Tool integration

MITRE SAF Integration Guide

MITRE Security Automation Framework CLI for converting security tool output to/from Heimdall Data Format

Get a Free API Key

Integrate MITRE SAF CLI with Vulnetix. Use @mitre/saf to convert output from InSpec, DISA STIGs, Nessus, and SARIF into Heimdall Data Format, or convert HDF to SARIF for Vulnetix upload.

CLI toolSARIFJSONCSV

Install & scan

$ npm install -g @mitre/saf
# or use without install:
npx @mitre/saf --help
$ # SARIF to HDF (for Heimdall visualisation)
npx @mitre/saf convert sarif2hdf -i findings.sarif -o findings.hdf.json

# HDF to SARIF (for Vulnetix upload)
npx @mitre/saf convert hdf2sarif -i results.hdf.json -o results.sarif

Run MITRE SAF in CI

Scan on every push and upload the report as a workflow artifact:

- name: Install MITRE SAF CLI
  run: npm install -g @mitre/saf

- name: Convert InSpec results to SARIF
  run: |
    inspec exec ./my-profile --reporter json:inspec-output.json
    saf convert inspec2hdf -i inspec-output.json -o inspec.hdf.json
    saf convert hdf2sarif -i inspec.hdf.json -o inspec.sarif

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: mitre-saf
    path: inspec.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under MITRE SAF's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace MITRE SAF. Keep running it. Vulnetix sits on top of MITRE SAF (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

MITRE SAF is strongest at its core category and also carries features in SBOM Generation, SAST, SCA, Container & Image Scanning, DAST, Cloud Security & CSPM, Secret Scanning, just as Vulnetix spans categories.

CapabilityVulnetixMITRE SAF
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation~ Ingest-only: converts gosec, SonarQube, Fortify, Veracode output to HDF; runs no static analysis itself
SCA / dependencies40+ ecosystems, transitive graph~ Ingest-only: normalizes Snyk/Trivy/Dependency-Track/JFrog Xray dependency findings; no native SCA engine
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine~ Ingest-only: converts OWASP ZAP, Nikto, Burp, Netsparker output to HDF; runs no dynamic test
Container & imageImage CVEs, base image, Dockerfile~ Ingest-only: converts Trivy, Twistlock/Prisma, Anchore Grype, NeuVector output; runs no image scan
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history~ Ingest-only: converts Trufflehog secret-scan output to HDF; runs no secret detection itself
Cloud / CSPMCloud-posture findings, compliance tab~ Ingest-only: converts Prowler, AWS Config, Security Hub (ASFF), Scoutsuite findings to HDF
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable~ Converts CycloneDX and Dependency-Track SBOM/vuln output to/from HDF; does not generate SBOMs
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Normalizes 30+ tools' output into one HDF view for Heimdall, but no cross-scanner finding-level dedup/one-queue prioritization
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What MITRE SAF does well

Where Vulnetix adds to it: MITRE SAF is a normalization/compliance-conversion layer that ingests 30+ tools into HDF; it runs no scanners of its own. Vulnetix natively runs SAST/SCA/IaC/container/secrets/cloud/malware engines AND adds cross-scanner finding-level dedup into one prioritized queue, exploit-intel (EPSS/KEV/ESS/LEV), reachability, versioned VEX, autofix and SSVC. For the DAST tools SAF ingests (ZAP, Nikto, Burp), Vulnetix likewise ingests and orchestrates their output rather than running dynamic tests itself. The two are complementary where SAF feeds Heimdall/eMASS compliance evidence.

No migration, no rip-and-replace. MITRE SAF keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise MITRE SAF results in Vulnetix

Upload MITRE SAF SARIF, JSON, CSV output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

MITRE SAF documentation ↗  ·  Source repository ↗

Wire MITRE SAF into your CI/CD pipeline →