← All cheat sheets

SSLYZE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

SSLyze is a fast and powerful SSL/TLS scanning tool and Python
library. It analyzes SSL/TLS server configurations, identifies
vulnerabilities, and checks certificate validity.

BASIC USAGE#

sslyze <target>                  # Scan with defaults
sslyze <target>:8443             # Custom port
sslyze --regular <target>        # Regular scan (most useful)

SCAN COMMANDS#

sslyze --regular <target>        # Common scan commands combined
sslyze --certinfo <target>       # Certificate information
sslyze --sslv2 <target>          # Test SSLv2 support
sslyze --sslv3 <target>          # Test SSLv3 support
sslyze --tlsv1 <target>          # Test TLS 1.0 support
sslyze --tlsv1_1 <target>        # Test TLS 1.1 support
sslyze --tlsv1_2 <target>        # Test TLS 1.2 support
sslyze --tlsv1_3 <target>        # Test TLS 1.3 support

VULNERABILITY CHECKS#

sslyze --heartbleed <target>     # Test for Heartbleed (CVE-2014-0160)
sslyze --openssl_ccs <target>    # Test for CCS injection (CVE-2014-0224)
sslyze --robot <target>          # Test for ROBOT attack
sslyze --fallback <target>       # Test for downgrade attacks
sslyze --reneg <target>          # Test renegotiation support
sslyze --compression <target>    # Test for CRIME (compression)
sslyze --early_data <target>     # Test TLS 1.3 early data (0-RTT)

CERTIFICATE OPTIONS#

sslyze --certinfo <target>       # Full certificate info
sslyze --certinfo --ca_file=ca.pem <target>
                                 # Verify against custom CA

CONNECTION OPTIONS#

sslyze --starttls=smtp <target>  # STARTTLS for SMTP
sslyze --starttls=imap <target>  # STARTTLS for IMAP
sslyze --starttls=pop3 <target>  # STARTTLS for POP3
sslyze --starttls=ftp <target>   # STARTTLS for FTP
sslyze --starttls=xmpp <target>  # STARTTLS for XMPP
sslyze --starttls=ldap <target>  # STARTTLS for LDAP
sslyze --sni=<hostname> <target> # Set SNI hostname
sslyze --xmpp_to=<domain> <target>
                                 # Set XMPP destination

CLIENT AUTHENTICATION#

sslyze --cert=client.pem <target>
                                 # Client certificate for auth
sslyze --key=client.key <target> # Client key
sslyze --keyform=PEM <target>    # Key format
sslyze --pass=<password> <target>
                                 # Key passphrase

OUTPUT OPTIONS#

sslyze --json_out=results.json <target>
                                 # JSON output file
sslyze --targets_in=hosts.txt    # Scan targets from file
sslyze --slow_connection         # Slower but more reliable
sslyze --quiet <target>          # Minimal output

MULTIPLE TARGETS#

sslyze host1.com host2.com host3.com
                                 # Scan multiple hosts
sslyze --targets_in=targets.txt  # From file (one per line)

EXAMPLES#

# Full regular scan
sslyze --regular example.com

# Scan SMTP server with STARTTLS
sslyze --regular --starttls=smtp mail.example.com:25

# Vulnerability-focused scan
sslyze --heartbleed --openssl_ccs --robot --compression example.com

# Certificate chain validation
sslyze --certinfo --ca_file=/etc/ssl/certs/ca-certificates.crt example.com

# JSON output for automation
sslyze --regular --json_out=scan_results.json example.com

# Scan with client certificate
sslyze --regular --cert=client.pem --key=client.key example.com

# Multiple targets from file
sslyze --regular --targets_in=targets.txt --json_out=results.json

PYTHON API#

# SSLyze can also be used as a Python library:
from sslyze import ServerScanRequest, Scanner
from sslyze import ScanCommand

server = ServerScanRequest(server_location=...)
scanner = Scanner()
scanner.queue_scans([server])

KEY FINDINGS TO REPORT#

# CRITICAL:
# - SSLv2/SSLv3 enabled
# - Heartbleed vulnerable
# - ROBOT attack possible
# - CCS Injection vulnerable
# - NULL/export ciphers

# HIGH:
# - TLS 1.0/1.1 enabled
# - RC4 ciphers supported
# - Self-signed certificate
# - Expired certificate

# MEDIUM:
# - CRIME (compression enabled)
# - Weak DH parameters (<2048 bit)
# - Missing OCSP stapling
# - Insecure renegotiation

NOTES#

- Python-based, fast concurrent scanning
- Can be used as CLI tool or Python library
- Non-destructive scanning (safe for production)
- Supports client certificate authentication
- JSON output ideal for CI/CD integration
- More detailed than sslscan for compliance reporting
- Actively maintained and updated