#9 · Primary category: Cybersecurity & Decryption Tools

prowler

aws azure cis-benchmark cloud cloudsecurity compliance cspm devsecops forensics gcp gdpr hacktoberfest hardening iam multi-cloud python security security-audit security-hardening security-tools

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Project last updated:08/28/26

GitHub Stars

14.7K

Forks

2.3K

Contributors

460

License

Apache-2.0

Why we included this project

Prowler is a command-line cloud scanner that ships hundreds of ready-to-run checks, so a team can audit AWS, Azure, Google Cloud, Kubernetes, Microsoft 365, and GitHub from one tool instead of writing bespoke security scripts. Point it at a provider and it runs those checks against benchmarks such as CIS, NIST, PCI DSS, and ISO 27001, then exports the findings as HTML, JSON, or CSV for downstream tooling. That gives anyone who owns cloud accounts a repeatable way to answer 'what is misconfigured or exposed right now,' whether an SRE is chasing down a publicly accessible storage bucket, a security engineer is assembling evidence before an audit, or a startup is checking its hardening baseline. The checks are written to be readable and extensible, which matters if you want to verify what the tool actually does or add your own rules without fighting the codebase. It runs as a CLI, a Docker image, or a Python package, so it drops into an existing pipeline without forcing a particular deployment model.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category