Docs / CLI & SCANNING
CLI & SCANNING
Scanning
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex uses a multi-engine scanning architecture. Each engine specializes in a different aspect of cryptographic analysis, and results from all engines are merged into a unified finding set with cross-engine deduplication.
Scan Engines
Engine selection is a configuration block, not a flag. There is no --engines switch: put the toggles under engines.subEngines in a config file and pass it with --config . The config keys are the ones in the table above, so codeAnalysis and tlsCert are what an AST-plus-TLS run leaves enabled. At least one engine has to stay on, otherwise the scan is refused before a single file is read. See Configuration for the full block.
| Engine | Config key | Analyzes | Detects |
|---|---|---|---|
| AST | codeAnalysis | Source code abstract syntax trees | Crypto API calls, algorithm strings, key sizes, mode parameters |
| Binary | binary | .NET IL, JVM bytecode, native binaries | Compiled-in crypto usage, embedded keys, algorithm constants |
| Runtime | runtime | Dynamic execution traces | Runtime crypto operations, certificate validation, TLS handshakes |
| TLS | tlsCert | Network endpoints, certificate chains | Weak cipher suites, expiring certs, non-PQC TLS configurations |
| Git History | gitHistory | Repository history, deleted files | Previously committed secrets, removed crypto code, key rotations |
| Config | config | Configuration files, environment templates | Hardcoded secrets, weak algorithm settings, insecure defaults |
| Database | database | 41 database types (relational, NoSQL, cloud, KMS) | Insecure connections, missing TLS, hardcoded credentials, weak auth, encryption-at-rest |
Scan Modes
| Mode | Description | Use Case |
|---|---|---|
| Incremental (default) | Re-analyzes files whose content hash changed, plus everything that transitively imports them; the rest is served from the findings cache. Emits the same artifacts as a full scan. | Every scan, unless you opt out |
| Full Scan | Analyzes the entire codebase. Requested with fullRescan: true, and entered automatically whenever no usable cache snapshot exists. | First scan, audit, compliance evidence |
| Watch Mode | Continuous file-watching that re-runs the incremental path on change. | Real-time IDE feedback |
| Targeted | Scans a single file or specific directory. | Investigating a specific finding |
Language Support
Korthex supports 18 programming languages with dedicated AST parsers and crypto-library awareness:
| Language | File Extensions | Key Libraries Detected |
|---|---|---|
| JavaScript | .js, .mjs, .cjs | crypto, node:crypto, SubtleCrypto, CryptoJS, sjcl, forge |
| TypeScript | .ts, .tsx | Same as JavaScript + type-aware analysis |
| C# | .cs | System.Security.Cryptography, BouncyCastle, NSec |
| Java | .java | javax.crypto, java.security, BouncyCastle, Tink |
| Python | .py | cryptography, pycryptodome, hashlib, hmac, ssl |
| Go | .go | crypto/*, x/crypto/*, tls |
| PHP | .php | openssl_*, mcrypt_*, sodium_*, hash() |
| Ruby | .rb | OpenSSL, Digest, RbNaCl |
| Rust | .rs | ring, rust-crypto, openssl, sodiumoxide, aes-gcm |
| Kotlin | .kt, .kts | javax.crypto, BouncyCastle, Tink |
| Scala | .scala | javax.crypto, BouncyCastle, tsec |
| C++ | .cpp, .cc, .cxx, .h, .hpp | OpenSSL, Botan, Crypto++, libsodium, wolfSSL |
| C | .c, .h | OpenSSL, libsodium, wolfSSL, mbedTLS |
| Swift | .swift | CryptoKit, CommonCrypto, Security.framework |
| Dart | .dart | pointycastle, crypto, encrypt |
| VB.NET | .vb | System.Security.Cryptography |
| COBOL | .cbl, .cob | CALL 'CEERAN0', crypto service routines |
| Zig | .zig | std.crypto |
Framework Support
Beyond language-level detection, Korthex understands framework-specific crypto patterns:
| Framework / Platform | Detection Scope |
|---|---|
| ASP.NET Core | Data protection APIs, authentication schemes, HTTPS configuration |
| Spring Boot | Spring Security crypto, KeyStore configuration, OAuth2 tokens |
| Express / Fastify | Session encryption, CORS, Helmet security headers, JWT |
| Django | SECRET_KEY, password hashers, signing, CSRF tokens |
| Rails | ActiveSupport::MessageEncryptor, has_secure_password, credentials |
| Next.js | API route crypto, middleware tokens, environment secrets |
| .NET Framework | Legacy System.Security, machine keys, web.config encryption |
| Android (Kotlin/Java) | Android Keystore, BiometricPrompt, EncryptedSharedPreferences |
| iOS (Swift) | Keychain Services, Secure Enclave, App Transport Security |
| AWS SDK | KMS calls, S3 encryption, SSE configuration |
| Azure SDK | Key Vault, Blob encryption, Managed Identity tokens |
| gRPC | TLS channel credentials, call credentials |