アップデート一覧に戻る
New releaseJul 21, 2026

installer v13.30.0

cnquery と cnspec 向けの Linux、macOS、Windows インストールスクリプト

共有

概要

ステータス

  • Docker Containers: Release Test: Docker Containers
  • Homebrew: Release Test: Homebrew
  • Install.sh: Release Test: install.sh
  • Install.ps1: Release Test: install.ps1
  • macOS Pkg: Release Test: macOS Package
  • Arch Linux: Release Test: Arch Linux

インストール

mql と cnspec をインストールする最も簡単な方法は、インストールスクリプトを使用することです。

Shell スクリプト経由 (Linux および macOS)

https://install.mondoo.com/sh```bash bash -c "$(curl -sSL https://install.mondoo.com/sh)"

### PowerShell 経由 (Windows)

[`https://install.mondoo.com/ps1`](https://install.mondoo.com/ps1)```powershell
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;

HTTP プロキシの背後で

インストールスクリプトにプロキシを -x(Linux および macOS)または -Proxy (Windows)で渡します。スクリプトは自身のダウンロード、パッケージのインストール、 cnspec login、および自動アップデーターをプロキシ経由でルーティングします。 スクリプト自体の最初のダウンロードはフラグが読み取られる前に発生するため、 そちらもプロキシを指定してください:```bash export https_proxy='http://proxy.example.com:3128' curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"

## 主な機能

- **自動偵察**: サブドメイン列挙、ポートスキャン、技術フィンガープリンティング
- **AI駆動の脆弱性検出**: 機械学習モデルがパターンを分析し、潜在的な脆弱性を特定
- **スマートペイロード生成**: コンテキストを認識したペイロードが検出を回避し、成功率を最大化
- **適応型スキャン**: リアルタイムのフィードバックに基づいてテスト戦略を動的に調整
- **包括的なレポート**: 実行可能な修復手順を含む詳細なレポートを生成
- **モジュラーアーキテクチャ**: カスタムモジュールと統合による拡張が容易

## インストール

### 前提条件

- Python 3.8以上
- pipパッケージマネージャー
- Git

### ソースからのインストール

```bash
# リポジトリをクローン
git clone https://github.com/example/ai-vuln-scanner.git
cd ai-vuln-scanner

# 仮想環境を作成
python3 -m venv venv
source venv/bin/activate  # Windowsの場合: venv\Scripts\activate

# 依存関係をインストール
pip install -r requirements.txt

# ツールをインストール
pip install -e .

Dockerインストール

# Dockerイメージをビルド
docker build -t ai-vuln-scanner .

# コンテナを実行
docker run -it --rm ai-vuln-scanner --help

使用方法

基本的な使用方法

# 単一のターゲットをスキャン
ai-vuln-scanner scan --target https://example.com

# 複数のターゲットをスキャン
ai-vuln-scanner scan --targets targets.txt

# 特定のスキャンモジュールを使用
ai-vuln-scanner scan --target https://example.com --modules sqli,xss,rce

高度な使用方法

# AIモデルを指定してスキャン
ai-vuln-scanner scan --target https://example.com --ai-model advanced

# カスタムペイロードを使用
ai-vuln-scanner scan --target https://example.com --payloads custom_payloads.json

# レポートを生成
ai-vuln-scanner scan --target https://example.com --output report.html --format html

設定

設定ファイル ~/.ai-vuln-scanner/config.yaml を作成します:

ai:
  model: "default"
  confidence_threshold: 0.75
  max_iterations: 100

scanner:
  timeout: 30
  threads: 10
  user_agent: "Mozilla/5.0 (compatible; AIVulnScanner/1.0)"

reporting:
  format: "html"
  output_dir: "./reports"
  include_evidence: true

モジュール

偵察モジュール

  • subdomain_enum: サブドメインを列挙
  • port_scan: 開いているポートをスキャン
  • tech_detect: Web技術を検出
  • crawler: Webサイトをクロールしてエンドポイントを検出

脆弱性モジュール

  • sqli: SQLインジェクション検出
  • xss: クロスサイトスクリプティング検出
  • rce: リモートコード実行検出
  • lfi: ローカルファイルインクルージョン検出
  • ssrf: サーバーサイドリクエストフォージェリ検出
  • xxe: XML外部エンティティ検出

AIモジュール

  • pattern_analyzer: レスポンスパターンを分析して異常を検出
  • payload_generator: コンテキストを認識したペイロードを生成
  • false_positive_filter: 誤検出をフィルタリング
  • severity_predictor: 脆弱性の重大度を予測```powershell Set-ExecutionPolicy Unrestricted -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; $wc = New-Object System.Net.WebClient; $wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128'); iex ($wc.DownloadString('https://install.mondoo.com/ps1')); Install-Mondoo -Proxy 'http://proxy.example.com:3128';
Linux と macOS では、`-x` を指定しない場合、継承された `https_proxy` または `http_proxy` が自動的に使用されます。いずれの場合も両方の形式がエクスポートされるため、ディストリビューション自身のリポジトリ — Debian と Ubuntu ではプレーン HTTP — もプロキシ経由でアクセスされます。設定されている `no_proxy` は、`sudo` をまたぐ場合も含めて、変更されずに引き継がれます。

プロキシ URL はプレーンな URL である必要があります。認証情報を含む場合は、パーセントエンコードしてください(`!` は `%21` など)。この値は自動アップデーターのスケジュールされたジョブに書き込まれるため、そこでクォートが必要になる文字はエスケープされずに拒否されます。

## ターゲットプラットフォームをスキャンする

[ターゲットプラットフォーム](https://github.com/mondoohq/cnspec/#supported-targets)をスキャンします:```bash
# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws

Mondooアカウントに登録すると、より多くのポリシーにアクセスし、レポートを保存できます。詳細については、お問い合わせください。```bash cnspec login -t 'eyJh...llZ4BW'

mql と cnspec はローカルおよびリモートのターゲットをサポートしており、サーバー(Linux、Windows、macOS)、クラウド(AWS、Azure、Google、VMware)、Kubernetes(EKS、GKE、AKS、セルフマネージド)、コンテナ、コンテナレジストリ、SaaS 製品(Google Workspace、M365、GitHub、GitLab)などを含みます。

スキャンを実行します:```bash
# scan your local host
cnspec scan local

# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure

# scan a kubernetes cluster
cnspec scan k8s

# scan a docker image from a remote registry
cnspec scan docker image debian:12

# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a

# scan a system over ssh
cnspec scan ssh [email protected]

パッケージ情報

https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}

引数は以下の値をサポートしています:

引数値
platformlinux、windows、darwin
archamd64、arm64、armv7、armv6、386、ppc64le
filetypetar.gz、deb、rpm、zip、pkg、msi
versionlatest または特定の番号
methoddownload、filename、version、sha256

Download the latest version

https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download

## 検出

### 検出器

カテゴリ