PROWLER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Open-source cloud security auditing tool for AWS, Azure, and GCP. Checks against CIS benchmarks, GDPR, HIPAA, PCI-DSS, and more.
INSTALLATION#
pip install prowler # Or: pipx install prowler # Docker docker pull toniblyx/prowler docker run -v ~/.aws:/root/.aws toniblyx/prowler aws # From source git clone https://github.com/prowler-cloud/prowler cd prowler && pip install .
BASIC USAGE#
# AWS (uses default credentials) prowler aws # Azure prowler azure # GCP prowler gcp # Kubernetes prowler kubernetes
AWS SCANNING#
# Full scan prowler aws # Specific service prowler aws --service s3 prowler aws --service iam prowler aws --service ec2 prowler aws --service rds prowler aws --service lambda # Specific checks prowler aws --check iam_root_mfa_enabled prowler aws --check s3_bucket_public_access # List all checks prowler aws --list-checks # By severity prowler aws --severity critical prowler aws --severity critical high # By compliance framework prowler aws --compliance cis_1.5_aws prowler aws --compliance gdpr_aws prowler aws --compliance hipaa_aws prowler aws --compliance pci_3.2.1_aws prowler aws --compliance aws_well_architected_framework # Specific region prowler aws --region us-east-1 prowler aws --region eu-west-1,eu-central-1 # Specific profile prowler aws --profile staging # Assume role prowler aws --role arn:aws:iam::123456789012:role/ProwlerRole # Exclude checks prowler aws --excluded-checks iam_root_mfa_enabled # Exclude services prowler aws --excluded-services cloudwatch
AZURE SCANNING#
# Browser-based auth prowler azure --browser-auth # Service principal prowler azure --sp-env-auth # From env vars # Set: AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID # Specific subscription prowler azure --subscription-ids SUB_ID # Specific service prowler azure --service defender prowler azure --service iam prowler azure --service storage prowler azure --service network # Compliance prowler azure --compliance cis_2.0_azure
GCP SCANNING#
# Application Default Credentials prowler gcp # Service account key prowler gcp --credentials-file sa-key.json # Specific project prowler gcp --project-ids project-id # Compliance prowler gcp --compliance cis_2.0_gcp
OUTPUT OPTIONS#
# Output formats prowler aws -M csv # CSV prowler aws -M json # JSON prowler aws -M json-ocsf # OCSF format prowler aws -M html # HTML report # Output directory prowler aws -o /path/to/output/ # Only show failures prowler aws --status FAIL # Only show specific status prowler aws --status FAIL MANUAL # Quiet mode prowler aws --quiet
KEY CHECK CATEGORIES#
Category Example Checks -------- -------------- IAM Root MFA, password policy, access keys age S3 Public access, encryption, logging EC2 Security groups, EBS encryption, IMDSv2 RDS Public access, encryption, backups CloudTrail Enabled, multi-region, log validation VPC Flow logs, default SG rules Lambda Public access, runtime versions KMS Key rotation, policies EKS Public endpoint, logging, secrets GuardDuty Enabled in all regions
TIPS#
- Start with --severity critical to focus on high-impact issues - Use compliance frameworks for audit preparation - Schedule regular scans in CI/CD pipelines - --status FAIL reduces noise in reports - Supports multi-account scanning via role assumption - HTML output is great for stakeholder reports - Combine with ScoutSuite for comprehensive coverage - Prowler v3+ supports AWS, Azure, GCP, and K8s - Use OCSF output for SIEM integration - Check exit code for CI/CD pass/fail gates