prowler
https://github.com/prowler-cloud/prowler
Python
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST C
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported1 Subscribers
Add a CodeTriage badge to prowler
Help out
- Issues
- feat(api): accept Azure certificate credentials and document the contract
- fix(gcp): describe BigQuery datasets and tables through a bounded thread pool
- feat(azure): add certificate authentication to Azure SDK
- [New Check]: AWS SQS - Enforce encryption of data in transit
- fix(api): omit empty AWS session token when creating S3 client
- feat(aws): Update regions for AWS services
- Add SQS check for secure transport enabled
- S3 output: presigned download URLs carry an empty X-Amz-Security-Token, breaking non-AWS endpoints (403 AccessDenied)
- fix(github,aws): prevent incomplete security scans from passing
- GCP: BigQuery service does one tables.get() per table, making scans of large data estates appear hung
- Docs
- Python not yet supported