△EvalCybersecurityFree
Prowler — Cloud Security Posture Manager
Apache-licensed multi-cloud security assessment tool covering 500+ checks across AWS, Azure, GCP, and Kubernetes, including AI service misconfigurations.
Prowler — Cloud Security Posture Manager
Prowler is an open-source Cloud Security Posture Management (CSPM) tool that audits AWS, Azure, GCP, and Kubernetes environments against 500+ security best practices, CIS benchmarks, SOC2, GDPR, HIPAA, and NIST frameworks. It surfaces misconfigurations in the cloud infrastructure that hosts AI workloads — S3 buckets, IAM policies, SageMaker endpoints, Azure OpenAI service settings, and more.
Key Features
- 500+ checks across AWS (350+), Azure (100+), GCP (70+), Kubernetes
- Compliance frameworks: CIS, PCI-DSS, HIPAA, GDPR, SOC2, NIST 800-53
- AI-specific checks: SageMaker endpoint encryption, Bedrock model access policies, Azure OpenAI network rules
- HTML, JSON, CSV, OCSF output; Slack/S3 integrations
- GitHub Actions and CI/CD-ready
Quick Start
pip install prowler
# Scan AWS account
prowler aws
# Scan specific services
prowler aws --services sagemaker s3 iam
# Run CIS benchmark
prowler aws --compliance cis_1.5_aws
npx ai-supply add prowler-cloud-security-posture
Curated mirror of the open-source Prowler (Apache-2.0). Get it from the source.