Docs / CLI & SCANNING
CLI & SCANNING
Database Scanning
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex detects and analyzes 41 database types across 5 categories: relational, NoSQL, cloud, in-memory/cache, and key management systems (KMS). Findings include insecure connections, missing TLS/SSL, hardcoded credentials, weak authentication, missing encryption-at-rest, and key management policy violations.
Supported Databases
| Category | Databases | Detection Methods |
|---|---|---|
| Relational | PostgreSQL, MySQL, MariaDB, MSSQL, Oracle, SQLite, CockroachDB, DB2, SAP HANA, Informix, Teradata | Static analysis + wire protocol probing |
| NoSQL | MongoDB, Redis, Cassandra, Elasticsearch, Neo4j, ClickHouse, CouchDB, DynamoDB (API), Couchbase, InfluxDB, TimescaleDB | Static analysis + wire protocol probing |
| Cloud | AWS RDS/Aurora, Azure SQL, GCP Cloud SQL, DynamoDB, Cosmos DB, Firestore, Cloud Spanner, Azure Table Storage, GCP Bigtable | Static analysis (config/IAM) |
| In-Memory | Memcached, Hazelcast, Apache Ignite, Valkey | Static analysis + protocol probing |
| KMS | AWS KMS, Azure Key Vault, GCP KMS, HashiCorp Vault, CyberArk, Thales CipherTrust | Static analysis (config/policy) |
Discovery
Korthex discovers database usage from multiple sources: dependency manifests (package.json, build.gradle, requirements.txt), Docker Compose files, Kubernetes manifests, ORM configurations, environment variables, and connection strings in configuration files. Database scanning is a static analysis feature by default. Enable enableLiveProbe in your configuration to test running database instances via native wire protocol probing (requires network access to the database).
Security Checks
| Check | What it Detects |
|---|---|
| SSL/TLS | Unencrypted connections, sslmode=disable, missing TLS configuration |
| Credentials | Hardcoded passwords in connection strings, config files, environment templates |
| Authentication | Weak auth methods, default credentials, missing auth configuration |
| Encryption-at-Rest | Missing TDE, unencrypted storage, absent key management |
| PII Exposure | Sensitive data fields without column-level encryption |
| Key Management | Missing key rotation, expired keys, weak key policies (KMS) |
| Backup Encryption | Unencrypted backup configurations |