LogoSwissSign CLM
Discovery

Overview

The discovery and import operations that feed certificates into Horizon.

Discovery operations feed Horizon with certificates found on your hosts or network, along with metadata such as IP address, hostname, and TLS configuration. All discovery operations require a campaign configured in Horizon in advance.

For advanced campaign configuration, grading policies, and discovery data management, refer to the Evertrust Horizon documentation.

Operations

OperationCommandWhat it does
Local scanhorizon-cli localscanScans the local machine for certificates in PEM/DER files or Windows certificate stores.
Network scanhorizon-cli netscanReads host/port targets from the Horizon campaign, attempts TLS handshakes, and reports found certificates.
nmap importhorizon-cli importscan nmapImports the XML output of an nmap scan run with the ssl-cert plugin - the recommended method for cipher suite coverage.
Local importhorizon-cli localimportImports certificates from local PEM, PKCS#12, or CSV files into Horizon without discovery metadata.
Network importhorizon-cli netimportImports certificates from third-party systems (DigiCert, AWS ACM, Azure Key Vault, and others).

On this page