Comparison
Korthex vs Semgrep: Crypto Reachability vs Patterns
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Semgrep is a fast, hackable rule engine whose Pro engine adds genuine cross-file taint analysis, plus a secrets product that validates live credentials across hundreds of credential types. Korthex is not a rule engine you maintain - it specializes in cryptography out of the box: following values across import hops, correlating across engines, exporting a CBOM, planning the migration, and proving weakness by emulation.
Axis by axis on cryptography: cross-engine attack-paths vs rule-based per-scan findings; cryptographic value tracking vs injection-focused cross-file taint analysis; key-provenance classification vs validated secrets detection; CBOM-PQC export vs no cryptographic inventory; a dependency-ordered migration plan vs finding-level guidance and autofix rules; and offensive verification against NIST Known-Answer Tests. Comparison based on public vendor documentation as of 2026-07-10.
How Korthex and Semgrep differ, axis by axis
| Axis | Korthex | Semgrep |
|---|---|---|
| Cross-engine attack-paths | Merges code, config, TLS/PKI, database and git findings into one reachability-scored chain | Rule-based findings per scan (code, secrets, supply chain); no cryptographic attack-path correlation |
| Dataflow across import hops | Follows the cryptographic value across 16 import hops | Cross-file, cross-function taint analysis (Pro engine); not crypto-value tracking |
| Taint-classified key sources | Taint-classifies where keys and secrets originate before grading the finding | Secrets detection with live-credential validation; no cryptographic key-provenance classification |
| Cross-file crypto clusters | Union-find crypto clustering across files | No cryptographic clustering |
| CBOM-PQC export | Cryptographic Bill of Materials with per-finding post-quantum bucket (CycloneDX / SARIF / JSON / PDF / .kxr) | No cryptographic inventory export |
| Migration plan + simulation | Topologically-ordered plan with file:line, replacement algo, deadline, effort hours, dependency order | Finding-level guidance and autofix rules; no cryptographic migration plan |
| Offensive verification | Extracted crypto graded by emulation against NIST KAT to prove weak or broken, plus side-channel timing verdict | Static detection; no emulation-based proof of cryptographic weakness |