Integrate MITRE SAF CLI with Vulnetix. Use @mitre/saf to convert output from InSpec, DISA STIGs, Nessus, and SARIF into Heimdall Data Format, or convert HDF to SARIF for Vulnetix upload.
Install & scan
$ npm install -g @mitre/saf # or use without install: npx @mitre/saf --help $ # SARIF to HDF (for Heimdall visualisation) npx @mitre/saf convert sarif2hdf -i findings.sarif -o findings.hdf.json # HDF to SARIF (for Vulnetix upload) npx @mitre/saf convert hdf2sarif -i results.hdf.json -o results.sarif
Run MITRE SAF in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install MITRE SAF CLI
run: npm install -g @mitre/saf
- name: Convert InSpec results to SARIF
run: |
inspec exec ./my-profile --reporter json:inspec-output.json
saf convert inspec2hdf -i inspec-output.json -o inspec.hdf.json
saf convert hdf2sarif -i inspec.hdf.json -o inspec.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: mitre-saf
path: inspec.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under MITRE SAF's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace MITRE SAF. Keep running it. Vulnetix sits on top of MITRE SAF (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
MITRE SAF is strongest at its core category and also carries features in SBOM Generation, SAST, SCA, Container & Image Scanning, DAST, Cloud Security & CSPM, Secret Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | MITRE SAF |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ~ Ingest-only: converts gosec, SonarQube, Fortify, Veracode output to HDF; runs no static analysis itself |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Ingest-only: normalizes Snyk/Trivy/Dependency-Track/JFrog Xray dependency findings; no native SCA engine |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ~ Ingest-only: converts OWASP ZAP, Nikto, Burp, Netsparker output to HDF; runs no dynamic test |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Ingest-only: converts Trivy, Twistlock/Prisma, Anchore Grype, NeuVector output; runs no image scan |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ Ingest-only: converts Trufflehog secret-scan output to HDF; runs no secret detection itself |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ~ Ingest-only: converts Prowler, AWS Config, Security Hub (ASFF), Scoutsuite findings to HDF |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ~ Converts CycloneDX and Dependency-Track SBOM/vuln output to/from HDF; does not generate SBOMs |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Normalizes 30+ tools' output into one HDF view for Heimdall, but no cross-scanner finding-level dedup/one-queue prioritization |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What MITRE SAF does well
- Converts output from 30+ security tools (Nessus, Trivy, Snyk, Fortify, Prowler, Checkov, gosec, SonarQube, OWASP ZAP, Nikto, Anchore Grype, NeuVector, Trufflehog, CycloneDX, Dependency-Track) into the Heimdall Data Format for a single normalized view
- Deep federal/DoD compliance workflow: InSpec profile stubs from XCCDF/STIG benchmarks, POA&M generation, eMASS integration, and CI/CD threshold gating
- Compliance attestation support for controls that cannot be tested automatically, plus delta analysis for profile updates
- Free, open-source, vendor-neutral CLI that exports to ASFF, Splunk, XCCDF, CSV, HTML and checklist formats
Where Vulnetix adds to it: MITRE SAF is a normalization/compliance-conversion layer that ingests 30+ tools into HDF; it runs no scanners of its own. Vulnetix natively runs SAST/SCA/IaC/container/secrets/cloud/malware engines AND adds cross-scanner finding-level dedup into one prioritized queue, exploit-intel (EPSS/KEV/ESS/LEV), reachability, versioned VEX, autofix and SSVC. For the DAST tools SAF ingests (ZAP, Nikto, Burp), Vulnetix likewise ingests and orchestrates their output rather than running dynamic tests itself. The two are complementary where SAF feeds Heimdall/eMASS compliance evidence.
No migration, no rip-and-replace. MITRE SAF keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise MITRE SAF results in Vulnetix
Upload MITRE SAF SARIF, JSON, CSV output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.