KORTHEXDocumentation

Docs / CLI & SCANNING

CLI & SCANNING

Scanning

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex uses a multi-engine scanning architecture. Each engine specializes in a different aspect of cryptographic analysis, and results from all engines are merged into a unified finding set with cross-engine deduplication.

Scan Engines

Engine selection is a configuration block, not a flag. There is no --engines switch: put the toggles under engines.subEngines in a config file and pass it with --config . The config keys are the ones in the table above, so codeAnalysis and tlsCert are what an AST-plus-TLS run leaves enabled. At least one engine has to stay on, otherwise the scan is refused before a single file is read. See Configuration for the full block.

EngineConfig keyAnalyzesDetects
ASTcodeAnalysisSource code abstract syntax treesCrypto API calls, algorithm strings, key sizes, mode parameters
Binarybinary.NET IL, JVM bytecode, native binariesCompiled-in crypto usage, embedded keys, algorithm constants
RuntimeruntimeDynamic execution tracesRuntime crypto operations, certificate validation, TLS handshakes
TLStlsCertNetwork endpoints, certificate chainsWeak cipher suites, expiring certs, non-PQC TLS configurations
Git HistorygitHistoryRepository history, deleted filesPreviously committed secrets, removed crypto code, key rotations
ConfigconfigConfiguration files, environment templatesHardcoded secrets, weak algorithm settings, insecure defaults
Databasedatabase41 database types (relational, NoSQL, cloud, KMS)Insecure connections, missing TLS, hardcoded credentials, weak auth, encryption-at-rest

Scan Modes

ModeDescriptionUse Case
Incremental (default)Re-analyzes files whose content hash changed, plus everything that transitively imports them; the rest is served from the findings cache. Emits the same artifacts as a full scan.Every scan, unless you opt out
Full ScanAnalyzes the entire codebase. Requested with fullRescan: true, and entered automatically whenever no usable cache snapshot exists.First scan, audit, compliance evidence
Watch ModeContinuous file-watching that re-runs the incremental path on change.Real-time IDE feedback
TargetedScans a single file or specific directory.Investigating a specific finding

Language Support

Korthex supports 18 programming languages with dedicated AST parsers and crypto-library awareness:

LanguageFile ExtensionsKey Libraries Detected
JavaScript.js, .mjs, .cjscrypto, node:crypto, SubtleCrypto, CryptoJS, sjcl, forge
TypeScript.ts, .tsxSame as JavaScript + type-aware analysis
C#.csSystem.Security.Cryptography, BouncyCastle, NSec
Java.javajavax.crypto, java.security, BouncyCastle, Tink
Python.pycryptography, pycryptodome, hashlib, hmac, ssl
Go.gocrypto/*, x/crypto/*, tls
PHP.phpopenssl_*, mcrypt_*, sodium_*, hash()
Ruby.rbOpenSSL, Digest, RbNaCl
Rust.rsring, rust-crypto, openssl, sodiumoxide, aes-gcm
Kotlin.kt, .ktsjavax.crypto, BouncyCastle, Tink
Scala.scalajavax.crypto, BouncyCastle, tsec
C++.cpp, .cc, .cxx, .h, .hppOpenSSL, Botan, Crypto++, libsodium, wolfSSL
C.c, .hOpenSSL, libsodium, wolfSSL, mbedTLS
Swift.swiftCryptoKit, CommonCrypto, Security.framework
Dart.dartpointycastle, crypto, encrypt
VB.NET.vbSystem.Security.Cryptography
COBOL.cbl, .cobCALL 'CEERAN0', crypto service routines
Zig.zigstd.crypto

Framework Support

Beyond language-level detection, Korthex understands framework-specific crypto patterns:

Framework / PlatformDetection Scope
ASP.NET CoreData protection APIs, authentication schemes, HTTPS configuration
Spring BootSpring Security crypto, KeyStore configuration, OAuth2 tokens
Express / FastifySession encryption, CORS, Helmet security headers, JWT
DjangoSECRET_KEY, password hashers, signing, CSRF tokens
RailsActiveSupport::MessageEncryptor, has_secure_password, credentials
Next.jsAPI route crypto, middleware tokens, environment secrets
.NET FrameworkLegacy System.Security, machine keys, web.config encryption
Android (Kotlin/Java)Android Keystore, BiometricPrompt, EncryptedSharedPreferences
iOS (Swift)Keychain Services, Secure Enclave, App Transport Security
AWS SDKKMS calls, S3 encryption, SSE configuration
Azure SDKKey Vault, Blob encryption, Managed Identity tokens
gRPCTLS channel credentials, call credentials