Integrate CloudQuery with Vulnetix. Sync cloud asset data with CloudQuery, query for security findings, and upload results to Vulnetix.
Install & scan
$ curl -fsSL https://docs.cloudquery.io/install.sh | sh
# Verify
cloudquery --version
$ # Sync cloud assets
cloudquery sync config.yml
# Query for security findings (PostgreSQL example)
psql -h localhost -U cloudquery -d cloudquery -c "SELECT account_id, region, arn FROM aws_ec2_security_groups WHERE ingress @> '[{"CidrIp": "0.0.0.0/0"}]'" -o cloudquery-findings.csv
How Vulnetix compares: better together
Vulnetix does not replace CloudQuery. Keep running it. Vulnetix sits on top of CloudQuery (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
CloudQuery is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.
| Capability | Vulnetix | CloudQuery |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✓ Core: cloud asset inventory + SQL security/compliance policies (CIS, IAM, network exposure) |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What CloudQuery does well
- High-performance open-source ELT that extracts full cloud asset inventory from 70-100+ integrations (AWS, Azure, GCP, GitHub, Okta) into Postgres or a data warehouse for durable, historical querying
- SQL-based policy engine for continuous CSPM-style checks. CIS benchmarks, IAM hygiene, network/security-group exposure, tagging and cost governance in one place
- Warehouse-native model scales to very large multi-account estates and plugs into existing BI/analytics stacks
- Flexible source-and-destination plugin architecture lets teams build custom security queries and correlations
Where Vulnetix adds to it: CloudQuery is an asset-inventory and SQL-policy CSPM foundation, strong at 'what exists and what is misconfigured' but it does not scan code, dependencies, containers or supply-chain malware, and has no exploit-intel or remediation layer. Vulnetix ingests its cloud/compliance findings and unifies them with SAST/SCA/container/secrets results into a single prioritised queue, adding EPSS/KEV/CWSS/LEV scoring, reachability, immutable VEX, and autofix that CloudQuery does not provide.
No migration, no rip-and-replace. CloudQuery keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise CloudQuery results in Vulnetix
Upload CloudQuery JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.