prowler
https://github.com/prowler-cloud/prowler
Python
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST C
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported1 Subscribers
Add a CodeTriage badge to prowler
Help out
- Issues
- feat(m365): add entra check for federated credentials on privileged apps
- fix(github): preserve unkown secret scanning state
- chore: drop IAM actions covered by AWS managed policies
- Findings partition bounds leave a ~1ms gap at every month boundary; those findings land in findings_default and are never aged out
- fix(compliance): add M365 mappings to Cyber Essentials 3.3
- fix(gcp): report CSEK retirement in the instance encryption check
- fix(organizations): report MANUAL when policy inventory is incomplete
- Provider request: Fly.io
- github: repository_secret_scanning_enabled reports FAIL when GitHub never returned security_and_analysis, so the verdict tracks the caller's permission
- feat(compliance): add CISA SCuBA Microsoft Entra ID (AAD) baseline v1.8.0 for M365
- Docs
- Python not yet supported