Tool integration

CloudQuery Integration Guide

Open-source cloud asset inventory with SQL querying and compliance policies

Get a Free API Key

Integrate CloudQuery with Vulnetix. Sync cloud asset data with CloudQuery, query for security findings, and upload results to Vulnetix.

SQL / Cloud APIsCLI toolJSON

Install & scan

$ curl -fsSL https://docs.cloudquery.io/install.sh | sh

# Verify
cloudquery --version
$ # Sync cloud assets
cloudquery sync config.yml

# Query for security findings (PostgreSQL example)
psql -h localhost -U cloudquery -d cloudquery   -c "SELECT account_id, region, arn FROM aws_ec2_security_groups WHERE ingress @> '[{"CidrIp": "0.0.0.0/0"}]'"   -o cloudquery-findings.csv

How Vulnetix compares: better together

Vulnetix does not replace CloudQuery. Keep running it. Vulnetix sits on top of CloudQuery (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

CloudQuery is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.

CapabilityVulnetixCloudQuery
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tabCore: cloud asset inventory + SQL security/compliance policies (CIS, IAM, network exposure)
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What CloudQuery does well

Where Vulnetix adds to it: CloudQuery is an asset-inventory and SQL-policy CSPM foundation, strong at 'what exists and what is misconfigured' but it does not scan code, dependencies, containers or supply-chain malware, and has no exploit-intel or remediation layer. Vulnetix ingests its cloud/compliance findings and unifies them with SAST/SCA/container/secrets results into a single prioritised queue, adding EPSS/KEV/CWSS/LEV scoring, reachability, immutable VEX, and autofix that CloudQuery does not provide.

No migration, no rip-and-replace. CloudQuery keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise CloudQuery results in Vulnetix

Upload CloudQuery JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

CloudQuery documentation ↗  ·  Source repository ↗

Wire CloudQuery into your CI/CD pipeline →