KORTHEXDocumentation

Docs / ANALYSIS ENGINES

ANALYSIS ENGINES

Impact Engine

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The Impact Engine takes a flat list of findings ("MD5 detected at auth.py:42") and translates it into business language ("this finding affects the customer-payment service and represents approximately 250k of remediation effort"). It scores blast radius, estimates engineer-hours, walks dependency cascades, and renders the result for the right audience.

Inputs

The engine needs three things to produce a useful business-impact report: The scan findings (a .krx report). A business-context file describing your services, dependencies, and what each is worth (revenue-bearing, customer-facing, compliance-critical, internal-only). A local CVE / KEV / EPSS cache (bundled with Korthex; refreshed periodically - see the Air-Gapped section). { "services": [ { "name": "payments-svc", "files": ["services/payments/**"], "valueAtRisk": "high", "compliance": ["PCI-DSS"], "dependsOn": ["auth-svc", "billing-svc"] }, { "name": "auth-svc", "files": ["services/auth/**"], "valueAtRisk": "critical", "compliance": ["SOC2", "HIPAA"] } ] }

What It Produces

Per-finding risk scores - CVSS-style composite: severity x confidence x CVE multiplier x business multiplier. Engineer-hour estimates - with seniority-adjusted breakdowns. Critical-path analysis - if service X breaks, what else fails downstream? Attack-surface score - aggregated metric for trend reporting. Compliance impact - mapped to PCI-DSS, HIPAA, GDPR, SOC2. Trend persistence - direction-of-travel between scans (improving / degrading / flat).

Audience-Tailored Reports

The same data renders five different ways depending on who's reading. Each variant is a separate render with appropriate detail level, terminology, and chart selection - not a stripped-down view of the technical report. # Generate the CISO-flavored report korthex impact report latest --audience CISO --output ciso-report.json # Generate the executive board summary as PDF korthex impact report latest --audience BOARD --format pdf --output board-2026-05.pdf

AudienceFraming
CISOSecurity posture, threat landscape, compliance gap analysis.
CTOTechnology debt, migration roadmap, engineering capacity.
CFOFinancial: remediation cost, breach-cost exposure, vendor-cost optimization.
BOARDExecutive summary: 1 page, leading indicators, asks.
DEFAULT (engineering)Full technical report: findings + remediation steps + code locations.