Skip to content

Repository files navigation

VN-PQC Readiness Analyzer

CI Python 3.10+ License: MIT GitHub stars Lint

Lint status

Lint is red, and we are not hiding it. This repo enables ruff with a rule set it has never fully satisfied — the badge has been failing on every run, not since a regression. All six runs of the workflow (#1–#6) have failed.

Current count, produced by the exact command below, on Lint run #6, commit 6181ad8, 2026-09-06 (ruff 0.16.6, as pinned in CI), unchanged since run #3:

$ ruff check src/ tests/
Found 170 errors.
[*] 37 fixable with the `--fix` option (28 hidden fixes can be enabled with the `--unsafe-fixes` option).

For the per-rule breakdown, run ruff check --statistics src/ tests/ and read it off your own machine rather than off this page.

We publish this number instead of turning the gate off, for the same reason we publish the techniques a default SIEM does not alert on: a number you can reproduce is worth more than a green badge you cannot.

What CI covers, so the green means something: pip install -e ".[dev,flow]" then pytest on Python 3.10, 3.11 and 3.12. It excludes tests marked integration and the whole tests/test_reporter directory.

NIST has finalized post-quantum standards. Your TLS, SSH, and VPN are running dead algorithms. This tool tells you exactly what to fix, how long it takes, and how much it costs.

Scan your infrastructure for quantum-vulnerable cryptography. Get a migration roadmap with cost estimates. Maps findings to NIST FIPS 203/204.

Tieng Viet | English

Demo

Scan output at a glance

Scan output

Cloudflare and Google now serve hybrid X25519MLKEM768 (IANA 0x11EC) by default — the scanner detects this via an active TLS 1.3 ClientHello probe and marks those endpoints SAFE. GitHub still negotiates classical ECDHE, so it gets flagged HIGH with the NIST FIPS 203 replacement (ML-KEM-768) called out. The scan surfaces what's actually on the wire, not what a server could support.

Flow Analysis (HNDL Radar) in action

Flow demo

scan pcap groups packets into 5-tuple flows, parses the TLS/SSH handshake, classifies each flow's data sensitivity from SNI/port rules, and scores HNDL = 100 × V × S × R × E. The demo above runs on a synthetic fixture (docs/fixtures/flow_demo.pcap) shipped in the repo — every handshake byte is hand-crafted in scripts/mk_flow_demo_pcap.py so results are deterministic and offline-reproducible. For real traffic, feed any PCAP you captured yourself (see capture recipes).


Features

Community Edition (this repo)

  • Crypto Inventory Scanner — TLS endpoints, certificates, SSH/VPN configs, source code
  • Flow Analysis (HNDL Radar) — Parse PCAP traffic (tcpdump capture, Wireshark export, SPAN-port dump), score each flow's Harvest-Now-Decrypt-Later exposure with V × S × R × E. No decryption keys needed — handshakes travel in plaintext. See docs/flow-analysis.md for capture recipes.
  • PQC Benchmarker — Compare classical vs PQC algorithms (ML-KEM, ML-DSA) on your hardware
  • Migration Roadmap — Risk scoring, priority engine, 4-phase migration plan with cost estimation
  • Compliance Checker — NIST FIPS 203/204, SP 800-131A, SP 800-57
  • CLI — Full command-line interface with rich output
  • Bilingual — Vietnamese/English support
  • JSON output — Scan results and roadmaps exported as structured JSON

Enterprise Edition

For government and enterprise clients, we offer additional modules:

  • REST API — FastAPI backend for integration
  • Web UI — React dashboard with interactive charts, risk heatmaps, benchmark visualizations
  • Report Generator — HTML (dark theme), PDF (WeasyPrint), SARIF (CI/CD), Executive Summary
  • Docker Compose — Multi-service deployment with web frontend
  • Custom branding — Tailored report templates and UI for your organization

Found a bug or have a question? Open an issue: https://github.com/xuxu298/PQCAnalyzer/issues

Contact: support@vradar.io for enterprise licensing.

Why This Tool?

  • Q-Day is coming — Quantum computers will break RSA, ECDSA, and DH. NIST has finalized replacement standards (FIPS 203/204). The clock is ticking.
  • No existing open-source tool does the full picture — scan + benchmark + roadmap + cost estimation + compliance check, all in one CLI.
  • One command to know where you stand — pqc-analyzer scan tls yourdomain.com
  • Offline-first — works in air-gapped environments and CI/CD pipelines.

Quick Start

Install

pip install -e .

With development tools:

pip install -e ".[dev]"

With PQC benchmark support (requires liboqs):

pip install -e ".[benchmark]"

With PCAP flow analysis support:

pip install -e ".[flow]"

CLI Usage

# Scan a TLS endpoint
pqc-analyzer scan tls example.com --port 443

# Scan SSH configuration
pqc-analyzer scan ssh /etc/ssh/sshd_config

# Scan VPN configuration
pqc-analyzer scan vpn /etc/openvpn/server.conf

# Scan source code for crypto usage
pqc-analyzer scan code /path/to/project/src

# Scan config files (nginx, apache, haproxy)
pqc-analyzer scan config /etc/nginx/nginx.conf

# Analyse a PCAP capture (HNDL Radar)
# See docs/flow-analysis.md for capturing real traffic (tcpdump, SPAN, Wireshark)
pqc-analyzer scan pcap corp_edge.pcap -o flow_report.json

# Generate migration roadmap (accepts scanner OR flow JSON)
pqc-analyzer roadmap scan_results.json

# Run PQC benchmark
pqc-analyzer benchmark kem --iterations 1000
pqc-analyzer benchmark sign --iterations 1000

# Export results as JSON
pqc-analyzer scan tls example.com -o results.json

Docker

docker build -t pqc-analyzer .
docker run pqc-analyzer scan tls example.com

After you clone: three minutes, one number

The scan produces a number about your infrastructure, not ours. One command gets it:

pip install -e .
pqc-analyzer scan tls yourdomain.com --port 443 -o results.json

results.json holds every endpoint the scanner reached, the key exchange each one actually negotiated, and a risk level per finding. Two follow-ups read the same file:

pqc-analyzer roadmap results.json      # priority order, effort estimate, phase plan

Before you act on a score, read what it is made of: docs/hndl-scoring.md explains V x S x R x E, and docs/flow-analysis.md covers capturing your own traffic instead of the fixture shipped here.

Then tell me what it said. Open an issue using the Scan result template. Paste the roadmap summary — or the whole JSON with hostnames removed, it stays useful without them — plus one line about what you pointed it at. I answer in the thread, in writing: which finding I would fix first, and why that one. No call, no signup, no email address needed.

If it got something wrong about your infrastructure, that is the single most useful thing you can send me. A scanner that is confidently wrong on your estate is worse than no scanner, and I cannot find that failure mode from here.

What this tool does not do

  • No third-party audit. Every number in this repository is self-measured. The commands above exist so you can reproduce them, or contradict them.
  • The flow-analysis demo is not real traffic. It runs on docs/fixtures/flow_demo.pcap, a synthetic capture generated by scripts/mk_flow_demo_pcap.py, deterministic on purpose.
  • It reports what is on the wire at scan time — not what a server could support if configured differently, and not that a host is safe from anything beyond the specific quantum-vulnerable primitives listed under Scan Targets.

Architecture

src/
  scanner/          # Crypto inventory scanner (TLS, cert, SSH, VPN, code)
  flow_analyzer/    # PCAP flow analyser + HNDL scorer (V x S x R x E)
  benchmarker/      # PQC performance benchmarker (KEM, signatures)
  roadmap/          # Migration roadmap (risk, recommendation, priority, cost)
  utils/            # Shared utilities (crypto DB, i18n, constants)
  cli.py            # CLI entry point (typer)

data/               # Algorithm database, NIST/Vietnam guidelines, sensitivity rules
examples/           # Demo scripts
tests/              # Test suite (scanner, roadmap, flow_analyzer, benchmarker)

Scan Targets

Scanner Target What it finds
TLS host:port Cipher suites, key exchange, protocol versions
Certificate X.509 chain Signature algorithms, key types, expiry
SSH sshd_config KEX, ciphers, MACs, host key algorithms
VPN OpenVPN/WireGuard/IPSec configs Crypto primitives, DH groups
Code Source directories Crypto API usage in Python/Java/Go/JS/C
Config nginx/apache/haproxy SSL/TLS settings
PCAP .pcap / .pcapng Per-flow HNDL score (TLS 1.2/1.3, SSH-2)

Output Format

CLI Roadmap Output

Overall Risk: CRITICAL
Total findings: 5 | Critical: 2 | QV: 4

Phase 1 — Quick Wins (3-6 months)
  Enable hybrid KEX on TLS endpoints (8h)
  Upgrade SSH weak ciphers (4h)
  Total effort: 12 person-hours

Phase 2 — Core Migration (6-18 months)
  Migrate VPN to PQC-aware stack (40h)
  Update application crypto libraries (80h)
  Total effort: 120 person-hours

Cost Estimation:
  Total effort: 200 person-hours
  Timeline: 24 months
  Cost range: 80 trieu VND — 160 trieu VND

Compliance:
  NON_COMPLIANT NIST FIPS 203
  PARTIAL SP 800-131A Rev2

JSON Export

All scan results and roadmaps export as structured JSON via CLI (-o output.json).

Risk Levels

Level Description Action
CRITICAL Quantum-vulnerable + internet-facing Migrate immediately
HIGH Quantum-vulnerable or broken classical Migrate in 3-6 months
MEDIUM Weak but not broken Upgrade when convenient
LOW Acceptable but not optimal Monitor
SAFE Post-quantum safe or AES-256 No action needed

Testing

pytest -v                          # Run all tests
pytest --cov=src --cov-report=html # With coverage
pytest -m "not integration"        # Skip network tests

257 tests collected under the exact selection CI runs — pytest -m "not integration" --ignore=tests/test_reporter — counted on 2026-09-02.

Contributing

See CONTRIBUTING.md for guidelines.

License

MIT License. See LICENSE.


Tiếng Việt

VN-PQC Readiness Analyzer

Công cụ đánh giá mức độ sẵn sàng chuyển đổi mật mã hậu lượng tử.

Công cụ mã nguồn mở giúp quét thuật toán mật mã trong hạ tầng, benchmark hiệu năng PQC, và tạo lộ trình chuyển đổi — thiết kế cho bối cảnh Việt Nam/ASEAN.

Phiên bản

Community (mã nguồn mở) Enterprise (liên hệ)
Scanner (TLS, SSH, VPN, Code) Có Có
Flow Analysis (PCAP → HNDL score) Có Có
Benchmarker (KEM, Signatures) Có Có
Roadmap + Chi phí + Tuân thủ Có Có
CLI Có Có
JSON output Có Có
REST API - Có
Web UI (React dashboard) - Có
Báo cáo HTML/PDF/SARIF - Có
Tóm tắt Điều hành - Có
Tuỳ chỉnh thương hiệu - Có

Cài đặt nhanh

pip install -e .

# Quét TLS
pqc-analyzer scan tls example.vn --port 443

# Phân tích PCAP (HNDL Radar) — cài thêm extra "flow"
pip install -e ".[flow]"
pqc-analyzer scan pcap capture.pcap -o flow_report.json

# Tạo lộ trình chuyển đổi (nhận cả JSON scanner lẫn flow)
pqc-analyzer roadmap ket_qua.json

# Chạy benchmark
pqc-analyzer benchmark kem --iterations 1000

Đối tượng sử dụng

Người dùng Nhu cầu Output
Kỹ sư IT/viễn thông Biết hệ thống dùng crypto gì, thay bằng gì Danh sách findings + benchmark
Kỹ sư bảo mật Đánh giá risk, compliance Risk matrix + kế hoạch xử lý
Nhà làm chính sách quản lý Tổng quan hạ tầng, ngân sách, timeline JSON (Enterprise: báo cáo điều hành + Web UI)
Nghiên cứu sinh Reproduce kết quả Raw data + JSON

Gặp lỗi hoặc có câu hỏi? Mở một issue: https://github.com/xuxu298/PQCAnalyzer/issues

Liên hệ support@vradar.io để sử dụng phiên bản Enterprise.


About

PQCAnalyzer is built and maintained by Nguyen Dong, founder of Vradar.io — an AI-assisted SOC platform with built-in post-quantum log transport (ML-KEM-768 + ML-DSA-65, FIPS 203/204) for enterprise customers in Vietnam and APAC.

For PQCAnalyzer Enterprise (REST API, Web UI, reports, on-prem deploy): support@vradar.io.


Developed by: Nguyen Dong — Founder of vradar.io | License: MIT

About

Scan your infrastructure for quantum-vulnerable cryptography. Get a migration roadmap. Maps findings to NIST FIPS 203/204.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

11 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages