
tlsx v1.4.0
TLS 기반 데이터 수집에 중점을 둔 빠르고 구성 가능한 TLS 그래버.
기능 • 설치 • 사용법 • tlsx 실행 • Discord 참여
TLS 기반 데이터 수집 및 분석에 중점을 둔 빠르고 구성 가능한 TLS 그래버입니다.
기능

- 빠르고 완전히 구성 가능한 TLS 연결
- 다양한 TLS 연결 모드
- 여러 TLS 프로브
- 이전 TLS 버전용 자동 TLS 폴백
- 핸드셰이크 전 TLS 연결(조기 종료)
- 사용자 정의 가능한 Cipher / SNI / TLS 선택
- JARM/JA3 TLS 핑거프린트
- TLS 잘못된 구성
- ASN, CIDR, IP, HOST 및 URL 입력
- STD IN/OUT 및 TXT/JSON 출력
설치
tlsx를 설치하려면 Go 1.24가 필요합니다. 설치하려면 아래 명령을 실행하거나 릴리스 페이지에서 사전 컴파일된 바이너리를 다운로드하세요.```console go install github.com/projectdiscovery/tlsx/cmd/tlsx@latest
## 사용법```console
tlsx -h
이 도구에 대한 도움말이 표시됩니다. 지원하는 모든 스위치는 다음과 같습니다.```console TLSX is a tls data gathering and analysis toolkit.
Usage: tlsx [flags]
Flags: INPUT: -u, -host string[] target host to scan (-u INPUT1,INPUT2) -l, -list string target list to scan (-l INPUT_FILE) -p, -port string[] target port to connect (default 443)
SCAN-MODE: -sm, -scan-mode string tls connection mode to use (ctls, ztls, openssl, auto) (default "auto") -ps, -pre-handshake enable pre-handshake tls connection (early termination) using ztls -sa, -scan-all-ips scan all ips for a host (default false) -iv, -ip-version string[] ip version to use (4, 6) (default 4)
PROBES: -san display subject alternative names -cn display subject common names -so display subject organization name -tv, -tls-version display used tls version -cipher display used cipher -hash string display certificate fingerprint hashes (md5,sha1,sha256) -jarm display jarm fingerprint hash -ja3 display ja3 fingerprint hash (using ztls) -wc, -wildcard-cert display host with wildcard ssl certificate -tps, -probe-status display tls probe status -ve, -version-enum enumerate and display supported tls versions -ce, -cipher-enum enumerate and display supported cipher -ct, -cipher-type value ciphers types to enumerate. possible values: all/secure/insecure/weak (comma-separated) (default all) -ch, -client-hello include client hello in json output (ztls mode only) -sh, -server-hello include server hello in json output (ztls mode only) -se, -serial display certificate serial number
MISCONFIGURATIONS: -ex, -expired display host with host expired certificate -ss, -self-signed display host with self-signed certificate -mm, -mismatched display host with mismatched certificate -re, -revoked display host with revoked certificate -un, -untrusted display host with untrusted certificate
CONFIGURATIONS: -config string path to the tlsx configuration file -r, -resolvers string[] list of resolvers to use -cc, -cacert string client certificate authority file -ci, -cipher-input string[] ciphers to use with tls connection -sni string[] tls sni hostname to use -rs, -random-sni use random sni when empty -rps, -rev-ptr-sni perform reverse PTR to retrieve SNI from IP -min-version string minimum tls version to accept (ssl30,tls10,tls11,tls12,tls13) -max-version string maximum tls version to accept (ssl30,tls10,tls11,tls12,tls13) -cert, -certificate include certificates in json output (PEM format) -tc, -tls-chain include certificates chain in json output -vc, -verify-cert enable verification of server certificate -ob, -openssl-binary string OpenSSL Binary Path -hf, -hardfail strategy to use if encountered errors while checking revocation status -proxy string socks5 proxy to use for tlsx
OPTIMIZATIONS: -c, -concurrency int number of concurrent threads to process (default 300) -cec, -cipher-concurrency int cipher enum concurrency for each target (default 10) -timeout int tls connection timeout in seconds (default 5) -retry int number of retries to perform for failures (default 3) -delay string duration to wait between each connection per thread (eg: 200ms, 1s)
UPDATE: -up, -update update tlsx to latest version -duc, -disable-update-check disable automatic tlsx update check
OUTPUT: -o, -output string file to write output to -j, -json display output in jsonline format -dns display unique hostname from SSL certificate response -ro, -resp-only display tls response only -silent display silent output -nc, -no-color disable colors in cli output -v, -verbose display verbose output -version display project version
PDCP: -pd, -dashboard upload or view output in the PDCP UI dashboard -pdu, -dashboard-upload string upload tlsx output file (JSONL format) to the PDCP UI dashboard -auth string PDCP API key for authentication -tid, -team-id string upload asset results to a specified team ID -aid, -asset-id string upload new assets to an existing asset ID -aname, -asset-name string asset group name
DEBUG: -health-check, -hc run diagnostic check up
## Using tlsx as library
tlsx를 라이브러리로 사용하는 예제는 [examples](https://github.com/projectdiscovery/tlsx/blob/main/examples) 폴더에서 제공됩니다.
## Running tlsx
### Input for tlsx
**tlsx**는 TLS 연결을 위해 **ip**가 필요하며, 아래 나열된 것처럼 여러 형식을 허용합니다:```bash
AS1449 # ASN input
173.0.84.0/24 # CIDR input
93.184.216.34 # IP input
example.com # DNS input
example.com:443 # DNS input with port
https://example.com:443 # URL input port
입력 호스트는 -host / -u 플래그를 사용하여 제공할 수 있으며, 여러 값을 쉼표로 구분된 입력으로 제공할 수 있습니다. 마찬가지로 파일 입력은 -list / -l 플래그를 사용하여 지원됩니다.
쉼표로 구분된 호스트 입력 예시:```console $ tlsx -u 93.184.216.34,example.com,example.com:443,https://example.com:443 -silent
파일 기반 호스트 입력의 예:```console
$ tlsx -list host_list.txt
포트 입력:
tlsx는 기본적으로 443 포트에 연결되며, -port / -p 플래그를 사용하여 사용자 정의할 수 있습니다. 단일 또는 여러 포트는 쉼표로 구분된 입력 또는 연결할 포트 목록이 포함된 줄바꿈 구분 파일을 사용하여 지정할 수 있습니다.
쉼표로 구분된 포트 입력 예:``` $ tlsx -u hackerone.com -p 443,8443
파일 기반 포트 입력 예시:```
$ tlsx -u hackerone.com -p port_list.txt
참고:
입력 호스트에 포트가 포함된 경우(예:
8.8.8.8:443또는hackerone.com:8443), 호스트와 함께 지정된 포트가 기본 포트 또는-port / -p플래그로 제공된 포트 대신 TLS 연결에 사용됩니다.
TLS 프로브 (기본 실행)
이 도구는 주어진 CIDR 범위에 대해 실행되어 포트 443에서 TLS 연결을 허용하는 호스트를 반환합니다.```console $ echo 173.0.84.0/24 | tlsx