Scrape TLS certs and OCSP endpoints
2.0K
TLS Scrape is both a Go library and a CLI tool designed to scrape websites for TLS certificate details and log relevant metrics.
Library:
CLI Tool:
1.24.1-bullseye)You can build and run the CLI tool using the provided Makefile:
# To build the project
make build
# To run the project
make run
# To build the Docker image
make docker-build
Ensure you have the required environment variables or flags set (like fqdn or filepath) when running.
To use the TLS Scrape library in your Go project:
import "github.com/scotta01/tls-scrape"
You can configure the TLS Scrape tool using flags or environment variables:
Note
Only provide one of: fqdn, filepath, ip, or subnet. These options are mutually exclusive.The tool will gracefully skip any IPs or domains that don't connect (e.g., unreachable or not running a TLS service) and continue scanning the rest. A message will be displayed for each skipped IP or domain.
Example Usage:
# Scan a single domain
tls-scrape --fqdn=www.google.com --outdir=./output
# Scan a list of domains from a CSV file
tls-scrape --filepath=./websites.csv --header=url --outdir=./output
# Scan a single IP address
tls-scrape --ip=192.168.1.1 --port=443 --outdir=./output
# Scan an entire subnet
tls-scrape --subnet=192.168.1.0/24 --port=443 --outdir=./output
# Bundle all output into a single file
tls-scrape --subnet=192.168.1.0/24 --port=443 --outdir=./output --bundle --prettyjson
After building the Docker image using the Makefile, you can run it with:
docker run -e YOUR_ENV_VARIABLES scotta01/tls-scrape
Note
Replace YOUR_ENV_VARIABLES with the necessary environment variables.
If you'd like to contribute to TLS Scrape, please fork the repository and use a feature branch. Pull requests are warmly welcome.
The code in this project is licensed under the MIT license. Please see the LICENSE file for more information.
Content type
Image
Digest
sha256:fcedfac50…
Size
3.1 MB
Last updated
about 1 year ago
docker pull scotta01/tls-scrape