Repository Issues
prowler-cloud/prowler
Prowler is an Open Source Security tool for AWS, Azure and GCP to perform Cloud Security best practices assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
Issues
Open
Add SAP BTP as a Cloud Provider
feature-requesthelp wanted
No assignee yetHas a beginner-friendly labelContributing guide available
5 comments0 reactions0 assignees
Closed
Missing documented workload checks in prowler kubernetes scan output
feature-requestgood first issue
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
5 comments0 reactions0 assignees
Open
GDPR Compliance Mappings for Azure and GCP
compliancefeature-requesthelp wanted
Why recommendedNo comments yet · Has a beginner-friendly label
No comments yetHas a beginner-friendly labelContributing guide available
0 comments0 reactions1 assignee
Closed
Running into 302 error Subscription could not be found
ai-issue-reviewbugcan't reproducehelp wantedprovider/azureseverity/critical
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
24 comments0 reactions1 assignee
Closed
In the prowler ocsf.json report, the Finding_info entity is missing Analytic, and Attack field
feature-requesthelp wantedoutput/ocsf
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
3 comments1 reaction0 assignees
Open
Integrating SCP/RCP Policy Awareness into Prowler Security Checks
feature-requesthelp wanted
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
2 comments0 reactions1 assignee
Open
SSH Access to Kuberenetes clusters for K8S Scans via UI.
component/uifeature-requesthelp wanted
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
3 comments3 reactions0 assignees
Open
Environment-Specific Log Group Retention Policy Validation
feature-requesthelp wanted
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
1 comment0 reactions0 assignees
Open
Possibility to use Mutelist in DynamoDB to all providers
feature-requesthelp wantedmutelist
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
1 comment0 reactions0 assignees
Closed
Add a new s3 check to verify if objects inside the bucket are public
feature-requestgood first issueprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
9 comments0 reactions1 assignee
Open
False positive on ec2_securitygroup_not_used with Batch Compute
feature-requesthelp wantedprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
6 comments0 reactions1 assignee
Closed
Implement more secrets checks
feature-requestgood first issue
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
12 comments0 reactions2 assignees
Open
Requesting an additional framework: CIS AWS Compute Services Benchmark v1.0.0
compliancefeature-requesthelp wantedprovider/aws
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
4 comments0 reactions0 assignees