Docs / CLI & SCANNING
CLI & SCANNING
CLI Reference
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Korthex CLI is the primary interface for scanning, reporting, and managing cryptographic findings. All commands follow the pattern: korthex <command> [subcommand] [options] Run korthex --help for the list of commands, or korthex <command> --help for the detailed usage of any one of them. There is no help verb - help is an option, not a command.
scan
The core command. Scans a directory, repository, or file for cryptographic usage and vulnerabilities. korthex scan <path> [options] Engine selection, language filters, exclude patterns, thread count and the delta scan are configuration , not flags: set engines , globalFilters , global.maxThreads , incremental and fullRescan in the scanner config and pass it with --config . In particular there is no --no-cache and no --full-rescan flag. Examples # Scan the current directory, JSON on stdout korthex scan . --json # Gate a build: fail on any critical, allow up to 5 high korthex scan . --gate --max-critical 0 --max-high 5 # Scan with a custom config and write a SARIF file korthex scan ./src --config ./korthex.scan.json --format sarif -o findings.sarif
check
Runs a scan and exits with a non-zero code if findings exceed a threshold. Designed for CI/CD gate checks. korthex check <path> [options] --max-critical and --max-high belong to korthex scan , not to check . Passing them here is a usage error (exit 4), and a pipeline that does so never gates at all. Use --fail-on for the severity threshold. - name: Korthex Security Check run: korthex check . --fail-on high
watch
Watches a directory and tells you when it is worth re-scanning. It does not re-scan: after a batch of changes it prints a reminder to run korthex scan , and the scan stays your call. The watch covers the directory you name, not the tree beneath it. # Watch the active project korthex watch # Watch a specific directory and print every file event korthex watch --path /path/to/repo --verbose
diff
Compares two scan reports. Both are named by flag, not by position, and both are decrypted with the stored master key before they are compared. korthex diff --before before.krx --after after.krx The zero-argument form is not a diff. korthex diff without flags compares nothing: it prints the two most recent report entries under the heading "Diff of latest two reports". Pass both paths when you want an actual comparison.
reports
List, export, or delete scan reports. The command is reports , it is flag-driven, and it has no subcommands. # List every report in the report directory korthex reports # Show the most recent one korthex reports --latest # Decrypt a report to plain JSON (without an outfile: <path>.json) korthex reports --export .korthex/reports/scan_20260406.krx report.json # Delete a report - refuses anything that is not .krx or .kxd korthex reports --delete old_report.krx
decrypt
Read a native encrypted report back into plain JSON. This is the low-level counterpart to reports --export : same result, but it takes an explicit key and can read just the header. # Decrypt to stdout korthex decrypt report.krx # Decrypt to a file korthex decrypt report.krx --output report.json # Header only - no key required korthex decrypt report.krx --header There is no export verb. Converting findings into a portable format happens at scan time - korthex scan . --format json , korthex check . --format sarif - or by decrypting the native report as shown above.
config
Create, validate, migrate or edit the project configuration file, korthex.json , in the current directory. These are flags, not subcommands. korthex config [--init] [--validate [--strict]] [--migrate] [--set <key> <value>] [--json] # Create the default config korthex config --init # Validate it the way the engine will read it korthex config --validate --strict # Change one value korthex config --set maxFiles 50000
policy
Manage organizational security policies. Policies define which algorithms, key sizes, and configurations are permitted. korthex policy <subcommand>
| Subcommand | Description |
|---|---|
| validate <file> | Validate a .kxp policy file. |
| apply <file> | Apply a policy to the current project. |
| check <report> | Check a report against the active policy. |
| show | Display the current active policy. |
migrate
Automated migration planning and code generation for transitioning to quantum-safe cryptography. Coming in V2 korthex migrate <subcommand> [options] The migrate command family is available in Korthex V2. In V1, use the scan and report commands to identify what needs to change.
| Subcommand | Description |
|---|---|
| plan <report> | Generate a migration plan from a scan report. |
| execute <plan> | Execute a migration plan with automated code generation. |
| simulate <plan> | Simulate migration without writing changes. |
| impact <plan> | Estimate the impact of a migration on the codebase. |