
Linux, macOS and Windows Install scripts for cnquery & cnspec
The easiest way to install mql & cnspec is to use the install scripts.
bash -c "$(curl -sSL https://install.mondoo.com/sh)"
https://install.mondoo.com/ps1
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;
Pass the proxy to the install script with -x (Linux and macOS) or -Proxy
(Windows). The script routes its own downloads, the package installation,
cnspec login and the auto updater through it. The initial download of the
script happens before the flag is read, so point that at the proxy as well:
export https_proxy='http://proxy.example.com:3128'
curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
$wc = New-Object System.Net.WebClient;
$wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128');
iex ($wc.DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo -Proxy 'http://proxy.example.com:3128';
On Linux and macOS an inherited https_proxy or http_proxy is picked up
automatically when -x is not given. Either way both forms are exported, so
the distribution's own repositories — which are plain HTTP on Debian and Ubuntu
— are reached through the proxy as well. Any no_proxy you have set is carried
through unchanged, including across sudo.
The proxy URL must be a plain URL: if it carries credentials, percent-encode
them (! as %21, and so on). The value is written into the auto updater's
scheduled job, so characters that would need quoting there are refused rather
than escaped.
Scan your target platform:
# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws
Sign up for a Mondoo account to access more policies and store reports. To learn more, contact us.
cnspec login -t 'eyJh...llZ4BW'
mql & cnspec support local and remote targets, including servers (Linux, Windows, macOS), Cloud (AWS, Azure, Google, VMware), Kubernetes (EKS, GKE, AKS, self-managed), containers, container registries, SaaS products (Google Workspace, M365, GitHub, GitLab), and more.
Run a scan:
# scan your local host
cnspec scan local
# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure
# scan a kubernetes cluster
cnspec scan k8s
# scan a docker image from a remote registry
cnspec scan docker image debian:12
# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a
# scan a system over ssh
cnspec scan ssh [email protected]
https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}
The arguments support the following values:
| Argument | Values |
|---|---|
platform | linux, windows, darwin |
arch | amd64, arm64, armv7, armv6, 386, ppc64le |
filetype | tar.gz, deb, rpm, zip, pkg, msi |
version | latest or specific number |
method | download, filename, version, sha256 |
# Download the latest version
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download
# Get the filename for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/filename
# Get the version for the latest cnspec package
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/version
# Get the sha256 for the latest cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/sha256
# Download a specific version of cnspec client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/download
# Get the sha256 for a specific version of cnspec Client
https://install.mondoo.com/package/cnspec/linux/arm64/rpm/5.21.1/sha256
https://install.mondoo.com/k8s/operator
kubectl apply -f https://install.mondoo.com/k8s/operator
https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true
kubectl apply -f https://install.mondoo.com/k8s/auditconfig?nodes=true&kubernetesResources=true
To browse all releases, please visit https://releases.mondoo.com
Install Scripts Sources
mql & cnspec Bash Installermql & cnspec Bash Binary Downloadermql & cnspec PowerShell Installermql & cnspec PowerShell Binary DownloaderConfig Management
Docker Containers
Releases