prowler

Security scanner

An automated security assessment tool for cloud infrastructure and applications

Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.

GitHub

11k stars
130 watching
2k forks
Language: Python
last commit: almost 2 years ago
Linked from 6 awesome lists

awsazurecis-benchmarkcloudcompliancecspmdevsecopsforensicsgcpgdprhardeningiammulti-cloudpythonsaassecuritysecurity-auditsecurity-hardeningsecurity-toolswell-architected

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
securityftw/cs-suiteAn automated tool suite to assess and improve cloud security across multiple platforms1,145
t0pcyber/hawkA PowerShell-based tool to gather information on O365 intrusions and potential breaches.722
bishopfox/cloudfoxAn open-source tool to help penetration testers gather information about cloud environments and identify potential vulnerabilities.1,983
jordanpotti/cloudscraperA tool to spider and search cloud resources like AWS, Azure, and Digital Ocean for potential vulnerabilities.506
cloudina/hawkAn API-based antivirus scanning system for cloud storage services23
portswigger/aws-security-checksA set of automated security checks for AWS services written in Python to identify potential vulnerabilities and configuration issues.36
toniblyx/my-arsenal-of-aws-security-toolsA curated list of open-source tools for assessing and improving AWS security posture9,007
eliasgranderubio/dagdaA tool to analyze and monitor Docker images and containers for security threats1,164
azure/stormspotterA tool for analyzing and visualizing Azure objects to help security teams understand potential attack surfaces.1,555
azure/cloud-katanaAutomates security assessment and research in cloud-native environments using event-driven serverless computing250
jonrau1/electriceyeA Python CLI tool for managing security and compliance in cloud and SaaS environments966
deepfence/threatmapperAn application protection platform that monitors and analyzes cloud-native applications for vulnerabilities and threats.4,861
belane/cloudhunterTools for scanning and analyzing cloud storage bucket permissions134
openscanner/xguardianA security scanner for OSX applications that detects potential vulnerabilities in URL scheme hijack, bundle ID hijack, and keychain hijack.41
coinbase/salusA tool for coordinating security scanning of software projects25