CBOM tools: open-source cryptographic discovery and scanning tools
No single tool sees all of an organisation's cryptography. This guide groups well-known open-source tools by what they can discover, what they output and where they fit in a CBOM pipeline.
- CBOM tools fall into three groups: code and artefact scanners that emit CycloneDX CBOMs, network scanners that probe live endpoints, and BOM utilities that validate and compare documents.
- CBOMkit, originally developed at IBM Research and donated to the Post-Quantum Cryptography Alliance in June 2025, includes source-code and container scanners that output CycloneDX CBOMs.
- Network scanners such as testssl.sh, SSLyze, Nmap's ssl-enum-ciphers and ssh-audit produce JSON or structured output that must be mapped into CBOM form.
- Choose tools by coverage of your languages, protocols and deployment artefacts, not by feature count.
Three kinds of CBOM tool
A Cryptographic Bill of Materials is assembled from several discovery methods, and open-source tools tend to specialise in one. It helps to group them:
- Code and artefact scanners read source code, container images or file systems and emit a CycloneDX CBOM directly.
- Network scanners connect to running services and report the protocols, cipher suites and certificates they offer. Their output needs mapping into CBOM form.
- BOM utilities validate, merge, convert and compare BOM documents once they exist.
CISA's strategy on automated cryptography discovery and inventory tools notes that agencies should expect to combine automated tools with manual collection where automation falls short, particularly for embedded cryptography [12]. The same holds for any organisation.
Code and artefact scanners
CBOMkit and sonar-cryptography
IBM Research donated its CBOM toolset to the Post-Quantum Cryptography Alliance (PQCA), a Linux Foundation project, on 23 June 2025 [1]. PQCA's architecture overview (March 2026) describes five parts, now hosted under the cbomkit GitHub organisation [2]:
- sonar-cryptography (CBOMkit-hyperion)a SonarQube plugin that detects cryptographic API usage and writes a
cbom.jsonin CycloneDX 1.6 format. Its README lists coverage for Java (JCA and the Bouncy Castle lightweight API), Python (pyca/cryptography) and Go (the standard crypto library, with partialgolang.org/x/cryptosupport), with C# in development [3]. - cbomkit-lib and cbomkit-actiona library wrapper that runs the detection engine without a SonarQube server, and a GitHub Action for CI pipelines [2].
- cbomkit-theiaa Go command-line tool that detects certificates, keys, secrets and configuration files in container images and directories [2].
- cbomkitthe application that stores CBOMs, visualises them and evaluates them against policy. Its README notes that it does not build repositories before scanning, which can reduce accuracy for Java projects without compiled classes [4]. All components are Apache 2.0 licensed.
cdxgen
OWASP CycloneDX's cdxgen generator can produce a CBOM through its cbom alias or the --include-crypto option. Its README describes coverage of Java keystores and certificates and source-level algorithm inventory for JavaScript and TypeScript [5].
cryptobom-forge
Santander Security Research's cryptobom-forge converts CodeQL SARIF output into a CycloneDX CBOM and includes a rules-based check that reports issues such as weak algorithms or modes. It is GPL-3.0 licensed [6].
Network scanners
| Tool | What it examines | Structured output | Licence |
|---|---|---|---|
| testssl.sh | TLS/SSL protocols, ciphers and a range of cryptographic flaws on any port [7] | JSON, CSV, HTML | GPLv2 |
| SSLyze | TLS configuration and known attacks; can check servers against Mozilla's recommended TLS configurations [8] | JSON (with published schema) | AGPL |
| Nmap ssl-enum-ciphers | Enumerates every cipher suite and compressor a server accepts and grades each A–F [9] | Nmap XML | Nmap project licence |
| ssh-audit | SSH key exchange, host-key, encryption and MAC algorithms; policy audits against hardened baselines [10] | JSON | MIT |
These tools see what is negotiated on the wire, which a code scanner cannot. They do not see keys at rest, algorithms used internally for data encryption, or services that are not reachable from the scanning host. A typical invocation of the Nmap script is nmap -sV --script ssl-enum-ciphers -p 443 <host> [9].
BOM utilities
The CycloneDX CLI validates, merges, converts and diffs BOMs, and can sign and verify them [11]. Schema validation and diffing are the minimum you need to keep CBOMs trustworthy over time; see CBOM validation.
How to choose
- Map coverage to your estate. List your languages, crypto libraries, protocols and deployment artefacts, then check each tool's documented coverage against that list.
- Prefer standard output. Tools that emit CycloneDX CBOMs directly reduce mapping work. For the rest, plan a conversion step.
- Run in the pipeline and on a schedule. Code scanners belong in CI; network scanners belong on a recurring schedule because configurations drift.
- Check licences. GPL and AGPL tools are fine for internal scanning; review obligations before embedding them in a product.
- Plan for gaps. HSM and KMS key metadata, firmware and third-party products usually need exports or supplier CBOMs rather than scanning.
For the full discovery approach, see CBOM generation; for what to look for once you have results, see finding weak cryptography with a CBOM.
How IntelliXBOM helps
IntelliXBOM ingests CycloneDX CBOMs produced by open-source scanners and other sources, validates them against required-field policies, and keeps version history and diffs across scans. It correlates the resulting cryptographic assets with vulnerabilities, end-of-life data and business services, so findings from different tools can be reviewed in one place.
Frequently asked questions
What is the best open-source CBOM tool?
There is no single best tool, because each covers a different discovery method. Code scanners such as sonar-cryptography and cdxgen find cryptography in source, while network scanners such as testssl.sh and SSLyze find what services actually negotiate. Most organisations combine several.
Can a TLS scanner produce a CBOM?
TLS scanners such as testssl.sh and SSLyze produce structured JSON describing protocols, cipher suites and certificates, but not a CycloneDX CBOM directly. Their output can be mapped into CBOM protocol, algorithm and certificate assets.
Who maintains CBOMkit?
CBOMkit was developed at IBM Research and donated to the Post-Quantum Cryptography Alliance, a Linux Foundation project, in June 2025. Its repositories are hosted under the cbomkit organisation on GitHub and are Apache 2.0 licensed.
Sources
- IBM is donating its CBOM toolset to the Linux Foundation (23 June 2025)IBM Researchresearch.ibm.com/blog/cryptographic-cbom-linux-foundation
- PQCA CBOMkit Architecture (16 March 2026)Post-Quantum Cryptography Alliancepqca.org/blog/2026/pqca-cbomkit-architecture/
- Sonar Cryptography Plugin (CBOMkit-hyperion)CBOMkit / Post-Quantum Cryptography Alliance (GitHub)github.com/cbomkit/sonar-cryptography
- CBOMkitCBOMkit / Post-Quantum Cryptography Alliance (GitHub)github.com/cbomkit/cbomkit
- cdxgen, CycloneDX GeneratorOWASP CycloneDX (GitHub)github.com/CycloneDX/cdxgen
- cryptobom-forgeSantander Security Research (GitHub)github.com/Santandersecurityresearch/cryptobom-forge
- testssl.shtestssl.sh project (GitHub)github.com/testssl/testssl.sh
- SSLyzeSSLyze project (GitHub)github.com/nabla-c0d3/sslyze
- ssl-enum-ciphers NSE scriptNmap Projectnmap.org/nsedoc/scripts/ssl-enum-ciphers.html
- ssh-auditssh-audit project (GitHub)github.com/jtesta/ssh-audit
- CycloneDX CLIOWASP CycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
- Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools (September 2024)CISAwww.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.