KORTHEXDocumentation

Docs / CLI & SCANNING

CLI & SCANNING

CLI Reference

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The Korthex CLI is the primary interface for scanning, reporting, and managing cryptographic findings. All commands follow the pattern: korthex <command> [subcommand] [options] Run korthex --help for the list of commands, or korthex <command> --help for the detailed usage of any one of them. There is no help verb - help is an option, not a command.

scan

The core command. Scans a directory, repository, or file for cryptographic usage and vulnerabilities. korthex scan <path> [options] Engine selection, language filters, exclude patterns, thread count and the delta scan are configuration , not flags: set engines , globalFilters , global.maxThreads , incremental and fullRescan in the scanner config and pass it with --config . In particular there is no --no-cache and no --full-rescan flag. Examples # Scan the current directory, JSON on stdout korthex scan . --json # Gate a build: fail on any critical, allow up to 5 high korthex scan . --gate --max-critical 0 --max-high 5 # Scan with a custom config and write a SARIF file korthex scan ./src --config ./korthex.scan.json --format sarif -o findings.sarif

check

Runs a scan and exits with a non-zero code if findings exceed a threshold. Designed for CI/CD gate checks. korthex check <path> [options] --max-critical and --max-high belong to korthex scan , not to check . Passing them here is a usage error (exit 4), and a pipeline that does so never gates at all. Use --fail-on for the severity threshold. - name: Korthex Security Check run: korthex check . --fail-on high

watch

Watches a directory and tells you when it is worth re-scanning. It does not re-scan: after a batch of changes it prints a reminder to run korthex scan , and the scan stays your call. The watch covers the directory you name, not the tree beneath it. # Watch the active project korthex watch # Watch a specific directory and print every file event korthex watch --path /path/to/repo --verbose

diff

Compares two scan reports. Both are named by flag, not by position, and both are decrypted with the stored master key before they are compared. korthex diff --before before.krx --after after.krx The zero-argument form is not a diff. korthex diff without flags compares nothing: it prints the two most recent report entries under the heading "Diff of latest two reports". Pass both paths when you want an actual comparison.

reports

List, export, or delete scan reports. The command is reports , it is flag-driven, and it has no subcommands. # List every report in the report directory korthex reports # Show the most recent one korthex reports --latest # Decrypt a report to plain JSON (without an outfile: <path>.json) korthex reports --export .korthex/reports/scan_20260406.krx report.json # Delete a report - refuses anything that is not .krx or .kxd korthex reports --delete old_report.krx

decrypt

Read a native encrypted report back into plain JSON. This is the low-level counterpart to reports --export : same result, but it takes an explicit key and can read just the header. # Decrypt to stdout korthex decrypt report.krx # Decrypt to a file korthex decrypt report.krx --output report.json # Header only - no key required korthex decrypt report.krx --header There is no export verb. Converting findings into a portable format happens at scan time - korthex scan . --format json , korthex check . --format sarif - or by decrypting the native report as shown above.

config

Create, validate, migrate or edit the project configuration file, korthex.json , in the current directory. These are flags, not subcommands. korthex config [--init] [--validate [--strict]] [--migrate] [--set <key> <value>] [--json] # Create the default config korthex config --init # Validate it the way the engine will read it korthex config --validate --strict # Change one value korthex config --set maxFiles 50000

policy

Manage organizational security policies. Policies define which algorithms, key sizes, and configurations are permitted. korthex policy <subcommand>

SubcommandDescription
validate <file>Validate a .kxp policy file.
apply <file>Apply a policy to the current project.
check <report>Check a report against the active policy.
showDisplay the current active policy.

migrate

Automated migration planning and code generation for transitioning to quantum-safe cryptography. Coming in V2 korthex migrate <subcommand> [options] The migrate command family is available in Korthex V2. In V1, use the scan and report commands to identify what needs to change.

SubcommandDescription
plan <report>Generate a migration plan from a scan report.
execute <plan>Execute a migration plan with automated code generation.
simulate <plan>Simulate migration without writing changes.
impact <plan>Estimate the impact of a migration on the codebase.