Repository Issues
prowler-cloud/prowler
Prowler is an Open Source Security tool for AWS, Azure and GCP to perform Cloud Security best practices assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
Issues
Closed
[New Check]: Service principals with privileged Entra directory roles must not have owners
feature-requestgood first issuenew-checkprovider/m365
No assignee yetHas a beginner-friendly labelContributing guide available
3 comments0 reactions0 assignees
Closed
[New Check]: Mailbox primary SMTP address must use a verified custom domain (not .onmicrosoft.com)
feature-requestgood first issuenew-checkprovider/m365
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
3 comments0 reactions1 assignee
Closed
[New Check]: Microsoft Entra directory sync must block object takeover (soft- and hard-matching)
feature-requestgood first issuenew-checkprovider/m365
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
1 comment0 reactions0 assignees
Closed
[New Check]: At least one Conditional Access policy must explicitly target Azure DevOps
feature-requestgood first issuenew-checkprovider/m365
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
1 comment0 reactions0 assignees
Closed
[New Check]: Apps with Exchange mailbox permissions must be scoped via Application Access Policy
feature-requestgood first issuenew-checkprovider/m365
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
1 comment0 reactions1 assignee
Closed
[New Check]: Conditional Access policies must not reference deleted users, groups, or roles
feature-requestgood first issuenew-checkprovider/m365
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
1 comment0 reactions1 assignee
Closed
[New Check]: Conditional Access excluded objects must be covered by another policy (no exclusion gaps)
feature-requestgood first issuenew-checkprovider/m365
Why recommendedNo assignee yet · No comments yet
No assignee yetNo comments yetHas a beginner-friendly labelContributing guide available
0 comments0 reactions0 assignees
Closed
[New Check]: Conditional Access groups must be protected by RMAU or role-assignable groups
feature-requestgood first issuenew-checkprovider/m365
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
2 comments0 reactions1 assignee
Closed
[New Check]: SageMaker model monitoring schedules are active
feature-requestgood first issuenew-checkprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
2 comments0 reactions1 assignee
Closed
[New Check]: SageMaker Clarify processing jobs exist
feature-requestgood first issuenew-checkprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
2 comments0 reactions1 assignee
Closed
[New Check]: Bedrock agent execution roles follow least privilege
feature-requestgood first issuenew-checkprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
2 comments0 reactions1 assignee
Closed
Org-aware checks for GuardDuty / Security Hub / AWS Config (Delegated Admin + all opted-in Regions)
feature-requesthelp wanted
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
7 comments0 reactions1 assignee
Closed
Unable to run a scan in AzureChinaCloud region
ai-issue-reviewbugcan't reproducehelp wantedprovider/azureseverity/critical
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
3 comments0 reactions1 assignee
Closed
Add Support for Google Workspace admin settings
feature-requesthelp wantedplannedsource/slack
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
3 comments3 reactions0 assignees
Closed
Missing documented workload checks in prowler kubernetes scan output
feature-requestgood first issue
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
5 comments0 reactions0 assignees
Closed
Running into 302 error Subscription could not be found
ai-issue-reviewbugcan't reproducehelp wantedprovider/azureseverity/critical
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
24 comments0 reactions1 assignee
Closed
In the prowler ocsf.json report, the Finding_info entity is missing Analytic, and Attack field
feature-requesthelp wantedoutput/ocsf
Why recommendedNo assignee yet · Has a beginner-friendly label
No assignee yetHas a beginner-friendly labelContributing guide available
3 comments1 reaction0 assignees
Closed
Add a new s3 check to verify if objects inside the bucket are public
feature-requestgood first issueprovider/aws
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
9 comments0 reactions1 assignee
Closed
Implement more secrets checks
feature-requestgood first issue
Why recommendedHas a beginner-friendly label · Contributing guide available
Has a beginner-friendly labelContributing guide available
12 comments0 reactions2 assignees