KORTHEXDocumentation

Docs / ANALYSIS ENGINES

ANALYSIS ENGINES

Dataflow Engine

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The Dataflow Engine turns the flat list of findings into a directed graph: nodes are cryptographic assets (keys, certs, algorithms, call sites, services), edges are the relationships between them (generates, reads, encrypts-with, transmits-to, rotates-from, deprecated-by, ...). You can then ask the graph questions a per-file scan can't answer.

Questions It Answers

Where does this key go? - every service that reads it, every line that derives a new key from it. What depends on this certificate? - every endpoint, every config file, every code path that pins it. Which services still touch SHA-1 today? - live map across the project. Was this key ever transmitted unencrypted? - reachability query through the transmission edges. When was algorithm X introduced and when was it last rotated? - via the git-timeline view.

Edge Types

The graph supports 24 edge types covering source, runtime, configuration, and infrastructure relationships:

EdgeMeaning
GENERATESCode site that creates a new key, IV, or nonce.
READSCode site that consumes a previously-generated value.
IMPORTSCross-file or cross-module import path.
ENCRYPTS_WITHPlaintext value encrypted using a specific key reference.
DECRYPTS_WITHInverse of ENCRYPTS_WITH.
SIGNS_WITHSignature operation using a specific key.
VERIFIES_WITHSignature verification.
TRANSMITS_OVERValue sent over a network connection / channel.
STORES_INValue persisted to a config, database, or KMS.
DERIVES_FROMKDF / HKDF / PBKDF derivation.
ROTATES_FROMReplaces or supersedes an earlier value.
DESTROYSExplicit zeroization / wipe.
...and 12 moreCovering TLS handshake states, runtime hooks, attribute relationships.

Anomaly Queries

Built-in queries surface patterns a per-file scan cannot detect because they span multiple nodes: Key reused after destroy - a value zeroed in one path but referenced again later. Private key transmitted unencrypted - reachability from a key-gen node to a TRANSMITS_OVER edge on a plaintext channel. Nonce reused - the same nonce edge appearing across multiple ENCRYPTS_WITH operations. Key generated but never destroyed - GENERATES node without a downstream DESTROYS. Cert pinned in code but not in config - inconsistency between the IaC and the application layer.

Files & Output

CLI - four subcommands, and every one of them names its input by flag rather than by position: # Build from the latest report of a project korthex dataflow build --path /path/to/repo # Path query: how does this credential reach the database? korthex dataflow query --graph graph.kxg --from "secret:db-password" --to "service:billing-svc" # Anomalies in an existing graph korthex dataflow anomalies --graph graph.kxg # Export to DOT for Graphviz / external visualization korthex dataflow view graph.kxg --format dot > graph.dot Two shapes are worth knowing before you script against this. query is a path query and nothing else: it needs --graph , --from and --to together, and refuses the call if any of the three is missing. There is no one-ended form - "every service that reads this key" is not a query you can ask the CLI today. And view writes to standard output; it has no --output , so redirect it as above.

FilePurpose
.kxg.codeStatic source-code dataflow graph.
.kxg.binaryCompiled-binary dataflow graph.
.kxg.runtimeRuntime traces from a Runtime-Agent session.
.kxg.configConfiguration-file dataflow (Terraform, YAML, web.config, ...).
.kxg.tlsTLS-endpoint relationships (cert chains, cipher suites).
.kxg.gitGit-history dataflow: when algorithms were introduced, rotated, replaced.