prowler-cloud / prowler
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
☆11,185Updated this week
Alternatives and similar repositories for prowler:
Users that are interested in prowler are comparing it to the libraries listed below
- Multi-Cloud Security Auditing Tool☆6,910Updated 2 months ago
- Cloud Security Posture Management (CSPM)☆3,419Updated last week
- List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.☆9,063Updated 3 months ago
- Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resour…☆5,542Updated this week
- CloudMapper helps you analyze your Amazon Web Services (AWS) environments.☆6,055Updated 6 months ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆4,507Updated last week
- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized repo…☆2,030Updated this week
- Tfsec is now part of Trivy☆6,756Updated 3 weeks ago
- A tool for quickly evaluating IAM permissions in AWS.☆1,450Updated 6 months ago
- Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.☆4,822Updated last month
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,064Updated last week
- Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.☆1,146Updated 2 years ago
- Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powere…☆3,149Updated this week
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆1,800Updated last month
- Security auditing tool for AWS environments☆1,730Updated 6 years ago
- ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring su…☆972Updated last week
- Automating situational awareness for cloud penetration tests.☆2,020Updated last month
- IAM Least Privilege Policy Generator☆2,045Updated this week
- Granular, Actionable Adversary Emulation for the Cloud☆1,902Updated this week
- [Node, Python, Java] Repository of sample Custom Rules for AWS Config.☆1,629Updated 3 weeks ago
- Terratest is a Go library that makes it easier to write automated tests for your infrastructure code.☆7,572Updated this week
- AWS Least Privilege for Distributed, High-Velocity Deployment☆1,129Updated last year
- Hunt for security weaknesses in Kubernetes clusters☆4,787Updated 10 months ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆24,545Updated this week
- PacBot (Policy as Code Bot)☆1,291Updated 2 years ago
- Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.☆7,162Updated this week
- Generate an IAM policy from AWS, Azure, or Google Cloud (GCP) calls using client-side monitoring (CSM) or embedded proxy☆3,173Updated this week
- Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.☆4,356Updated 3 years ago
- Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS F…☆1,152Updated 6 months ago
- Ultimate DevSecOps library☆5,876Updated 2 months ago