
Enterprise-grade toolkit to audit and migrate legacy infrastructure to hybrid post-quantum cryptography (PQC).
QSM is an advanced, production-ready security toolkit implemented in Python 3.10+, designed specifically for DevOps engineers and security auditors on distributions like Parrot OS Security. It addresses the critical threat vector of "Harvest Now, Decrypt Later" (HNDL) by assessing infrastructure cryptographic postures and automating hybrid post-quantum migrations.
โ ๏ธ Strict Architectural Principle: QSM never permits pure post-quantum deployment. All operations enforce a secure, backward-compatible Hybrid Paradigm combining classical and PQC algorithms (e.g., ECDSA + Dilithium3 for authentication and X25519 + Kyber768 for key exchange).
QSM is built to run adaptively across environments without blocking your security workflow:
liboqs system integration to patch configuration layers atomically with integrated checksum-verified rollback logic.# Clone and enter the vault
git clone https://github.com/soufianecyber/Quantum-Safe-Migration
cd Quantum-Safe-Migration
# Initialize virtual environment
python3 -m venv venv
source venv/bin/activate
# Install lightweight dependencies
pip install -r requirements.txt
python3 qsm.py --preflight
# 1. Run Quantum Attack Simulation on target assets
python3 qsm.py --simulate --target example.com
python3 qsm.py --simulate --keyfile ./test_legacy_key.pem
# 2. Preview Hybrid Migration Block (Safe Dry-Run)
python3 qsm.py --migrate --target nginx --config ./dummy_nginx.conf --dry-run
# 3. Apply Production Migration (Requires Sudo)
sudo venv/bin/python3 qsm.py --migrate --target nginx --config /etc/nginx/nginx.conf
sudo venv/bin/python3 qsm.py --migrate --target sshd --config /etc/ssh/sshd_config
# 4. Atomic Rollback Checksum Restoration
sudo venv/bin/python3 qsm.py --rollback --target /etc/nginx/nginx.conf
Distributed under the MIT License. See LICENSE for details.
Disclaimer: This toolkit is built exclusively for authorized testing and infrastructure migration verification purposes.
Soufiane Cyber
liboqssudo python3 qsm.py --preflight

Validates Python version, liboqs bindings, Kyber/Dilithium availability, and OpenSSL.
python3 qsm.py --simulate --target google.com

Detects ECC-256 on google.com and computes Shor's Algorithm time-to-crack.
sudo python3 qsm.py --migrate --target nginx --config /etc/nginx/nginx.conf --dry-run

Preview of hybrid cipher suite injection โ no files modified.
If QSM helps you secure your infrastructure against quantum threats, please consider giving it a star on GitHub. It helps the project gain visibility and reach more security teams who need it.