Docs / ANALYSIS ENGINES
ANALYSIS ENGINES
Dataflow Engine
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Dataflow Engine turns the flat list of findings into a directed graph: nodes are cryptographic assets (keys, certs, algorithms, call sites, services), edges are the relationships between them (generates, reads, encrypts-with, transmits-to, rotates-from, deprecated-by, ...). You can then ask the graph questions a per-file scan can't answer.
Questions It Answers
Where does this key go? - every service that reads it, every line that derives a new key from it. What depends on this certificate? - every endpoint, every config file, every code path that pins it. Which services still touch SHA-1 today? - live map across the project. Was this key ever transmitted unencrypted? - reachability query through the transmission edges. When was algorithm X introduced and when was it last rotated? - via the git-timeline view.
Edge Types
The graph supports 24 edge types covering source, runtime, configuration, and infrastructure relationships:
| Edge | Meaning |
|---|---|
| GENERATES | Code site that creates a new key, IV, or nonce. |
| READS | Code site that consumes a previously-generated value. |
| IMPORTS | Cross-file or cross-module import path. |
| ENCRYPTS_WITH | Plaintext value encrypted using a specific key reference. |
| DECRYPTS_WITH | Inverse of ENCRYPTS_WITH. |
| SIGNS_WITH | Signature operation using a specific key. |
| VERIFIES_WITH | Signature verification. |
| TRANSMITS_OVER | Value sent over a network connection / channel. |
| STORES_IN | Value persisted to a config, database, or KMS. |
| DERIVES_FROM | KDF / HKDF / PBKDF derivation. |
| ROTATES_FROM | Replaces or supersedes an earlier value. |
| DESTROYS | Explicit zeroization / wipe. |
| ...and 12 more | Covering TLS handshake states, runtime hooks, attribute relationships. |
Anomaly Queries
Built-in queries surface patterns a per-file scan cannot detect because they span multiple nodes: Key reused after destroy - a value zeroed in one path but referenced again later. Private key transmitted unencrypted - reachability from a key-gen node to a TRANSMITS_OVER edge on a plaintext channel. Nonce reused - the same nonce edge appearing across multiple ENCRYPTS_WITH operations. Key generated but never destroyed - GENERATES node without a downstream DESTROYS. Cert pinned in code but not in config - inconsistency between the IaC and the application layer.
Files & Output
CLI - four subcommands, and every one of them names its input by flag rather than by position: # Build from the latest report of a project korthex dataflow build --path /path/to/repo # Path query: how does this credential reach the database? korthex dataflow query --graph graph.kxg --from "secret:db-password" --to "service:billing-svc" # Anomalies in an existing graph korthex dataflow anomalies --graph graph.kxg # Export to DOT for Graphviz / external visualization korthex dataflow view graph.kxg --format dot > graph.dot Two shapes are worth knowing before you script against this. query is a path query and nothing else: it needs --graph , --from and --to together, and refuses the call if any of the three is missing. There is no one-ended form - "every service that reads this key" is not a query you can ask the CLI today. And view writes to standard output; it has no --output , so redirect it as above.
| File | Purpose |
|---|---|
| .kxg.code | Static source-code dataflow graph. |
| .kxg.binary | Compiled-binary dataflow graph. |
| .kxg.runtime | Runtime traces from a Runtime-Agent session. |
| .kxg.config | Configuration-file dataflow (Terraform, YAML, web.config, ...). |
| .kxg.tls | TLS-endpoint relationships (cert chains, cipher suites). |
| .kxg.git | Git-history dataflow: when algorithms were introduced, rotated, replaced. |