
installer v13.30.0
Linux, macOS and Windows Install scripts for cnquery & cnspec
Overview
Status
Installation
The easiest way to install mql & cnspec is to use the install scripts.
via Shell Script (Linux and macOS)
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
via PowerShell (Windows)
https://install.mondoo.com/ps1
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;
Behind an HTTP proxy
Pass the proxy to the install script with -x (Linux and macOS) or -Proxy
(Windows). The script routes its own downloads, the package installation,
cnspec login and the auto updater through it. The initial download of the
script happens before the flag is read, so point that at the proxy as well:
export https_proxy='http://proxy.example.com:3128'
curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
$wc = New-Object System.Net.WebClient;
$wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128');
iex ($wc.DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo -Proxy 'http://proxy.example.com:3128';
On Linux and macOS an inherited https_proxy or http_proxy is picked up
automatically when -x is not given. Either way both forms are exported, so
the distribution's own repositories — which are plain HTTP on Debian and Ubuntu
— are reached through the proxy as well. Any no_proxy you have set is carried
through unchanged, including across sudo.
The proxy URL must be a plain URL: if it carries credentials, percent-encode
them (! as %21, and so on). The value is written into the auto updater's
scheduled job, so characters that would need quoting there are refused rather
than escaped.
Scan your target platform
Scan your target platform:
# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws
Sign up for a Mondoo account to access more policies and store reports. To learn more, contact us.
cnspec login -t 'eyJh...llZ4BW'
mql & cnspec support local and remote targets, including servers (Linux, Windows, macOS), Cloud (AWS, Azure, Google, VMware), Kubernetes (EKS, GKE, AKS, self-managed), containers, container registries, SaaS products (Google Workspace, M365, GitHub, GitLab), and more.
Run a scan:
# scan your local host
cnspec scan local
# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure
# scan a kubernetes cluster
cnspec scan k8s
# scan a docker image from a remote registry
cnspec scan docker image debian:12
# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a
# scan a system over ssh
cnspec scan ssh [email protected]
Package Information
https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}
The arguments support the following values:
| Argument | Values |
|---|---|
platform | linux, windows, darwin |
arch | amd64, arm64, armv7, armv6, 386, ppc64le |
filetype | tar.gz, deb, rpm, zip, pkg, msi |
version | latest or specific number |
method | download, filename, version, sha256 |
# Download the latest version
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download
# Get the filename for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/filename
# Get the version for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/version
# Get the sha256 for the latest cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/sha256
# Download a specific version of cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/download
# Get the sha256 for a specific version of cnspec Client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/sha256
Kubernetes
Kubernetes Manifests to install the operator
https://install.mondoo.com/k8s/operator
kubectl apply -f https://install.mondoo.com/k8s/operator
Kubernetes manifest to configure the MondooAuditConfig
https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true
kubectl apply -f https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true
To browse all releases, please visit https://releases.mondoo.com
References
Install Scripts Sources
- install.sh -
mql&cnspecBash Installer - download.sh -
mql&cnspecBash Binary Downloader - install.ps1 -
mql&cnspecPowerShell Installer - download.ps1 -
mql&cnspecPowerShell Binary Downloader
Config Management
Docker Containers
Releases