prowler
https://github.com/prowler-cloud/prowler
Python
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST C
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported1 Subscribers
Add a CodeTriage badge to prowler
Help out
- Issues
- feat(compliance): add Cloudflare mappings to NCSC Cyber Essentials 3.3 framework
- `s3_bucket_public_access` reports a public bucket as PASS when `GetBucketAcl` or `GetBucketPolicy` is denied
- feat(ui): connect and test AWS accounts in one step
- feat(api): add an explicit endpoint for S3-compatible scan output storage
- fix(aws): reuse the STS region that answered and add PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS
- fix(sdk): report MANUAL when S3 bucket ACL or policy is unreadable
- fix(ui): wait for the full provider connection check before reporting a result
- Feature request: retention / purge policy for `findings` and `compliance_requirements_overviews` in Prowler Local Server
- [New Check]: aks_cluster_kms_cmk_encryption_enabled
- fix(azure): support destination_port_ranges and wildcard ports in network NSG checks (#12854)
- Docs
- Python not yet supported