Run ReportsContinuous Data Exports

Export Findings to Google Security Command Center

Send Mondoo findings to Google Security Command Center using Workload Identity Federation or a service account key.

Send your Mondoo findings to Google Security Command Center (SCC) so your Google Cloud security team sees Mondoo results alongside Google's own detections. Unlike the storage and warehouse exports, this integration writes SCC findings rather than files or tables. For how exports work in general, read Continuous Data Exports.

Preview feature

The Google Security Command Center export is in preview. To use it, select your avatar at the top of the side navigation, select Feature Flags, and turn on Google Security Command Center. The Google Security Command Center card then appears under Data Exports when you install an integration.

Requirements

  • A Google Cloud organization with Security Command Center enabled

  • An SCC source that Mondoo writes findings to. Create one with gcloud scc sources create and note its full resource name, in the format organizations/ORGANIZATION_ID/sources/SOURCE_ID.

  • Editor or Owner access to the Mondoo space from which you want to export findings

  • Permission in GCP to create service accounts, Workload Identity Pools, and organization-level IAM policy bindings

Choose an authentication method

Mondoo can authenticate to GCP in two ways:

  • Workload Identity Federation (WIF) (recommended): Keyless. You create a Workload Identity Pool, an OIDC provider for Mondoo, and a service account in GCP, then paste the audience URL and service account email into Mondoo. Nothing to rotate.

  • Service account key: A static JSON key file. Simplest to set up, but you're responsible for securely storing and regularly rotating the key.

With WIF, Mondoo acts as an OIDC identity provider. When it's time to export, Mondoo issues a short-lived OIDC token and presents it to GCP. GCP validates the token against Mondoo's public signing keys (fetched from Mondoo's OIDC discovery endpoint), then issues temporary GCP credentials that Mondoo uses to write findings. No static keys are stored or transmitted.

Step 1: Create a GCP service account

Create a GCP service account that Mondoo will impersonate to write findings. Do not create a key for this service account; WIF replaces the need for static keys.

  1. In the GCP Console, navigate to IAM & Admin > Service Accounts.

  2. Select Create Service Account.

  3. Give the service account a name (for example, mondoo-scc-export) and select Create and Continue.

  4. Select Done. Note the service account email address (for example, mondoo-scc-export@PROJECT_ID.iam.gserviceaccount.com).

  5. Grant the service account the Security Center Findings Editor role (roles/securitycenter.findingsEditor) on the organization that owns the SCC source:

    gcloud organizations add-iam-policy-binding ORGANIZATION_ID \
      --member="serviceAccount:mondoo-scc-export@PROJECT_ID.iam.gserviceaccount.com" \
      --role="roles/securitycenter.findingsEditor"

Step 2: Create a Workload Identity Pool

A Workload Identity Pool is a GCP resource that manages external identities. You create one pool and add Mondoo as an OIDC provider within it.

If you already created a Workload Identity Pool and Mondoo OIDC provider for another integration, you can reuse it. Skip to Step 4.

  1. In the GCP Console, navigate to IAM & Admin > Workload Identity Federation.

  2. Select Create Pool.

  3. Enter a name for the pool (for example, mondoo-export-pool) and an optional description.

  4. Make sure the pool is Enabled and select Continue.

Step 3: Add Mondoo as an OIDC provider to the pool

Within the Workload Identity Pool, add Mondoo as a trusted OpenID Connect (OIDC) identity provider.

  1. In the pool you just created, select Add Provider.

  2. For Select a provider, choose OpenID Connect (OIDC).

  3. Enter a provider name (for example, mondoo-provider).

  4. Set the Issuer (URL) to the Mondoo STS endpoint for your environment:

    EnvironmentIssuer URL
    Mondoo (US)https://sts.us.mondoo.com
    Mondoo (EU)https://sts.eu.mondoo.com
    Mondoo Edgehttps://sts.edge.mondoo.com
    Dedicated deploymenthttps://sts.mondoo.CUSTOMER.com
  5. Under Audiences, select Allowed audiences and leave the default value.

  6. Under Attribute Mapping, add this mapping:

    Google attributeOIDC attribute
    google.subjectassertion.sub
  7. Select Save.

Step 4: Note the WIF audience URL

After creating the provider, note the full audience URL. It follows this format:

https://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/providers/PROVIDER_ID

Step 5: Create the SCC export integration in Mondoo

  1. In the Mondoo App, navigate to the space from which you want to export findings. In the side navigation bar, select Integrations, then select INSTALL. Under Data Exports, select Google Security Command Center.

  2. In the Integration name box, enter a name for the integration.

  3. In the Source Name box, enter the full SCC source resource name, for example organizations/123456/sources/789.

  4. Under Configure authentication, select the Workload Identity Federation (recommended) tab.

  5. In the WIF Audience URL box, enter the audience URL from Step 4.

  6. In the Service Account Email (for impersonation) box, enter the email of the service account you created in Step 1.

  7. Select Create Integration.

Creating the integration immediately attempts a first export, but the GCP binding that authorizes Mondoo doesn't exist yet, so that attempt fails. That's expected. Complete Step 6, then run a fresh export in Step 7.

Step 6: Authorize the WIF subject to impersonate the service account

On the integration details page, find the WifSubject field and copy its value. It has the format INTEGRATION_ID@integrations.SPACE_ID.spaces.iam.REGION.mondoo.app, where REGION is the short name of your Mondoo region (for example, us).

Back in GCP, grant that subject the Workload Identity User role on the service account:

gcloud iam service-accounts add-iam-policy-binding \
  mondoo-scc-export@PROJECT_ID.iam.gserviceaccount.com \
  --project=PROJECT_ID \
  --role="roles/iam.workloadIdentityUser" \
  --member="principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/subject/SUBJECT_VALUE"

Step 7: Verify the integration

Select RUN on the integration details page to trigger an immediate export, then check Security Command Center > Findings in the Google Cloud console.

Manage this integration

After it's created, find your integration under Integrations in your space's side navigation. Select it to open the detail page, where you can:

  • Trigger a manual export. Exports run automatically about every 24 hours. To export immediately, select RUN.
  • Check the status. ACTIVE means the integration is healthy and exporting on schedule. PENDING means Mondoo hasn't attempted the first export yet. ERROR means the last export failed. The Export Details section shows when the last export succeeded and when Mondoo last attempted one.
  • Review the activity log. Most Recent Activity lists each export run's messages, such as when a job started, finished, or failed and why. Filter it to errors, warnings, or info messages.
  • Change the settings. Select the pencil icon to edit the integration, for example to update credentials.
  • Remove the integration. Select the trash can icon and confirm. Mondoo stops future exports but does not delete data that has already been exported.

Next steps

On this page