PQC Discovery Details

The BigFix Quantum Risk Analyzer scanner provides comprehensive detection and analysis of post-quantum cryptographic implementations, preparing your infrastructure for the quantum-safe future.

Key Exchange Group Detection - 35+ PQC Groups Covered

The scanner uses a dual-mode detection strategy. For IANA-standardized groups it completes a full TLS 1.3 handshake as a PQC-capable client. For experimental and non-IANA groups (BIKE, FrodoKEM, draft-era hybrids) it identifies the server's required group via passive inspection of TLS HelloRetryRequest messages - ensuring no TLS server goes undetected regardless of its KEX requirements. Validated against all 721 ports of the Open Quantum Safe interop server.

Full Handshake (IANA Standard)

  • X25519MLKEM768
  • SecP256r1MLKEM768
  • SecP384r1MLKEM1024
  • MLKEM512 / MLKEM768 / MLKEM1024
  • All ECDHE, DHE, RSA groups

Passive HRR Detection

  • BIKE-L1 / L3 / L5 + classical hybrids
  • FrodoKEM-640/976/1344 (AES & SHAKE)
  • Draft ML-KEM hybrids (X25519/P-256/BP-256/P-384/BP-384/X448/BP-512/P-521)

Classical KEX (Full Handshake)

  • P-256, P-384, P-521
  • X25519, X448
  • ffdhe2048 - ffdhe8192
  • DHE, RSA key exchange

Digital Signature Algorithms

Falcon (NIST FIPS 206)

  • falcon512
  • falcon1024
  • falconpadded512
  • falconpadded1024

Dilithium (NIST FIPS 204)

  • dilithium2
  • dilithium3
  • dilithium5

MAYO (Multivariate)

  • mayo1
  • mayo2
  • mayo3
  • mayo5

SPHINCS+ (Hash-based)

  • sphincssha2*
  • sphincsshake*
  • 128/192/256 variants
  • fsimple/ssimple modes

Complete Cipher Suite Intelligence Database

The BigFix Quantum Risk Analyzer online documentation provides a comprehensive, searchable database of 300+ cipher suites with detailed security analysis, quantum readiness assessments, and compliance information.