Back to updates
New releaseJul 21, 2026

installer v13.30.0

Linux, macOS and Windows Install scripts for cnquery & cnspec

Share

Overview

Status

  • Docker Containers: Release Test: Docker Containers
  • Homebrew: Release Test: Homebrew
  • Install.sh: Release Test: install.sh
  • Install.ps1: Release Test: install.ps1
  • macOS Pkg: Release Test: macOS Package
  • Arch Linux: Release Test: Arch Linux

Installation

The easiest way to install mql & cnspec is to use the install scripts.

via Shell Script (Linux and macOS)

https://install.mondoo.com/sh

bash -c "$(curl -sSL https://install.mondoo.com/sh)"

via PowerShell (Windows)

https://install.mondoo.com/ps1

Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;

Behind an HTTP proxy

Pass the proxy to the install script with -x (Linux and macOS) or -Proxy (Windows). The script routes its own downloads, the package installation, cnspec login and the auto updater through it. The initial download of the script happens before the flag is read, so point that at the proxy as well:

export https_proxy='http://proxy.example.com:3128'
curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
$wc = New-Object System.Net.WebClient;
$wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128');
iex ($wc.DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo -Proxy 'http://proxy.example.com:3128';

On Linux and macOS an inherited https_proxy or http_proxy is picked up automatically when -x is not given. Either way both forms are exported, so the distribution's own repositories — which are plain HTTP on Debian and Ubuntu — are reached through the proxy as well. Any no_proxy you have set is carried through unchanged, including across sudo.

The proxy URL must be a plain URL: if it carries credentials, percent-encode them (! as %21, and so on). The value is written into the auto updater's scheduled job, so characters that would need quoting there are refused rather than escaped.

Scan your target platform

Scan your target platform:

# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws

Sign up for a Mondoo account to access more policies and store reports. To learn more, contact us.

cnspec login -t 'eyJh...llZ4BW'

mql & cnspec support local and remote targets, including servers (Linux, Windows, macOS), Cloud (AWS, Azure, Google, VMware), Kubernetes (EKS, GKE, AKS, self-managed), containers, container registries, SaaS products (Google Workspace, M365, GitHub, GitLab), and more.

Run a scan:

# scan your local host
cnspec scan local

# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure

# scan a kubernetes cluster
cnspec scan k8s

# scan a docker image from a remote registry
cnspec scan docker image debian:12

# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a

# scan a system over ssh
cnspec scan ssh [email protected]

Package Information

https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}

The arguments support the following values:

ArgumentValues
platformlinux, windows, darwin
archamd64, arm64, armv7, armv6, 386, ppc64le
filetypetar.gz, deb, rpm, zip, pkg, msi
versionlatest or specific number
methoddownload, filename, version, sha256
# Download the latest version
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download
# Get the filename for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/filename
# Get the version for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/version
# Get the sha256 for the latest cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/sha256
# Download a specific version of cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/download
# Get the sha256 for a specific version of cnspec Client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/sha256

Kubernetes

Kubernetes Manifests to install the operator

https://install.mondoo.com/k8s/operator

kubectl apply -f https://install.mondoo.com/k8s/operator

Kubernetes manifest to configure the MondooAuditConfig

https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true

kubectl apply -f https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true

To browse all releases, please visit https://releases.mondoo.com

References

Install Scripts Sources

Config Management

Docker Containers

Releases

Categories