Transit Layer.
Network crypto, probed.
External, credential-less interrogation of every internet-facing and internal endpoint. The first thing your auditor will look at is the first thing ResilQ checks.
Every protocol that carries crypto on the wire.
The Transit layer is what an attacker sees, what an external auditor scans, and what a regulator can verify without ever touching your hosts. ResilQ probes all of it in parallel, classifies what it finds against a curated cipher database, and emits findings sorted by exploitability and quantum sensitivity.
Eight workers, one estate.
Concurrent crypto interrogation across the entire reachable surface — hosts, load balancers, proxies, mail servers, DNS, internal services. No host install required.
→ 8 parallel crypto probes
→ graph.json built
→ findings emitted
What ResilQ actually inspects.
Transport Layer Security
- Protocol versions (SSL 2/3, TLS 1.0–1.3) per endpoint
- Cipher suites enumerated against IANA + testssl.sh — 310 suites, 23 name variants
- Key-exchange groups: classical (X25519, P-256, P-384) vs post-quantum (ML-KEM-768 hybrid)
- Signature algorithms: RSA, ECDSA, EdDSA, ML-DSA
- Certificate chain hygiene: key size, expiry, CT inclusion, OCSP stapling
- Session-resumption posture (tickets, PSK), 0-RTT exposure
Secure Shell
- KEX algorithm enumeration — DH groups, ECDH curves, sntrup761x25519
- Host-key types and sizes (RSA, Ed25519, ECDSA)
- MAC and cipher posture per offered set
- Authentication methods exposed (password, key, GSSAPI)
- Banner / version reachability (CVE surface)
- Optional credentialed login for deeper config inspection
Name resolution & PKI
- DNSSEC chain validation (DS, RRSIG, NSEC/NSEC3)
- DANE (TLSA) presence and correctness
- CAA record posture — issuer restrictions, account binding, IODEF
- SPF, DKIM, DMARC for email surface
- Certificate Transparency log presence and reissuance velocity
Web-edge headers
- HSTS posture: max-age, preload, includeSubDomains
- Content-Security-Policy: hash/nonce vs unsafe-inline
- X-Frame-Options, Referrer-Policy, Permissions-Policy
- Cross-Origin-Embedder/Opener-Policy, Resource-Policy
- Server & framework banner exposure
- TLS-handshake to header alignment (downgrade risk)
What you actually receive.
Every Transit-layer finding lands in your dashboard as a structured record tagged with severity, asset, layer and quantum sensitivity — and as a row in your exportable JSON / CBOM / PDF audit pack.
Where Transit findings carry their weight.
Cryptographic posture is in scope of essential-entity audits — Transit findings map directly to risk-management measures (Art. 21).
Article 8 ICT risk management explicitly covers protocol-level cryptographic exposure for financial entities.
Req. 4 — strong cryptography for cardholder data in transit. ResilQ outputs evidence acceptable to QSAs.
SR 4.1 (data confidentiality) and SR 3.1 (network segmentation) — Transit posture as zoned evidence.
Toolbox technical measure TM-04 on supply-chain crypto — Transit findings land directly in the framework.
U.S. NSA mandate for PQC by 2030 — Transit-layer hybrid TLS posture is the leading indicator.