Discover / Security

Prowler

by prowler-cloudPython

Cloud security assessments for AWS, Azure, GCP and Kubernetes.

Toolstable

Maturity: stable because 10y old, 5.36.0 released 10d ago. Derived from release and commit history, not a rating.

Stars
15k
Forks
2.3k
Downloads / mo
Last commit
2026-08-01
License
Apache-2.0
Open issues
260

Market and trust evidence

Edition not yet matched

No exact skills.sh identity match is available for this repository. Repository adoption and freshness remain visible above; install momentum is not inferred.

Trust analysis is a screening signal, not a security warranty. Read the ranking and trust methodology.

In practice

Written by AI from this repository’s README · high confidence

Cloud accounts drift out of compliance and teams have no repeatable way to audit them against standards like CIS, PCI DSS or SOC2.

Use it when

When you need repeatable security and compliance assessments across cloud provider accounts with ready made framework coverage.

Not the right pick when

Wrong pick if you want a hosted interface with no operational work, which the README routes to Prowler Cloud instead.

Capabilities

  • thousands of ready to use security checks
  • compliance frameworks including CIS, NIST, PCI-DSS, GDPR, HIPAA and SOC2
  • ThreatScore weighted risk prioritization scoring
  • local dashboard launched with prowler dashboard
  • self hosted Prowler Local Server web application

Cost: Open source with a paid cloud option

Install

Derived from the published package name in the repository, not from a model.

Video walkthroughs

Third-party YouTube uploads matched to this tool by title, channel and repository name on 2026-08-03. Not made, reviewed or endorsed by SkillPilot. View counts and publish months are as of the match date and the month is approximate. Nothing loads from YouTube until you press play.

What the repository ships

Has testsHas docsHas examplesDocker imageSecurity policyCI configured

Detected from the actual files in the repository root.

Latest release 5.36.0

Published 2026-07-24

✨ New features to highlight in this version

Enjoy them all now for free at https://cloud.prowler.com

🎫 Finding Groups - Jira

[!NOTE]

This feature is available exclusively in Prowler Cloud and Prowler Private Cloud with a subscription.

Selected Findings, Finding Groups, and mixed selections can now be sent to Jira. When you select multiple findings, choose between one grouped issue or separate issues. Generated issues keep their Prowler context with deep links and filter details, while the UI provides clear dispatch and failure feedback.

<img width="4596" height="2614" alt="image" src="https://github.com/user-attachments/assets/00220926-aae1-480d-96a0-437e0d91763f" />

Read more in our Jira integration documentation.

🕸️ Attack Paths - Queries

[!NOTE]

This feature is available exclusively in Prowler Cloud and Prowler Private Cloud with a subscription.

Prowler Cloud now records which built-in Attack Paths queries returned data at the end of each scan. The query selector hides confirmed-empty queries for the selected scan, so you can focus on paths that exist without opening blank graph views. Errored, unknown, and parameterized queries remain available when they still require investigation or input.

All Attack Paths queries are now published on Prowler Hub, where you can browse the full catalog.

<img width="4406" height="2260" alt="image" src="https://github.com/user-attachments/assets/a4f3de04-6499-4f5d-9398-8f8469220065" />

Read more in our Attack Paths documentation.

🧑‍🏫 New Tutorials: Connect Your AI Agents to Prowler Cloud

[!NOTE]

For this feature you need a Prowler Cloud API key so this is available exclusively in Prowler Cloud and Prowler Private Cloud with a subscription.

New tutorials walk you through connecting your own AI agents to Prowler Cloud, so they can query your security posture and act on it programmatically.

Read more in our AI agents documentation.

☁️ Region-less Oracle Cloud Infrastructure Setup

Oracle Cloud Infrastructure (OCI) provider credentials no longer require a region. Existing clients can still send the legacy region field for compatibility, but the API ignores it before storing credentials or starting a scan. This removes an unnecessary step from OCI onboarding.

Read more in our OCI documentation.

🔍 Checks

AWS

  • sagemaker_notebook_instance_no_secrets scans the OnCreate and OnStart lifecycle scripts of SageMaker notebook instances for hardcoded API keys, passwords, tokens, connection strings, and other secrets. Thanks to @kiranrajsg!

Read more in our AWS documentation.

Explore all AWS checks at Prowler Hub.

🔐 Security

  • Integration responses and operations now respect provider visibility, preventing hidden-provider disclosure and blocking unauthorized attachment, connection checks, Jira dispatches, edits, and deletion.
  • Next.js was updated from 16.2.9 to 16.2.11, patching four high-severity and five medium-severity vulnerabilities.
  • The unused npm CLI was removed from the UI container image, eliminating the bundled node-tar CVE-2026-59873 and reducing exposure to future bundled npm vulnerabilities.
  • Vitest and its browser packages were updated from 4.1.8 to 4.1.10, resolving the critical @vitest/browser file-access permission bypass. These are development dependencies and have no runtime impact.
  • Kubernetes kubeconfig valida

Tags

README

<p align="center">

<img align="center" alt="Prowler logo" src="https://github.com/prowler-cloud/prowler/blob/master/docs/img/prowler-logo-black.png#gh-light-mode-only" width="50%" height="50%">

<img align="center" alt="Prowler logo" src="https://github.com/prowler-cloud/prowler/blob/master/docs/img/prowler-logo-white.png#gh-dark-mode-only" width="50%" height="50%">

</p>

<p align="center">

<b><i>Prowler</b> is the Open Cloud Security Platform trusted by thousands to automate security and compliance in any cloud environment. With thousands of ready-to-use checks and compliance frameworks, Prowler delivers real-time, customizable monitoring and seamless integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.

</p>

<p align="center">

<b>The Agentic Cloud Defender</i></b>

</p>

<p align="center">

<a href="https://cloud.prowler.com/sign-up">Try Prowler Cloud</a>

</p>

<p align="center">

<a href="https://goto.prowler.com/slack"><img width="30" height="30" alt="Prowler community on Slack" src="https://github.com/prowler-cloud/prowler/assets/38561120/3c8b4ec5-6849-41a5-b5e1-52bbb94af73a"></a>

<br>

<a href="https://goto.prowler.com/slack">Join our Prowler community!</a>

</p>

<hr>

<p align="center">

<a href="https://goto.prowler.com/slack"><img alt="Slack Shield" src="https://img.shields.io/badge/slack-prowler-brightgreen.svg?logo=slack"></a>

<a href="https://pypi.org/project/prowler/"><img alt="Python Version" src="https://img.shields.io/pypi/v/prowler.svg"></a>

<a href="https://pypi.python.org/pypi/prowler/"><img alt="Python Version" src="https://img.shields.io/pypi/pyversions/prowler.svg"></a>

<a href="https://pypistats.org/packages/prowler"><img alt="PyPI Downloads" src="https://img.shields.io/pypi/dw/prowler.svg?label=downloads"></a>

<a href="https://hub.docker.com/r/toniblyx/prowler"><img alt="Docker Pulls" src="https://img.shields.io/docker/pulls/toniblyx/prowler"></a>

<a href="https://gallery.ecr.aws/prowler-cloud/prowler"><img width="120" height="19" alt="AWS ECR Gallery" src="https://user-images.githubusercontent.com/3985464/151531396-b6535a68-c907-44eb-95a1-a09508178616.png"></a>

<a href="https://codecov.io/gh/prowler-cloud/prowler"><img alt="Codecov coverage" src="https://codecov.io/gh/prowler-cloud/prowler/graph/badge.svg?token=OflBGsdpDl"/></a>

<a href="https://insights.linuxfoundation.org/project/prowler-cloud-prowler"><img alt="Linux Foundation insights health score" src="https://insights.linuxfoundation.org/api/badge/health-score?project=prowler-cloud-prowler"/></a>

</p>

<p align="center">

<a href="https://github.com/prowler-cloud/prowler/releases"><img alt="Version" src="https://img.shields.io/github/v/release/prowler-cloud/prowler"></a>

<a href="https://github.com/prowler-cloud/prowler/releases"><img alt="Version" src="https://img.shields.io/github/release-date/prowler-cloud/prowler"></a>

<a href="https://github.com/prowler-cloud/prowler"><img alt="Contributors" src="https://img.shields.io/github/contributors-anon/prowler-cloud/prowler"></a>

<a href="https://github.com/prowler-cloud/prowler/issues"><img alt="Issues" src="https://img.shields.io/github/issues/prowler-cloud/prowler"></a>

<a href="https://github.com/prowler-cloud/prowler"><img alt="License" src="https://img.shields.io/github/license/prowler-cloud/prowler"></a>

<a href="https://twitter.com/ToniBlyx"><img alt="Twitter" src="https://img.shields.io/twitter/follow/toniblyx?style=social"></a>

<a href="https://twitter.com/prowlercloud"><img alt="Twitter" src="https://img.shields.io/twitter/follow/prowlercloud?style=social"></a>

</p>

<hr>

<p align="center">

<img align="center" alt="Prowler Cloud demo" src="/docs/img/prowler-cloud.gif" width="100%" height="100%">

</p>

Description

Prowler is the world’s most widely used _Open-Source Cloud Security Platform_ that automates security and compliance across any cloud environment. With thousands of ready-to-use security checks, remediation guidance, and compliance frameworks, Prowler is built to _“Secure ANY Cloud at AI Speed”_. Prowler delivers AI-driven, customizable, and easy-to-use assessments, dashboards, reports, and integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.

Prowler includes hundreds of built-in controls to ensure compliance with standards and frameworks, including:

  • Prowler ThreatScore: Weighted risk prioritization scoring that helps you focus on the most critical security findings first
  • Industry Standards: CIS, NIST 800, NIST CSF, CISA, and MITRE ATT&CK
  • Regulatory Compliance and Governance: RBI, FedRAMP, PCI-DSS, and NIS2
  • Frameworks for Sensitive Data and Privacy: GDPR, HIPAA, and FFIEC
  • Frameworks for Organizational Governance and Quality Control: SOC2, GXP, and ISO 27001
  • Cloud-Specific Frameworks: AWS Foundational Technical Review (FTR), AWS Well-Architected Framework, and BSI C5
  • National Security Standards: ENS (Spanish National Security Scheme) and KISA ISMS-P (Korean)
  • Custom Security Frameworks: Tailored to your needs

Prowler Cloud & Prowler Local Server

Prowler Cloud and Prowler Local Server, its self-hosted open-source version, are web applications that simplify running Prowler across your cloud provider accounts. They provide a user-friendly interface to visualize the results and streamline your security assessments.

Prowler Cloud

Risk Pipeline

Threat Map

For more details, refer to the Prowler Local Server documentation

Prowler CLI


prowler <provider>

Prowler CLI Execution

Prowler Local Dashboard


prowler dashboard

Prowler Local Dashboard

Attack Paths

Attack Paths automatically extends every completed AWS scan with a graph that combines Cartography's cloud inventory with Prowler findings. The feature runs in the API worker after each scan.

Two graph backends are supported as the long-lived sink:

  • Neo4j (default; the Docker Compose files already ship a neo4j service).
  • Amazon Neptune (cloud-managed; opt-in).

Select the sink with ATTACK_PATHS_SINK_DATABASE (neo4j or neptune; default neo4j).

Note: Cartography ingestion always uses a temporary Neo4j database, regardless of the configured sink. The NEO4J_* variables below must remain set even when ATTACK_PATHS_SINK_DATABASE=neptune.

Neo4j sink

| Variable | Description | Default |

| --- | --- | --- |

| NEO4J_HOST | Hostname used by the API containers. | neo4j |

| NEO4J_PORT | Bolt port exposed by Neo4j. | 7687 |

| NEO4J_USER / NEO4J_PASSWORD | Credentials with rights to create per-tenant databases. | neo4j / neo4j_password |

Neptune sink

| Variable | Description | Default |

| --- | --- | --- |

| NEPTUNE_WRITER_ENDPOINT | Bolt host for the Neptune writer instance. Required when sink is neptune. | _empty_ |

| NEPTUNE_READER_ENDPOINT | Optional reader endpoint for read-only queries. Falls back to the writer when unset. | _empty_ |

| NEPTUNE_PORT | Bolt port exposed by Neptune. | 8182 |

| AWS_REGION | Region the Neptune cluster lives in. Required when sink is neptune. | _empty_ |

Neptune authenticates with SigV4 using the standard boto3 credential chain. The worker's IAM role (or AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY) supplies the credentials. There is no Neptune password variable.

Every AWS provider scan will enqueue an Attack Paths ingestion job automatically. Other cloud providers will be added in future iterations.

Prowler at a Glance

[!Tip]

For the most accurate and up-to-date information about checks, services, frameworks, and categories, visit Prowler Hub.

| Provider | Checks | Services | Compliance Frameworks | Categories | Support | Interface |

|---|---|---|---|---|---|---|

| AWS | 621 | 86 | 47 | 19 | Official | UI, API, CLI |

| Azure | 191 | 22 | 21 | 16 | Official | UI, API, CLI |

| GCP | 109 | 20 | 19 | 12 | Official | UI, API, CLI |

| Kubernetes | 92 | 7 | 8 | 11 | Official | UI, API, CLI |

| GitHub | 24 | 3 | 2 | 5 | Official | UI, API, CLI |

| M365 | 111 | 10 | 6 | 10 | Official | UI, API, CLI |

| OCI | 52 | 14 | 5 | 10 | Official | UI, API, CLI |

| Alibaba Cloud | 63 | 9 | 6 | 9 | Official | UI, API, CLI |

| Cloudflare | 29 | 3 | 2 | 5 | Official | UI, API, CLI |

| IaC | See trivy docs. | N/A | N/A | N/A | Official | UI, API, CLI |

| MongoDB Atlas | 10 | 3 | 1 | 8 | Official | UI, API, CLI |

| LLM | See promptfoo docs. | N/A | N/A | N/A | Official | CLI |

| Image | N/A | N/A | N/A | N/A | Official | UI, API, CLI |

| Google Workspace | 65 | 11 | 3 | 6 | Official | UI, API, CLI |

| OpenStack | 34 | 5 | 1 | 9 | Official | UI, API, CLI |

| Vercel | 26 | 6 | 1 | 8 | Official | UI, API, CLI |

| Okta | 29 | 8 | 2 | 2 | Official | UI, API, CLI |

| Linode Contact us | 10 | 3 | 1 | 4 | Unofficial | CLI |

| Huawei Cloud Contact us | 25 | 10 | 1 | 6 | Unofficial | CLI |

| E2E Networks Contact us | 27 | 6 | 0 | 2 | Unofficial | CLI |

| Scaleway Contact us | 1 | 1 | 1 | 1 | Unofficial | CLI |

| StackIT Contact us | 7 | 2 | 1 | 3 | Unofficial | CLI |

| NHN | 6 | 2 | 2 | 0 | Unofficial | CLI |

[!Note]

The numbers in the table are updated periodically.

[!Note]

Use the following commands to list Prowler's available checks, services, compliance frameworks, and categories:

- prowler <provider> --list-checks

- prowler <provider> --list-services

- prowler <provider> --list-compliance

- prowler <provider> --list-categories

💻 Installation

Prowler Local Server

Prowler Local Server offers flexible installation methods tailored to various environments:

For detailed instructions on using Prowler Local Server, refer to the usage guide.

Docker Compose

Requirements
  • Docker Compose installed: https://docs.docker.com/compose/install/.
Commands

_macOS/Linux:_


VERSION=$(curl -s https://api.github.com/repos/prowler-cloud/prowler/releases/latest | jq -r .tag_name)
curl -sLO "https://raw.githubusercontent.com/prowler-cloud/prowler/refs/tags/${VERSION}/docker-compose.yml"
# Environment variables can be customized in the .env file. Using default values in production environments is not recommended.
curl -sLO "https://raw.githubusercontent.com/prowler-cloud/prowler/refs/tags/${VERSION}/.env"
docker compose up -d

_Windows PowerShell:_


$VERSION = (Invoke-RestMethod -Uri "https://api.github.com/repos/prowler-cloud/prowler/releases/latest").tag_name
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/prowler-cloud/prowler/refs/tags/$VERSION/docker-compose.yml" -OutFile "docker-compose.yml"
# Environment variables can be customized in the .env file. Using default values in production environments is not recommended.
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/prowler-cloud/prowler/refs/tags/$VERSION/.env" -OutFile ".env"
docker compose up -d

[!WARNING]

🔒 For a secure setup, the API auto-generates a unique key pair, DJANGO_TOKEN_SIGNING_KEY and DJANGO_TOKEN_VERIFYING_KEY, and stores it in ~/.config/prowler-api (non-container) or the bound Docker volume in _data/api (container). Never commit or reuse static/default keys. To rotate keys, delete the stored key files and restart the API.

Once configured, access Prowler Local Server at http://localhost:3000. Sign up using your email and password to get started.

Common Issues with Docker Pull Installation

[!Note]

If you want to use AWS role assumption (e.g., with the "Connect assuming IAM Role" option), you may need to mount your local .aws directory into the container as a volume (e.g., - "${HOME}/.aws:/home/prowler/.aws:ro"). There are several ways to configure credentials for Docker containers. See the Troubleshooting section for more details and examples.

You can find more information in the Troubleshooting section.

From GitHub

Requirements
Commands to run the API

git clone https://github.com/prowler-cloud/prowler
cd prowler/api
uv sync
source .venv/bin/activate
set -a
source .env
docker compose up postgres valkey -d
cd src/backend
python manage.py migrate --database admin
gunicorn -c config/guniconf.py config.wsgi:application

After completing the setup, access the API documentation at http://localhost:8080/api/v1/docs.

Commands to run the API Worker

git clone https://github.com/prowler-cloud/prowler
cd prowler/api
uv sync
source .venv/bin/activate
set -a
source .env
cd src/backend
python -m celery -A config.celery worker -l info -E
Commands to run the API Scheduler

git clone https://github.com/prowler-cloud/prowler
cd prowler/api
uv sync
source .venv/bin/activate
set -a
source .env
cd src/backend
python -m celery -A config.celery beat -l info --scheduler django_celery

Truncated. Read the full README on GitHub ↗

Related tools