Educator manuscriptAugust 2026

Post-Quantum
Pentest

Ethical hacking and resilience testing for the quantum transition. A field handbook that turns cryptographic uncertainty into observable, defensible evidence.

By Prof. Dr. Šarūnas Grigaliūnas
Kaunas University of Technology

A retro technical-comic robot testing a classical padlock beside a post-quantum lattice shield
Field test 001 · lock, lattice, evidence
140pages
15chapters
12safe labs
15editable figures

The recurring discipline

Observe the asset. Test the claim. Preserve the evidence. State the limitation.

Never test systems without explicit written authorisation.
01

The handbook

A complete learning path, from threat to field programme.

Each chapter opens with outcomes, develops a testable argument, connects it to a local laboratory, and closes with educator prompts.

Part IChapters 1–4

Threat & method

Reframe quantum risk as a present evidence problem, then build scope, inventory, and a repeatable PAREX assessment.

Part IIChapters 5–10

Technical testing

Test Transit, Use, and Rest; hybrid negotiation; implementation leakage; signatures, certificates, and long-term identity.

Part IIIChapters 11–12

Assurance & decisions

Place QKD inside a layered assurance model and turn evidence into findings, retest criteria, and board decisions.

Part IVChapters 13–15

Teaching & fieldwork

Run an evidence-led capstone, teach strict legal boundaries, and move from a course to a sustainable field programme.

Interactive field note

Is the migration window already open?

Use Mosca's timing inequality as a planning prompt. It does not predict a quantum computer; it exposes assumptions that require an owner and a review date.

15 + 5 > 12Action window open

8 years of planning pressure should be assigned and evidenced now.

02

Hands-on practice

Twelve labs. No external targets.

Deterministic fixtures, standard-library Python, and two loopback-bound containers keep classroom work reproducible.

01

Scope & ethics

Static + Python

Write a rules-of-engagement gate before any probe runs.

02

Crypto inventory

Fixtures + Python

Turn scattered configuration into a cryptographic bill of materials.

03

Risk window

CSV + Python

Prioritise assets using lifetime, exposure, and migration assumptions.

04

Transit profile

Docker + Python

Compare advertised hybrid support with observed loopback evidence.

05

Hybrid negotiation

JSON + Python

Exercise success, downgrade, and fail-closed state transitions.

06

Source discovery

Static repository

Find algorithms, providers, build settings, and evidence gaps.

07

Timing channel

Local Python

Measure a deliberate leak without attacking a real implementation.

08

Signature lifecycle

JSON + Python

Map creation, preservation, validation, and migration obligations.

09

PassQ case study

Threat modelling

Separate published design claims from evidence requests.

10

Reporting

JSON → Markdown

Render a technical finding and an executive decision record.

11

QCI architecture

Topology + Python

Validate layers, trust assumptions, and classical authentication.

12

Integrated capstone

Docker + Python

Collect, normalise, analyse, and defend a complete local assessment.

Download all labs
03

For educators

Teach judgement, not tool theatre.

Designed for university modules, professional workshops, and guided self-study alongside current certification material.

ProgrammeUseful overlapBoundary
CEHEthics, reconnaissance, vulnerability analysis, cryptography, reportingUse the current official blueprint.
OPST / OPSAScope, operational channels, evidence, metrics, analysisUse current OSSTMM and ISECOM terminology.
PenTest+Engagement, discovery, attacks, scripting, remediationPQC extends rather than replaces PT0-003.

Open course materials

Read. Edit. Teach. Test locally.

Every package is versioned with the manuscript and ready for local review.