Docs / ANALYSIS ENGINES
ANALYSIS ENGINES
Inventory Engine
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Inventory Engine builds an authoritative inventory of every cryptographic asset in your project - every algorithm use, every certificate, every TLS endpoint, every key in code or config - and writes it as an encrypted .kxi snapshot alongside the scan report. This is the engine that answers "what cryptography are we actually using, in which files, at what strength?" The inventory is a Dashboard surface, not a CLI verb . The CLI's job is to produce the snapshot - korthex scan . writes it - and the Dashboard's job is to read it. Both clients carry the same Inventory screen with four views: Desktop app: Inventory in the sidebar. Web Dashboard: Inventory (the separate CBOM page shows the same asset list in bill-of-materials shape).
| View | What it shows |
|---|---|
| Files | Per-file rollup: which algorithms and keys appear in which file. |
| Census | One row per distinct algorithm: family, strength, occurrence count, NIST status, PQC flag. Filter by family, search by name. |
| PQC Readiness | The PQC-safe share of the inventory, plus the ready list and the at-risk list. |
| Snapshot Diff | Compare the loaded snapshot against an earlier one. |
What It Inventories
| Category | Examples captured |
|---|---|
| Algorithms | Every distinct algorithm + mode + key-length combination, with usage counts. |
| Certificates | X.509 certs in code, config, and TLS endpoints. Validity, signing chain, key type. |
| TLS endpoints | Hostnames, ports, cipher suites, protocol versions, cert pinning state. |
| Top crypto files | Files containing the highest density of crypto operations (audit hotspots). |
| Binary findings | Algorithms discovered in shipped artifacts (.dll, .so, .jar, .wasm). |
| Git history | Algorithms introduced or removed across commits. |
| Runtime processes | Live algorithm choice from a Runtime-Agent session. |
PQC Readiness Score
The PQC Readiness view scores the snapshot: what share of the inventoried algorithms is already post-quantum safe. It shows the percentage as a bar, then two lists - the algorithms that are already PQC-safe, and the quantum-vulnerable ones still in use. Two things are worth knowing before you quote the number: It is a ratio over distinct algorithms, not over call sites. Ten RSA call sites and one RSA algorithm count once. When you need the call-site weight, read the occurrence column in the Census view. Hashes are excluded from the at-risk list - they still count in the denominator, but a hash function is not a quantum-migration item the way a key-exchange or signature primitive is. An empty inventory has no ratio, and Korthex says so rather than reporting 0%. "Not measured" and "measured, and it is zero" are different answers and are rendered differently.
CBOM / SBOM Export
The Inventory engine emits the snapshot in two standard bill-of-materials formats. What a client hands you today is a third thing - be precise about which one you need. Today: open the Inventory screen and use Export CBOM . Name the target .json for the JSON rows or .csv for the spreadsheet form; the export is permission-gated on findings.read . Planned: the CycloneDX and SPDX emitters get a CLI surface. The commands below are the interface they will carry - they are not available yet, and the CLI will reject them until they are. # Planned - not yet available. Use Export CBOM in the Dashboard today. korthex inventory export latest --format cyclonedx --output cbom.cdx.json korthex inventory export latest --format spdx --output sbom.spdx.json
| Format | Standard | Status |
|---|---|---|
| CycloneDX 1.5 JSON | OWASP Crypto-BOM profile | Emitted by the engine. Not yet reachable from the CLI or the Dashboard - the CLI surface is being built. |
| SPDX 2.3 JSON | SPDX 2.3 with package extensions | Emitted by the engine. Not yet reachable from a client. |
| Korthex JSON / CSV | Native per-usage rows | What Export CBOM writes today. One row per usage: algorithm, type, file, line, language, deprecated, PQC-safe, NIST status, severity, key size, mode. |
Snapshot Diffs
Inventory snapshots compare cleanly across scans. Open the Inventory screen, pick Snapshot Diff , and choose the earlier .kxi . The comparison is per algorithm and reports five things: .kxi snapshots are encrypted. The Desktop app decrypts them with the workspace master key, so it diffs a snapshot straight from disk - without a master key loaded, the Diff action tells you so instead of failing quietly. The Web Dashboard currently needs an already-decrypted snapshot and rejects an encrypted payload with an inline error.
| Section | Meaning |
|---|---|
| Added | Algorithms present now that the earlier snapshot did not have. |
| Removed | Algorithms the earlier snapshot had and this one does not. |
| Unchanged | How many algorithms carried over untouched (a count, not a list). |
| Newly deprecated | Algorithms that were fine before and are flagged deprecated now. |
| Newly PQC-safe | Algorithms that crossed over to a post-quantum primitive. |