat
p
If you are hardcore you can watch the cipher exchange in Wireshark. It occurs in plain text before the encryption really kicks off. It's nice because you can see both sides of the negotiations.