Key Discovery

Can CAP identify hard-coded keys?

CAP combines static scanning with dynamic tracing to identify hard-coded keys and eliminate false positives.

Can CAP identify unprotected private/encryption keys or those that use a default vendor PIN/passcode?

Yes. CAP detects default passwords and unencrypted private keys on filesystems. Additionally, CAP also evaluates the security of every keystore credential used by the application, giving an estimation for the computational resources that would be required to break into that specific keystore type with that credential leveraging the latest Hashcat benchmarks.

Can CAP find PGP keys?


