Mondoo
100+ integrations available

Connect to everything

Connect Mondoo to your entire infrastructure. From cloud providers to CI/CD pipelines, we integrate with the tools you already use.

Popular integrations

AWS

AWS

Assess security and compliance of AWS organizations and accounts

Azure

Azure

Evaluate Azure subscriptions for security posture

Google Cloud

Google Cloud

Monitor Google Cloud organizations and projects

Kubernetes

Kubernetes

Use Mondoo Operator for cluster assessment

Terraform

Terraform

Assess Terraform projects and state files

GitHub Actions

GitHub Actions

Continuous security testing in GitHub workflows

Qualys

Qualys

Import vulnerability data from Qualys VMDR

CrowdStrike Falcon

CrowdStrike Falcon

Import EDR data and threat intelligence

Snyk

Snyk

Import Snyk vulnerability and dependency findings

102 integrations

Aikido Security

Aikido Security

Application Security

Import Aikido application security findings

AIX

AIX

Operating Systems

Assess IBM AIX systems security

AlmaLinux OS

AlmaLinux OS

Operating Systems

Evaluate AlmaLinux OS security

Alpine Linux

Alpine Linux

Operating Systems

Scan Alpine containers and systems

Amazon Linux

Amazon Linux

Operating Systems

Scan Amazon Linux instances

Amazon S3

Amazon S3

Data Export

Export security data to S3 buckets

Ansible

Ansible

Infrastructure as Code

Evaluate playbook security configurations

Arch Linux

Arch Linux

Operating Systems

Assess Arch Linux systems

Archer

Archer

GRC

Export compliance data to RSA Archer

Arista

Arista

Network

Assess Arista network device security

Arnica

Arnica

Application Security

Integrate Arnica developer security data

Atlassian

Atlassian

SaaS

Monitor Jira, Confluence, and SCIM

AWS

AWS

Cloud

Assess security and compliance of AWS organizations and accounts

AWS ECR

AWS ECR

Containers

Integrate AWS Elastic Container Registry

AWS Inspector

AWS Inspector

Vulnerability Management

Import AWS Inspector vulnerability findings

Azure

Azure

Cloud

Evaluate Azure subscriptions for security posture

Azure ACR

Azure ACR

Containers

Integrate Azure Container Registry

Azure Blob Storage

Azure Blob Storage

Data Export

Export data to Azure storage

Azure DevOps

Azure DevOps

Ticket Systems

Create work items in Azure DevOps

Azure Pipelines

Azure Pipelines

CI/CD

Continuous testing in Azure DevOps

BigQuery

BigQuery

Data Export

Export and analyze in BigQuery

BitSight

BitSight

Third-Party Risk

Integrate BitSight security ratings

Bottlerocket

Bottlerocket

Operating Systems

Scan AWS Bottlerocket container hosts

Checkmarx

Checkmarx

Application Security

Import Checkmarx SAST/DAST results

CircleCI

CircleCI

CI/CD

Security scanning in CircleCI pipelines

Cisco

Cisco

Network

Evaluate Cisco network device security

CloudFormation

CloudFormation

Infrastructure as Code

Test AWS CloudFormation templates

CrowdStrike Falcon

CrowdStrike Falcon

EDR

Import EDR data and threat intelligence

Debian

Debian

Operating Systems

Assess Debian system security

Docker

Docker

Containers

Evaluate Docker container environments

Docker Hub

Docker Hub

Containers

Integrate Docker Hub registries

Fedora Linux

Fedora Linux

Operating Systems

Evaluate Fedora Linux workstations

Fortinet

Fortinet

Network

Evaluate FortiGate firewall security

GitHub

GitHub

SaaS

Assess organizations and repositories

GitHub Actions

GitHub Actions

CI/CD

Continuous security testing in GitHub workflows

GitHub Advanced Security

GitHub Advanced Security

Application Security

Import GHAS code scanning alerts

GitLab

GitLab

SaaS

Assess groups and projects

GitLab CI/CD

GitLab CI/CD

CI/CD

Pipeline security testing integration

GitLab Security

GitLab Security

Application Security

Integrate GitLab security scanning results

Google Cloud

Google Cloud

Cloud

Monitor Google Cloud organizations and projects

Google GCR

Google GCR

Containers

Integrate Google Container Registry

Google Workspace

Google Workspace

SaaS

Monitor Google Workspace environments

Jenkins

Jenkins

CI/CD

Integrate security scans into Jenkins builds

Jira

Jira

Ticket Systems

Create issues for security findings

Kubernetes

Kubernetes

Containers

Use Mondoo Operator for cluster assessment

Lacework

Lacework

Cloud Security

Integrate Lacework cloud security data

macOS

macOS

Operating Systems

Evaluate macOS security posture

Mend

Mend

Application Security

Integrate Mend (WhiteSource) SCA findings

Microsoft 365

Microsoft 365

SaaS

Assess M365 environments and configurations

MS Defender for Endpoint

MS Defender for Endpoint

EDR

Import Defender EDR findings

Microsoft Defender VM

Microsoft Defender VM

Vulnerability Management

Integrate Defender vulnerability management

Microsoft Entra ID

Microsoft Entra ID

SaaS

Assess Azure AD / Entra ID configurations

MS Defender for Cloud

MS Defender for Cloud

Cloud Security

Integrate Azure Defender findings

Okta

Okta

SaaS

Evaluate Okta identity resources

OneTrust

OneTrust

GRC

Integrate with OneTrust GRC platform

Oracle Cloud

Oracle Cloud

Cloud

Assess OCI tenancies and resources

Oracle Linux

Oracle Linux

Operating Systems

Evaluate Oracle Linux systems

Orca Security

Orca Security

Cloud Security

Import Orca cloud security findings

Packer

Packer

Infrastructure as Code

Analyze Packer builds and images

Palo Alto Networks

Palo Alto Networks

Network

Assess Palo Alto firewall configurations

Photon OS

Photon OS

Operating Systems

Assess VMware Photon OS security

PostgreSQL

PostgreSQL

Data Export

Export findings to PostgreSQL databases

Qualys

Qualys

Vulnerability Management

Import vulnerability data from Qualys VMDR

Rapid7

Rapid7

Vulnerability Management

Import InsightVM vulnerability data

Red Hat Enterprise Linux

Red Hat Enterprise Linux

Operating Systems

Evaluate RHEL systems

Rocky Linux

Rocky Linux

Operating Systems

Assess Rocky Linux systems

SecurityScorecard

SecurityScorecard

Third-Party Risk

Correlate with vendor risk ratings

Semgrep

Semgrep

Application Security

Integrate Semgrep SAST findings

SentinelOne Singularity

SentinelOne Singularity

EDR

Integrate endpoint detection and response data

ServiceNow GRC

ServiceNow GRC

GRC

Integrate with ServiceNow compliance

Shodan

Shodan

Network

Integrate Shodan reconnaissance data

Slack

Slack

SaaS

Monitor Slack workspace security

Snowflake

Snowflake

SaaS

Assess Snowflake data warehouse security

Snowflake Export

Snowflake Export

Data Export

Export findings to Snowflake

Snyk

Snyk

Application Security

Import Snyk vulnerability and dependency findings

SUSE / openSUSE

SUSE / openSUSE

Operating Systems

Assess SUSE and openSUSE systems

Tailscale

Tailscale

Network

Query Tailscale network devices

Tanium

Tanium

Vulnerability Management

Integrate Tanium vulnerability and asset data

Tenable

Tenable

Vulnerability Management

Integrate Tenable.io and Nessus findings

Terraform

Terraform

Infrastructure as Code

Assess Terraform projects and state files

Ubuntu

Ubuntu

Operating Systems

Scan Ubuntu servers and desktops

UpGuard

UpGuard

Third-Party Risk

Import UpGuard risk assessment data

VMware

VMware

Cloud

Evaluate vCenter Server, vSphere, ESXi systems

Windows

Windows

Operating Systems

Scan Windows servers and endpoints

Wiz

Wiz

Cloud Security

Import Wiz cloud security findings

Zendesk

Zendesk

Ticket Systems

Generate support tickets for findings

Coming Soon
Aqua Security

Aqua Security

Containers

Container security and runtime protection

Coming Soon
Armis

Armis

Asset Management

Import asset inventory from Armis

Coming Soon
Cribl

Cribl

Threat Intelligence

Integrate threat intelligence feeds via Cribl

Coming Soon
Elastic Security

Elastic Security

SIEM

Integrate with Elastic SIEM

Coming Soon
Exabeam

Exabeam

SIEM

Integrate with Exabeam security analytics

Coming Soon
Jamf

Jamf

MDM

Evaluate Jamf-managed device security

Coming Soon
Kandji

Kandji

MDM

Assess Kandji-managed Apple devices

Coming Soon
Microsoft Intune

Microsoft Intune

MDM

Assess Intune-managed endpoints

Coming Soon
Microsoft Sentinel

Microsoft Sentinel

SIEM

Export findings to Azure Sentinel

Coming Soon
MITRE ATT&CK

MITRE ATT&CK

Threat Intelligence

Map findings to MITRE ATT&CK framework

Coming Soon
PagerDuty

PagerDuty

Ticket Systems

Trigger alerts for critical findings

Coming Soon
Panther

Panther

SIEM

Export findings to Panther SIEM

Coming Soon
ServiceNow CMDB

ServiceNow CMDB

Asset Management

Sync with ServiceNow asset database

Coming Soon
ServiceNow ITSM

ServiceNow ITSM

Ticket Systems

Create incidents and change requests

Coming Soon
Splunk

Splunk

SIEM

Export security data to Splunk

Coming Soon
Zscaler

Zscaler

Network

Integrate Zscaler cloud security

Unified Security Across Your Entire Stack

Cloud Security Integrations

Mondoo integrates with AWS, Azure, Google Cloud, Oracle Cloud, and VMware to provide comprehensive security assessment of your cloud infrastructure. Use cnspec to scan IAM policies, network configurations, storage security, and compute resources to identify vulnerabilities and misconfigurations before they become breaches.

Container & Kubernetes Security

Deploy the Mondoo Operator in your Kubernetes clusters for continuous security monitoring. Integrate with Docker Hub, AWS ECR, Azure ACR, and Google GCR to scan container images for vulnerabilities. Query your infrastructure with cnquery to identify misconfigured workloads, exposed secrets, and compliance violations.

CI/CD Pipeline Security

Shift security left with native integrations for GitHub Actions, GitLab CI/CD, Azure Pipelines, CircleCI, and Jenkins. Run security scans as part of every build, block vulnerable deployments, and generate compliance reports automatically. Catch issues during development, not in production.

Vulnerability Management Consolidation

Import findings from Qualys, Tenable, Rapid7, Tanium, and other vulnerability scanners. Correlate data across tools to eliminate duplicate findings and prioritize remediation based on exploitability and business context. Agentic Vulnerability Management acts as your central hub for unified, AI-powered security posture management.

Integration Categories

Cloud Providers

AWS, Azure, GCP, OCI

Containers

Kubernetes, Docker, ECR

CI/CD

GitHub, GitLab, Jenkins

IaC

Terraform, Ansible, Packer

Vulnerability

Qualys, Tenable, Rapid7

EDR

CrowdStrike, SentinelOne

AppSec

Snyk, Semgrep, Checkmarx

Ticketing

Jira, ServiceNow, Zendesk

Don't see your integration?

Mondoo's extensible provider system lets you build custom integrations. Contact us to learn more.