← All cheat sheets

PROWLER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Open-source cloud security auditing tool for AWS, Azure, and GCP.
Checks against CIS benchmarks, GDPR, HIPAA, PCI-DSS, and more.

INSTALLATION#

pip install prowler
# Or: pipx install prowler

# Docker
docker pull toniblyx/prowler
docker run -v ~/.aws:/root/.aws toniblyx/prowler aws

# From source
git clone https://github.com/prowler-cloud/prowler
cd prowler && pip install .

BASIC USAGE#

# AWS (uses default credentials)
prowler aws

# Azure
prowler azure

# GCP
prowler gcp

# Kubernetes
prowler kubernetes

AWS SCANNING#

# Full scan
prowler aws

# Specific service
prowler aws --service s3
prowler aws --service iam
prowler aws --service ec2
prowler aws --service rds
prowler aws --service lambda

# Specific checks
prowler aws --check iam_root_mfa_enabled
prowler aws --check s3_bucket_public_access

# List all checks
prowler aws --list-checks

# By severity
prowler aws --severity critical
prowler aws --severity critical high

# By compliance framework
prowler aws --compliance cis_1.5_aws
prowler aws --compliance gdpr_aws
prowler aws --compliance hipaa_aws
prowler aws --compliance pci_3.2.1_aws
prowler aws --compliance aws_well_architected_framework

# Specific region
prowler aws --region us-east-1
prowler aws --region eu-west-1,eu-central-1

# Specific profile
prowler aws --profile staging

# Assume role
prowler aws --role arn:aws:iam::123456789012:role/ProwlerRole

# Exclude checks
prowler aws --excluded-checks iam_root_mfa_enabled

# Exclude services
prowler aws --excluded-services cloudwatch

AZURE SCANNING#

# Browser-based auth
prowler azure --browser-auth

# Service principal
prowler azure --sp-env-auth                 # From env vars
# Set: AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID

# Specific subscription
prowler azure --subscription-ids SUB_ID

# Specific service
prowler azure --service defender
prowler azure --service iam
prowler azure --service storage
prowler azure --service network

# Compliance
prowler azure --compliance cis_2.0_azure

GCP SCANNING#

# Application Default Credentials
prowler gcp

# Service account key
prowler gcp --credentials-file sa-key.json

# Specific project
prowler gcp --project-ids project-id

# Compliance
prowler gcp --compliance cis_2.0_gcp

OUTPUT OPTIONS#

# Output formats
prowler aws -M csv                          # CSV
prowler aws -M json                         # JSON
prowler aws -M json-ocsf                    # OCSF format
prowler aws -M html                         # HTML report

# Output directory
prowler aws -o /path/to/output/

# Only show failures
prowler aws --status FAIL

# Only show specific status
prowler aws --status FAIL MANUAL

# Quiet mode
prowler aws --quiet

KEY CHECK CATEGORIES#

Category                Example Checks
--------                --------------
IAM                     Root MFA, password policy, access keys age
S3                      Public access, encryption, logging
EC2                     Security groups, EBS encryption, IMDSv2
RDS                     Public access, encryption, backups
CloudTrail              Enabled, multi-region, log validation
VPC                     Flow logs, default SG rules
Lambda                  Public access, runtime versions
KMS                     Key rotation, policies
EKS                     Public endpoint, logging, secrets
GuardDuty               Enabled in all regions

TIPS#

  - Start with --severity critical to focus on high-impact issues
  - Use compliance frameworks for audit preparation
  - Schedule regular scans in CI/CD pipelines
  - --status FAIL reduces noise in reports
  - Supports multi-account scanning via role assumption
  - HTML output is great for stakeholder reports
  - Combine with ScoutSuite for comprehensive coverage
  - Prowler v3+ supports AWS, Azure, GCP, and K8s
  - Use OCSF output for SIEM integration
  - Check exit code for CI/CD pass/fail gates