KORTHEXkorthex.io

Comparison

Korthex vs Semgrep: Crypto Reachability vs Patterns

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Semgrep is a fast, hackable rule engine whose Pro engine adds genuine cross-file taint analysis, plus a secrets product that validates live credentials across hundreds of credential types. Korthex is not a rule engine you maintain - it specializes in cryptography out of the box: following values across import hops, correlating across engines, exporting a CBOM, planning the migration, and proving weakness by emulation.

Axis by axis on cryptography: cross-engine attack-paths vs rule-based per-scan findings; cryptographic value tracking vs injection-focused cross-file taint analysis; key-provenance classification vs validated secrets detection; CBOM-PQC export vs no cryptographic inventory; a dependency-ordered migration plan vs finding-level guidance and autofix rules; and offensive verification against NIST Known-Answer Tests. Comparison based on public vendor documentation as of 2026-07-10.

How Korthex and Semgrep differ, axis by axis

Feature-by-feature comparison. Rows are the same ones the page renders.
AxisKorthexSemgrep
Cross-engine attack-pathsMerges code, config, TLS/PKI, database and git findings into one reachability-scored chainRule-based findings per scan (code, secrets, supply chain); no cryptographic attack-path correlation
Dataflow across import hopsFollows the cryptographic value across 16 import hopsCross-file, cross-function taint analysis (Pro engine); not crypto-value tracking
Taint-classified key sourcesTaint-classifies where keys and secrets originate before grading the findingSecrets detection with live-credential validation; no cryptographic key-provenance classification
Cross-file crypto clustersUnion-find crypto clustering across filesNo cryptographic clustering
CBOM-PQC exportCryptographic Bill of Materials with per-finding post-quantum bucket (CycloneDX / SARIF / JSON / PDF / .kxr)No cryptographic inventory export
Migration plan + simulationTopologically-ordered plan with file:line, replacement algo, deadline, effort hours, dependency orderFinding-level guidance and autofix rules; no cryptographic migration plan
Offensive verificationExtracted crypto graded by emulation against NIST KAT to prove weak or broken, plus side-channel timing verdictStatic detection; no emulation-based proof of cryptographic weakness