Docs / ANALYSIS ENGINES
ANALYSIS ENGINES
Planner Engine
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Planner takes a scan report and produces a concrete migration plan: for every weak algorithm, which file/line to change, what to replace it with, in what order, by when, and how long it will take. The plan is rendered as PDF for stakeholders and as a structured .krx file for the Auto Migration engine to execute (V2).
Plan Items by Domain
A plan is a topologically-ordered list of items, each scoped to a specific remediation domain:
| Item type | Captures |
|---|---|
| Code | File + line + algorithm to replace, with the recommended replacement. |
| Config | Config-file key paths and new values (web.config, application.properties, ...). |
| TLS | Certificate rotation, endpoint reconfiguration, cipher-suite changes. |
| Git | Historical-commit remediation (with explicit destructive-action confirmation). |
| Hybrid | Multi-domain coordinated changes (e.g., config + code + git revert as one unit). |
Per-Item Information
Every item carries the same set of properties so plans are easy to consume programmatically: Severity - inherited from the source finding. Replacement - recommended algorithm + key length + mode. Deadline - calibrated to NIST PQC 2030 + per-algorithm deprecation dates. Engineer-hours - estimated effort with confidence interval. Dependencies - ordered edges to other plan items (do foundational changes first). Verification steps - tests to write or run after the migration.
Using the Planner
Plan creation, preview and execution are separate top-level commands. There is no migrate plan subcommand: migrate is itself the executor and is flag-based. # Generate a plan from the latest scan korthex plan create # List the stored plans and read one back korthex plan list korthex plan view <plan-id> # Preview the changes without writing them korthex migrate --dry-run # Execute the plan, optionally narrowed by severity korthex migrate --plan <plan-id> --severity CRITICAL,HIGH # Execute a single finding, then watch or stop the run korthex migrate --single finding-123 korthex migrate --status korthex migrate --cancel korthex deploy --plan <plan-id> is the second route to rolling a plan out, with korthex deploy status for progress. korthex migrate works against the latest report and gives you the dry-run, severity filter and single-finding paths; deploy takes the plan id and nothing else. Not available from the CLI today: rendering a plan to PDF, a review gate before execution, and accepting or reverting an applied migration. --cancel stops a running migration; it does not roll back one that already completed.
ML Re-prioritization (Optional)
By default, the plan is ordered by deadline + severity + dependency edges. With the Neural Network Engine enabled, items can be re-prioritized based on predicted impact: two items with the same deadline get re-ordered so the one most likely to produce a measurable security improvement comes first. There is no CLI flag for this today. The planner applies its ordering when the Neural Network Engine is enabled; it is not selectable per run, and --reprioritize-with-nn does not exist. Re-prioritization is a hint, not a hard reorder - dependency edges are still respected. If item B depends on item A, item B never appears before item A in the output regardless of ML scores.