Pshtt was developed to push organizations, including government departments, to adopt HTTPS across the enterprise.

The pshtt project is a collaboration between GSA's 18F and the DHS National Cybersecurity Assessments and Technical Services team. The tool pshtt is pronounced as the word pushed.

Usage and audience

pshtt is commonly used for security assessment or web application analysis. Target users for this tool are pentesters, security professionals, and system administrators.


  • Command line interface
  • CSV output supported
  • JSON output supported

Example usage and output

pshtt [options] DOMAIN...
pshtt [options] INPUT

pshtt --output=homeland.csv --debug
pshtt --sorted current-federal.csv

The review and analysis of this project resulted in the following remarks for this security tool:


  • + More than 500 GitHub stars
  • + The source code of this software is available


Supported operating systems

Pshtt is known to work on Linux and macOS.

pshtt alternatives

Similar tools to pshtt:


Certificate Transparency

Google's Certificate Transparency project audits the way SSL/TLS certificates are used and its underlying cryptographic system.



Cipherscan is a tool to test the ordering of SSL/TLS ciphers on a given target. It tests the major versions of SSL, TLS, and any extensions of these protocols.

