awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Alfresco avatar

Alfresco/prowler

0
View on GitHub↗
14,005 stars·2,185 forks·Python·Apache-2.0·38 viewsprowler.com↗

Prowler

Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard.

The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories.

The platform covers a broad range of capabilities including automated security assessments, risk prioritization through weighted scoring, and continuous environment monitoring. It supports integration into development workflows via a security tooling SDK and programmatic APIs for triggering scans and exporting results.

Features

  • Cloud Security Posture Management - Provides a comprehensive platform for tracking, visualizing, and managing the security posture of multi-cloud environments.
  • Security Context Orchestration - Provides structured security context and data to AI assistants for performing automated vulnerability analysis and remediation.
  • AI Security Data Providers - Ships a data provider that feeds structured security context and tools to AI assistants for automated risk analysis.
  • Assistant Context Integrations - Streams structured security data and specialized toolsets to external AI assistants to provide enriched context for analysis.
  • Cloud Security Integrations - Interacts with multiple cloud provider endpoints to aggregate security audit data and infrastructure configuration states.
  • AI Security Context Servers - Implements a specialized context server that feeds structured security data to AI assistants for automated risk analysis.
  • Attack Surface Mapping - Maps cloud inventory and findings into directed graphs to visualize potential lateral movement and attacker exploitation routes.
  • Attack Path Visualizations - Employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories.
  • Automated Security Assessments - Provides a comprehensive library of security checks run across multi-cloud environments to identify risks.
  • Cloud Auditing Tools - Automates security checks across multiple cloud providers to identify vulnerabilities and infrastructure misconfigurations.
  • Compliance Frameworks - Evaluates cloud environments against regulatory frameworks and industry standards to ensure continuous policy adherence.
  • Audit and Compliance - Evaluates cloud infrastructure against established regulatory frameworks and industry security standards.
  • Regulatory Compliance - Evaluates cloud infrastructure against industry benchmarks, regulatory frameworks, and security standards.
  • Cloud Security Posture Scanners - Provides a scanning engine that detects security risks and calculates weighted risk scores for multi-cloud assets.
  • Modular Scanning Engines - Ships a modular scanning engine that executes a library of security checks to identify multi-cloud misconfigurations.
  • CI/CD Integrations - Runs automated security scans during the continuous integration process to detect infrastructure issues before production.
  • CI/CD Pipeline Integrations - Integrates security checks into continuous integration pipelines and exports results for pull request annotations.
  • Scan Result Exporters - Converts security scan findings into standardized file formats for integration with CI/CD pipelines and reporting tools.
  • Cloud Security Monitoring - Provides real-time tracking and auditing of security posture across diverse cloud platform configurations.
  • Custom Security Scan Extensions - Offers a pluggable architecture and SDK for adding custom security tests and vulnerability probes.
  • Security Scan Organizers - Ships a web interface for managing security scans and visualizing assessment results across multiple cloud accounts.
  • Security Analysis Dashboards - Provides a web interface for visualizing security findings and managing compliance assessments across multiple cloud accounts.
  • Security Auditing - Provides programmatic endpoints to trigger security scans and retrieve audit results via a dedicated API.
  • Security Management Dashboards - Provides a dedicated graphical application for triggering scans, viewing results, and managing security assessments.
  • Security Tooling SDKs - Allows developers to build custom security checks and capabilities by hooking into the core scanning framework.
  • Asset Risk Scoring - Calculates priority levels for security findings by applying numeric weights to vulnerability severity and asset criticality.
  • Cloud Security - Audits AWS security against CIS benchmarks.
  • Vulnerability Auditing - Comprehensive AWS security assessment and hardening tool.

Star history

Star history chart for alfresco/prowlerStar history chart for alfresco/prowler

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Prowler

These projects share indexed features with Prowler. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005
  • aquasecurity/cloudsploitaquasecurity avatar

    aquasecurity/cloudsploit

    3,705View on GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    JavaScriptalibabaaquaaws
    View on GitHub↗3,705
  • cloudquery/cloudquerycloudquery avatar

    cloudquery/cloudquery

    6,438View on GitHub↗

    CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses. The system distinguishes itself by transforming complex, nested cloud API responses into flat relational tables, enabling the use of standard SQL for asset querying and analysis. It employs a modular plugin system for data ex

    Goairbyteattack-surface-managementaws
    View on GitHub↗6,438
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
Compare all 30 related projects→

Frequently asked questions

What does alfresco/prowler do?

Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard.

What are the main features of alfresco/prowler?

The main features of alfresco/prowler are: Cloud Security Posture Management, Security Context Orchestration, AI Security Data Providers, Assistant Context Integrations, Cloud Security Integrations, AI Security Context Servers, Attack Surface Mapping, Attack Path Visualizations.

Which projects share features with alfresco/prowler?

Projects with overlapping indexed features include: toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… aquasecurity/cloudsploit — Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud… cloudquery/cloudquery — CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… intuitem/ciso-assistant-community — This project is a governance, risk, and compliance platform designed to centralize security governance, risk… cloudsploit/scans — This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and…