awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
prowler-cloud avatar

prowler-cloud/prowler

0
View on GitHub↗
13,049 stars·2,002 forks·Python·apache-2.0·9 vuesprowler.com↗

Prowler

Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity.

The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of configuration files, ensuring security coverage across the entire development lifecycle.

The tool provides comprehensive capabilities for continuous security integration, allowing teams to automate compliance reporting by mapping findings to regulatory frameworks. It supports risk prioritization and provides actionable remediation guidance, while enabling the integration of security data into external incident management and monitoring systems through automated reporting pipelines.

Features

  • Vulnerability Dependency Graphs - Identifies complex chains of misconfigurations using graph-based analysis to uncover exploitable security vulnerabilities.
  • Cloud Auditing Tools - Scans cloud infrastructure configurations against security benchmarks and industry best practices to identify vulnerabilities.
  • Infrastructure Security Scanners - Provides an automated engine for scanning cloud configurations and infrastructure-as-code templates for security risks.
  • Cloud Security Tools - Evaluates cloud environments against security benchmarks to maintain visibility into infrastructure posture and risk.
  • Attack Surface Analysis - Uses graph analysis to identify chains of misconfigurations that create exploitable routes for unauthorized access.
  • Infrastructure as Code Scanners - Analyzes infrastructure-as-code templates for security flaws to prevent misconfigurations in live cloud environments.
  • Posture Assessment Engines - Compares cloud resource snapshots against security rules to determine the current risk level of the infrastructure.
  • Compliance Reporting - Maps security assessment findings to regulatory frameworks to generate audit-ready compliance documentation.
  • Pipeline Security - Integrates automated security scanning into CI/CD pipelines to detect and block misconfigurations before deployment.
  • Compliance Mapping Tools - Maps security assessment results to regulatory frameworks to automate the generation of audit-ready documentation.
  • Regulatory Compliance - Tracks security findings against regulatory controls to maintain continuous compliance across cloud environments.
  • Cloud Infrastructure Security - Security assessment and hardening tool for AWS environments.
  • Network Reconnaissance - Audits security configurations across major cloud platforms.
  • Vulnerability Scanning and Auditing - Tool for AWS security best practices and auditing.
  • Audit and Compliance - Maps security findings to regulatory standards to simplify audit preparation and track compliance posture over time.
  • Remediation Guides - Provides actionable instructions and scripts for fixing identified security issues to reduce manual remediation effort.
  • Reachability Prioritizers - Evaluates and prioritizes identified vulnerabilities to help teams focus on the most critical infrastructure threats.
  • Static Analysis - Parses and evaluates infrastructure configuration files against security policies before deployment to prevent vulnerabilities.
  • Security Tool Integrations - Integrates security scanning tools into development workflows via APIs to automate vulnerability reporting.
  • Alerting and Incident Management - Streams security alerts and audit results to external incident management platforms for rapid response.
  • Security Information Management - Connects automated agents to security data sources to retrieve real-time risk information for programmatic analysis.
  • Plugin Execution Engines - Utilizes a modular plugin-based execution model to run independent security checks against cloud configurations.

Historique des stars

Graphique de l'historique des stars pour prowler-cloud/prowlerGraphique de l'historique des stars pour prowler-cloud/prowler

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Questions fréquentes

Que fait prowler-cloud/prowler ?

Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity.

Quelles sont les fonctionnalités principales de prowler-cloud/prowler ?

Les fonctionnalités principales de prowler-cloud/prowler sont : Vulnerability Dependency Graphs, Cloud Auditing Tools, Infrastructure Security Scanners, Cloud Security Tools, Attack Surface Analysis, Infrastructure as Code Scanners, Posture Assessment Engines, Compliance Reporting.

Quelles sont les alternatives open-source à prowler-cloud/prowler ?

Les alternatives open-source à prowler-cloud/prowler incluent : voltagent/awesome-claude-code-subagents — This project provides a framework for managing multi-agent systems, designed to automate complex software development,… toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… keygraphhq/shannon — Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis,… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… alfresco/prowler — Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for…

Alternatives open source à Prowler

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Prowler.
  • voltagent/awesome-claude-code-subagentsAvatar de VoltAgent

    VoltAgent/awesome-claude-code-subagents

    21,906Voir sur GitHub↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Shellai-agent-frameworkai-agent-toolsai-agents
    Voir sur GitHub↗21,906
  • toniblyx/prowlerAvatar de toniblyx

    toniblyx/prowler

    14,005Voir sur GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    Voir sur GitHub↗14,005
  • keygraphhq/shannonAvatar de KeygraphHQ

    KeygraphHQ/shannon

    44,672Voir sur GitHub↗

    Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis, and automated vulnerability remediation within self-hosted, private infrastructure. It functions as a unified security suite that orchestrates the entire lifecycle of vulnerability management, from initial discovery and reachability prioritization to the generation and verification of code-level patches. The platform distinguishes itself through its agentic approach to security, deploying autonomous agents to execute both black-box and white-box exploits against running applica

    TypeScriptpenetration-testingpentestingsecurity-audit
    Voir sur GitHub↗44,672
  • aws/aws-cdkAvatar de aws

    aws/aws-cdk

    12,817Voir sur GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    Voir sur GitHub↗12,817
  • Voir les 30 alternatives à Prowler→