docs: apply SEO and metadata best practices to changed pages

This commit is contained in:
mintlify[bot]
2026-07-08 12:31:58 +00:00
committed by GitHub
parent d874fc573d
commit 9c5ed27a7a
172 changed files with 318 additions and 156 deletions
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'AI Skills System'
title: 'AI Skills System for Prowler Contributors'
description: 'Enable AI coding assistants like Claude Code, Cursor, and Copilot to follow Prowler patterns using structured skills, setup scripts, and triggers.'
---
This guide explains the AI Skills system that provides on-demand context and patterns to AI agents working with the Prowler codebase.
@@ -1,5 +1,6 @@
---
title: 'Alibaba Cloud Provider'
title: 'Alibaba Cloud Provider Implementation'
description: 'Explore the Alibaba Cloud provider in Prowler, covering session management, RAM authentication, STS credentials, region discovery, and service classes.'
---
This page details the [Alibaba Cloud](https://www.alibabacloud.com/) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'AWS Provider'
title: 'AWS Provider Implementation'
description: 'Understand the AWS provider internals in Prowler: boto3 sessions, IAM role assumption, region and Organizations discovery, and service base classes.'
---
In this page you can find all the details about [Amazon Web Services (AWS)](https://aws.amazon.com/) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Azure Provider'
title: 'Azure Provider Implementation'
description: 'Learn how the Azure provider in Prowler manages Service Principal, CLI, browser, and Managed Identity auth, subscription discovery, and Entra ID scanning.'
---
In this page you can find all the details about [Microsoft Azure](https://azure.microsoft.com/) provider implementation in Prowler.
@@ -1,5 +1,6 @@
---
title: 'Check Metadata Guidelines'
title: 'Check Metadata Writing Guidelines'
description: 'Follow Prowler conventions for writing check titles, descriptions, risk, remediation, and status_extended fields when authoring check metadata JSON files.'
---
## Introduction
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Prowler Checks'
title: 'Creating New Prowler Checks'
description: 'Step-by-step guide to add a new security check to Prowler, covering folder structure, naming conventions, metadata files, test scenarios, and CLI validation.'
---
This guide explains how to create new checks in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Configurable Checks in Prowler'
title: 'Configurable Checks with audit_config'
description: 'Make Prowler checks configurable through the audit_config object and config.yaml, letting users override thresholds, defaults, and check behavior at scan time.'
---
Prowler empowers users to extend and adapt cloud security coverage by making checks configurable through the use of the `audit_config` object. This approach enables customization of checks to meet specific requirements through a configuration file.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Debugging in Prowler'
title: 'Debugging Prowler with VSCode'
description: 'Set up Visual Studio Code launch configurations and debugpy to step through Prowler checks, services, and provider code for AWS, Azure, GCP, and more.'
---
Debugging in Prowler simplifies the development process, allowing developers to efficiently inspect and resolve unexpected issues during execution.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Contributing to Documentation'
title: 'Contributing to Prowler Documentation'
description: 'Contribute to Prowler docs built with Mintlify: learn the section structure, AI agent guidelines, local preview setup, and style conventions for MDX pages.'
---
Prowler documentation is built using [Mintlify](https://www.mintlify.com/docs), allowing contributors to easily add or enhance documentation.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'End-2-End Tests for Prowler App'
title: 'End-to-End Tests for Prowler App'
description: 'Write Playwright end-to-end tests for Prowler App covering user journeys, Page Object Models, storage state reuse, and organizing spec files by feature area.'
---
End-to-end (E2E) tests validate complete user flows in Prowler App (UI + API). These tests are implemented with [Playwright](https://playwright.dev/) under the `ui/tests` folder and are designed to run against a Prowler App environment.
@@ -1,5 +1,6 @@
---
title: 'Environment Variable Naming Convention'
title: 'Environment Variable Naming Conventions'
description: 'Namespace Prowler App, API, SDK, and MCP Server environment variables with component prefixes like UI_ and API_ to avoid conflicts in a shared .env file.'
---
Prowler is a monorepo composed of several runtime components — Prowler App (the web user interface), Prowler API (the backend), Prowler SDK, and Prowler MCP Server (Model Context Protocol) — that frequently share a single `.env` file. To keep that shared configuration unambiguous, each component namespaces its environment variables with a component-specific prefix.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Google Cloud Provider'
title: 'Google Cloud (GCP) Provider Implementation'
description: 'Dive into the GCP provider in Prowler: Application Default Credentials, service accounts, OAuth, impersonation, and multi-project and organization discovery.'
---
This page details the [Google Cloud Platform (GCP)](https://cloud.google.com/) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'GitHub Provider'
title: 'GitHub Provider Implementation'
description: 'See how the GitHub provider in Prowler handles Personal Access Token, OAuth App, and GitHub App authentication to audit repositories and organizations.'
---
This page details the [GitHub](https://github.com/) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Integration Tests'
title: 'Integration Tests for Prowler'
description: 'Placeholder page tracking upcoming guidance on Prowler integration tests, covering how to validate multi-component flows across the SDK, API, and UI.'
---
Coming soon ...
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Creating a New Integration'
title: 'Creating New Prowler Integrations'
description: 'Build integrations that ship Prowler findings to Slack, Jira, AWS Security Hub, and other platforms by scripting API calls and configuring output pipelines.'
---
## Introduction
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Introduction to developing in Prowler'
title: 'Introduction to Developing in Prowler'
description: 'Get started as a Prowler contributor: pick a good first issue, extend checks, services, or integrations, and follow the AI-driven contribution workflow.'
---
Thanks for your interest in contributing to Prowler!
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Kubernetes Provider'
title: 'Kubernetes Provider Implementation'
description: 'Explore the Kubernetes provider in Prowler, including kubeconfig context loading, namespace discovery, in-cluster execution, and service class scaffolding.'
---
This page details the [Kubernetes](https://kubernetes.io/) provider implementation in Prowler.
@@ -1,5 +1,6 @@
---
title: 'Lighthouse AI Architecture'
title: 'Prowler Lighthouse AI Architecture'
description: 'Inside Prowler Lighthouse AI: a three-tier Next.js, API route, and Langchain agent design that connects LLMs to security data through MCP tool calls.'
---
This document describes the internal architecture of Prowler Lighthouse AI, enabling developers to understand how components interact and where to add new functionality.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'LLM Provider'
title: 'LLM Provider Implementation'
description: 'Learn how the Prowler LLM provider uses promptfoo to run red team security tests against OpenAI and other large language models with reusable test suites.'
---
This page details the [Large Language Model (LLM)](https://en.wikipedia.org/wiki/Large_language_model) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Microsoft 365 (M365) Provider'
title: 'Microsoft 365 (M365) Provider Implementation'
description: 'Understand the Microsoft 365 provider in Prowler, PowerShell 7.4+ requirements, Exchange Online and Teams modules, and Entra ID tenant scanning.'
---
This page details the [Microsoft 365 (M365)](https://www.microsoft.com/en-us/microsoft-365) provider implementation in Prowler.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Extending the MCP Server'
title: 'Extending the Prowler MCP Server'
description: 'Add new tools and sub-servers to the Prowler MCP Server so AI assistants like Claude Desktop and Cursor can query Prowler App, Hub, and documentation content.'
---
This guide explains how to extend the Prowler MCP Server with new tools and features.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Create a Custom Output Format'
title: 'Creating Custom Prowler Output Formats'
description: 'Add a new output format to Prowler by subclassing the Output class, defining the schema, and generating JSON, CSV, HTML, or SARIF-style reports from findings.'
---
## Introduction
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Prowler Providers'
title: 'Creating New Prowler Providers'
description: 'Design and implement new Prowler providers across cloud, SaaS, and container platforms, following the base Provider class patterns, models, and CLI wiring.'
---
## Introduction
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Prowler Studio'
title: 'Prowler Studio AI Check Workflow'
description: 'Prowler Studio is a Claude Code workflow that generates consistent, tested Prowler security checks by enforcing skills, guardrails, and provider conventions.'
---
**Prowler Studio is an AI workflow that ensures Claude Code follows Prowler's skills, guardrails, and best practices when creating new security checks.** What lands in the resulting pull request is consistent, tested, and ready for human review — not half-correct boilerplate that needs to be rewritten.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Renaming Checks in Prowler'
title: 'Renaming Existing Prowler Checks'
description: 'Safely rename a Prowler check by updating folder paths, class names, metadata JSON, CheckAliases, and compliance mappings without breaking existing users.'
---
To rename a check in Prowler, follow these steps when aligning with Check ID structure, fixing typos, or updating check logic that requires a new name.
@@ -1,5 +1,6 @@
---
title: 'Secret-Scanning Checks'
title: 'Building Secret-Scanning Checks'
description: 'Author efficient secret-scanning checks in Prowler using the Kingfisher engine and detect_secrets_scan_batch helper to scan payloads in chunked subprocesses.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -1,5 +1,6 @@
---
title: 'Creating a New Security Compliance Framework in Prowler'
title: 'Adding New Compliance Frameworks to Prowler'
description: 'Map catalogs like CIS, NIST 800-53, PCI DSS, or DORA into Prowler by defining JSON schemas, Pydantic models, check mappings, and validation tests.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Server-Sent Events (SSE)'
title: 'Adding Server-Sent Events (SSE) Endpoints'
description: 'Stream real-time updates from the Prowler API using Server-Sent Events with django-eventstream, including scan progress and streamed LLM token output.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Prowler Services'
title: 'Creating New Prowler Services'
description: 'Add new services like EC2 or Exchange Online to a Prowler provider by scaffolding the service class, data models, API client calls, and shared client instances.'
---
Here you can find how to create a new service, or to complement an existing one, for a [Prowler Provider](/developer-guide/provider).
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'StackIT Provider'
title: 'StackIT Cloud Provider Implementation'
description: 'Discover how the StackIT provider in Prowler authenticates using service account keys, manages token refresh via the SDK, and audits a single StackIT project.'
---
This page details the [StackIT Cloud](https://www.stackit.de/) provider implementation in Prowler.
@@ -1,5 +1,6 @@
---
title: 'Test Impact Analysis'
title: 'Test Impact Analysis in CI'
description: 'Prowler test impact analysis maps changed files to relevant SDK, API, and Playwright E2E tests through a GitHub Actions workflow and configurable path rules.'
---
Test impact analysis (TIA) determines which tests to run based on the files changed in a pull request. Instead of running the full test suite on every pull request, TIA maps changed files to the specific Prowler SDK, API, and end-to-end (E2E) tests that cover them. This approach reduces continuous integration (CI) time and resource usage while maintaining confidence that relevant code paths are tested.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Unit Tests for Prowler Checks'
title: 'Writing Unit Tests for Prowler Checks'
description: 'Write robust unit tests for Prowler checks with pytest and mock, covering zero-finding, PASS, FAIL, and multi-resource scenarios across every provider.'
---
Unit tests for Prowler checks vary based on the provider being evaluated.
@@ -1,5 +1,6 @@
---
title: 'Basic Usage'
title: 'Get started with the Prowler App web interface'
description: 'Sign up, add a cloud provider, launch a scan, and review findings in the Prowler App web UI for AWS, Azure, GCP, Kubernetes, and Microsoft 365.'
---
## Access Prowler App
@@ -1,5 +1,6 @@
---
title: 'Basic Usage'
title: 'Run scans with the Prowler CLI'
description: 'Learn the essential Prowler CLI commands to run multi-cloud security scans, list checks and services, and export CSV, JSON-OCSF, and HTML reports.'
---
## Running Prowler
@@ -1,5 +1,6 @@
---
title: "Tools Reference"
title: 'Prowler MCP Server tools reference'
description: 'Complete reference for Prowler MCP Server tools, grouped by namespace: Prowler Hub catalog, documentation search, and Prowler Cloud or App management.'
---
Complete reference guide for all tools available in the Prowler MCP Server. Tools are organized by namespace.
@@ -1,5 +1,6 @@
---
title: "Configuration"
title: 'Configure the Prowler MCP Server for AI clients'
description: 'Connect Claude Desktop, Cursor, and other MCP clients to Prowler MCP Server using HTTP or STDIO mode, and set up API key authentication for Prowler Cloud.'
---
Configure your MCP client to connect to Prowler MCP Server.
@@ -1,5 +1,6 @@
---
title: 'AWS Security Hub'
title: 'Prowler vs AWS Security Hub'
description: 'Compare Prowler with AWS Security Hub for cloud security posture management, multi-account scanning, compliance checks, and multi-cloud coverage beyond AWS.'
---
AWS Security Hub remains a managed service designed for centralizing security alerts and compliance status within AWS environments. It integrates with various AWS security services and provides a consolidated view of security findings.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'GCP Cloud Security Command Center (Cloud SCC)'
title: 'Prowler vs Google Cloud Security Command Center'
description: 'Compare Prowler with GCP Cloud Security Command Center for asset visibility, threat detection, compliance monitoring, and cloud-agnostic security scanning.'
---
Google Cloud Security Command Center (Cloud SCC) is a centralized security and risk management platform for Google Cloud Platform (GCP). It provides visibility into assets, vulnerabilities, and threats across GCP environments, helping organizations to manage and improve their security posture.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Comparison'
title: 'Prowler vs other cloud security platforms'
description: 'Compare Prowler with AWS Security Hub, Microsoft Sentinel, Microsoft Defender for Cloud, and Google Cloud Security Command Center for cloud security posture.'
---
Click to learn more about each cloud security provider and learn how Prowler is differentiated.
@@ -1,5 +1,6 @@
---
title: 'Microsoft Defender for Cloud'
title: 'Prowler vs Microsoft Defender for Cloud'
description: 'Use Prowler open-source scans alongside Microsoft Defender for Cloud to validate Azure posture, customize checks, and extend coverage to AWS, GCP, and K8s.'
---
**Use open-source scanning to validate and extend Microsoft Defender for Cloud**
@@ -1,5 +1,6 @@
---
title: 'Microsoft Sentinel'
title: 'Prowler vs Microsoft Sentinel'
description: 'Compare Prowler with Microsoft Sentinel SIEM and SOAR for threat detection, log ingestion, compliance scanning, and multi-cloud security posture management.'
---
Microsoft Sentinel is a scalable, cloud-native security information and event management (SIEM) and security orchestration automated response (SOAR) solution. It's designed to collect, detect, investigate, and respond to threats across the enterprise, primarily within the Azure cloud environment but also extending to on-premises and other cloud environments through various connectors.
@@ -1,4 +1,5 @@
---
title: "Prowler API Reference"
title: 'Prowler API reference'
description: 'Open the interactive Prowler Cloud API v1 reference to explore endpoints for scans, findings, providers, compliance, and integrations with auth details.'
url: "https://api.prowler.com/api/v1/docs"
---
+2 -1
View File
@@ -1,4 +1,5 @@
---
title: "Go to Cloud"
title: 'Open Prowler Cloud'
description: 'Jump to cloud.prowler.com to sign in or sign up for Prowler Cloud, the managed SaaS for cloud security scanning across AWS, Azure, GCP, Kubernetes, and M365.'
url: "https://cloud.prowler.com"
---
+2 -1
View File
@@ -1,4 +1,5 @@
---
title: "Go to Hub"
title: 'Open Prowler Hub'
description: 'Jump to hub.prowler.com to browse the searchable public library of Prowler checks, cloud service artifacts, and compliance framework mappings with versioning.'
url: "https://hub.prowler.com"
---
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: "Prowler MCP"
title: 'Prowler MCP Server on GitHub'
description: 'Jump to the Prowler MCP Server source code on GitHub to review the Model Context Protocol implementation, tools, and integration examples for AI assistants.'
url: "https://github.com/prowler-cloud/prowler/tree/master/mcp_server"
tag: "new!"
---
@@ -1,5 +1,6 @@
---
title: "Installation"
title: 'Install the Prowler App'
description: 'Install the self-hosted Prowler App with Docker Compose or from source to run the Prowler UI, API, and workers locally for multi-cloud security scans.'
---
### Installation
@@ -1,5 +1,6 @@
---
title: 'Installation'
title: 'Install the Prowler CLI'
description: 'Install the Prowler CLI on macOS, Linux, or Windows using pipx, pip, Docker, or the GitHub repository, then verify the version and run your first scan.'
---
## Installation
@@ -1,5 +1,6 @@
---
title: "Installation"
title: 'Install the Prowler MCP Server locally'
description: 'Run the Prowler MCP Server locally using Docker, PyPI, or source with uv, or use the hosted mcp.prowler.com endpoint managed by Prowler for AI assistants.'
---
There are **two ways** to use Prowler MCP Server:
@@ -1,5 +1,6 @@
---
title: 'Overview'
title: 'Prowler App overview'
description: 'Learn how the self-hosted Prowler App combines the Prowler UI, API, SDK, and MCP Server to configure scans, view findings, and manage cloud security posture.'
---
Prowler App is a web application that simplifies running Prowler. It provides:
@@ -1,5 +1,6 @@
---
title: 'Prowler for Claude Code'
title: 'Prowler for Claude Code plugin'
description: 'Install the Prowler plugin for Claude Code to run cloud security and compliance assessments and remediate findings against Prowler Cloud connected accounts.'
---
End-to-end cloud security and compliance from inside [Claude Code](https://www.claude.com/product/claude-code), powered by the [Prowler MCP server](/getting-started/products/prowler-mcp). The plugin lets Claude walk a Prowler Cloud-connected account through a compliance assessment and remediate findings until the chosen security or industry framework is compliant.
@@ -1,5 +1,6 @@
---
title: 'Overview'
title: 'Prowler CLI overview'
description: 'Discover the Prowler open-source CLI: run multi-cloud security scans, launch the dashboard, and audit against CIS, NIST, PCI DSS, ISO 27001, SOC 2, and more.'
---
Prowler CLI is a command-line interface for running Prowler scans from the terminal.
@@ -1,5 +1,6 @@
---
title: "AWS Marketplace"
title: 'Subscribe to Prowler Cloud via AWS Marketplace'
description: 'Subscribe to Prowler Cloud through the AWS Marketplace listing, set up your account, and manage billing for cloud security scanning directly from AWS Billing.'
---
This section contains the instructions to subscribe to **Prowler Cloud** through the **AWS Marketplace**.
@@ -1,5 +1,6 @@
---
title: 'Overview'
title: 'Lighthouse AI on Prowler Cloud'
description: 'Explore the enhanced Lighthouse AI on Prowler Cloud: persistent chat sessions, GPT-5.5 by default, an agentic chat view, and automatic provider validation.'
---
import { SubscriptionBanner } from "/snippets/subscription-banner.mdx"
@@ -1,4 +1,5 @@
---
title: "Pricing"
title: 'Prowler Cloud pricing'
description: 'Jump to prowler.com/pricing to compare Prowler Cloud plans, transparent per-resource pricing, free trial details, and enterprise support options for teams.'
url: "https://prowler.com/pricing"
---
@@ -1,5 +1,6 @@
---
title: "Overview"
title: 'Prowler Cloud overview'
description: 'Prowler Cloud is the managed SaaS on Prowler open source, with continuous monitoring, auto-scaling scan workers, Slack and Jira alerts, and SOC 2 controls.'
---
[Prowler Cloud](https://prowler.com) makes Cloud Security easy and enables your team to build trust in their deployed services and applications.
@@ -1,5 +1,6 @@
---
title: "Overview"
title: 'Prowler Hub overview'
description: 'Prowler Hub is a public library of versioned security checks, cloud service artifacts, and compliance framework mappings, with a documented API for automation.'
---
**Prowler Hub** is our growing public library of versioned checks, cloud service artifacts, and compliance frameworks with its mappings. It’s searchable, explainable, and built to serve the community.
@@ -1,5 +1,6 @@
---
title: 'Overview'
title: 'Prowler Lighthouse AI overview'
description: 'Prowler Lighthouse AI is an open-source cloud security analyst chatbot that helps teams query findings in natural language and get step-by-step remediation.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -1,5 +1,6 @@
---
title: "Overview"
title: 'Prowler MCP Server overview'
description: 'The Prowler MCP Server exposes Prowler Cloud, Prowler App, Prowler Hub, and docs to Claude Desktop, Cursor, and other AI assistants over Model Context Protocol.'
---
**Prowler MCP Server** brings the entire Prowler ecosystem to AI assistants through the Model Context Protocol (MCP). It enables seamless integration with AI tools like Claude Desktop, Cursor, and other MCP clients, allowing interaction with Prowler's security capabilities through natural language.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Data Regions & Availability'
title: 'Prowler Cloud data regions and availability'
description: 'Prowler Cloud AWS regions, EU Ireland hosting, high availability, disaster recovery, RPO, RTO, and status page for uptime and incidents.'
---
Prowler Cloud runs on AWS with high availability built in.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Encryption'
title: 'Prowler Cloud data encryption at rest and in transit'
description: 'How Prowler Cloud encrypts findings, backups, and API traffic with AES-256 at rest and TLS 1.2+ in transit across databases, storage, and services.'
---
Prowler Cloud uses encryption everywhere possible. All data and communications are encrypted at rest and in transit.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Security & Compliance'
title: 'Prowler security and compliance overview'
description: 'Prowler Cloud vs self-managed security posture: SOC 2 Type II, AWS FTR, encryption, backups, and the security tooling applied to every Prowler build.'
---
**Prowler secures itself with Prowler.** As an open-source cloud security platform trusted by thousands of organizations, Prowler applies the same rigorous security standards internally that customers achieve externally.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Networking'
title: 'Prowler Cloud networking and egress IP allowlist'
description: 'Prowler Cloud outbound egress IP addresses and DNS records to allowlist in firewalls and cloud security groups when scanning provider accounts.'
---
## Egress IP Addresses
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Software Security'
title: 'Prowler software security: SAST, SCA, and CI/CD'
description: 'Security controls applied to every Prowler build: SAST, SCA, container scanning, secrets detection, supply-chain pinning, and hardened GitHub Actions runners.'
---
Prowler applies security-by-design across the development lifecycle. Every change passes automated checks at each stage: pre-commit hooks locally, multiple CI gates on pull requests, branch protection before merge, container scanning before publish, and registry monitoring after release.
@@ -1,5 +1,6 @@
---
title: "Check Aliases"
title: "Define check aliases in Prowler CLI"
description: "Add CheckAliases to a check's metadata to run a Prowler check by an alternate name from the CLI without editing the underlying check ID."
---
Prowler allows you to use aliases for the checks. You only have to add the `CheckAliases` key to the check's metadata with a list of the aliases:
@@ -1,5 +1,6 @@
---
title: "Configuration File"
title: "Prowler CLI configuration file (config.yaml)"
description: "Customize Prowler CLI check thresholds and provider-specific tunables through config.yaml or a custom --config-file across AWS, Azure, GCP, and Kubernetes."
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -1,5 +1,6 @@
---
title: "Custom Checks Metadata"
title: "Override check metadata with custom severity and risk"
description: "Use --custom-checks-metadata-file in Prowler CLI to override default check severity, titles, risk, and remediation details with a custom YAML file."
---
In certain organizations, the severity of specific checks might differ from the default values defined in the check's metadata. For instance, while `s3_bucket_level_public_access_block` could be deemed `critical` for some organizations, others might assign a different severity level to it.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: "Dashboard"
title: "Run the Prowler local dashboard from CSV outputs"
description: "Launch the built-in Prowler dashboard to visualize CSV scan output locally or in Docker, exposing an interactive UI on port 11666 for review."
---
Prowler allows you to run your own local dashboards using the csv outputs provided by Prowler
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Prowler Fixers (Remediations)'
title: 'Prowler fixers: automated remediations for failed findings'
description: 'Use the Prowler CLI --fixer flag to remediate failed findings automatically and list available fixes per provider with --list-fixers or --list-remediations.'
---
Prowler allows you to fix some of the failed findings it identifies. You can use the `--fixer` flag to run the fixes that are available for the checks that failed.
@@ -1,5 +1,6 @@
---
title: 'Integrations'
title: 'Prowler CLI Slack integration for scan summaries'
description: 'Send Prowler CLI scan summaries to a Slack channel using --slack, a Slack App OAuth token, and the SLACK_API_TOKEN and SLACK_CHANNEL_NAME variables.'
---
## Integration with Slack
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Logging'
title: 'Prowler CLI logging levels and log file output'
description: 'Configure Prowler CLI log levels with --log-level and route DEBUG, INFO, WARNING, ERROR, or CRITICAL messages to a file with --log-file for troubleshooting.'
---
Prowler has a logging feature to be as transparent as possible, so that you can see every action that is being performed whilst the tool is being executing.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Miscellaneous'
title: 'Miscellaneous Prowler CLI flags and execution options'
description: 'Show Prowler version, enable verbose mode, tune execution behavior, and use miscellaneous Prowler CLI options that fine-tune everyday scan runs.'
---
## Prowler Version
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Mutelisting'
title: 'Mutelist Prowler findings for accepted risks'
description: 'Suppress intentional Prowler findings using a mutelist YAML with account, check, region, resource, and tag rules to keep expected exceptions out of reports.'
---
**Muting Findings for Intentional Configurations**
@@ -1,5 +1,6 @@
---
title: 'Parallel Execution'
title: 'Run Prowler in parallel across AWS services'
description: 'Speed up scans of large AWS accounts by executing Prowler in parallel per service on Linux and Windows while respecting API rate limits and retries.'
---
The strategy used here will be to execute Prowler once per service. You can modify this approach as per your requirements.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Pentesting'
title: 'Pentesting checks in Prowler: secrets and exposure'
description: 'Run Prowler pentesting checks for exposed secrets, internet-facing resources, weak authentication, and authorization gaps across AWS, Azure, and GCP.'
---
Prowler has some checks that analyse pentesting risks (Secrets, Internet Exposed, AuthN, AuthZ, and more).
@@ -1,5 +1,6 @@
---
title: 'Quick Inventory'
title: 'Prowler quick inventory for AWS resource counts'
description: 'Use prowler aws -i / --quick-inventory to list AWS resources per service and region, exporting a CSV and JSON summary of your cloud footprint.'
---
Prowler allows you to execute a quick inventory to extract the number of resources in your provider.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Reporting in Prowler'
title: 'Prowler CLI reporting: CSV, JSON-OCSF, ASFF, and HTML'
description: 'Generate Prowler scan reports in CSV, JSON-OCSF, JSON-ASFF (Security Hub), and HTML formats with -M/--output-formats and custom output directories.'
---
Prowler generates security assessment reports in multiple formats, ensuring compatibility with various analysis tools and AWS integrations.
@@ -1,5 +1,6 @@
---
title: 'Scanning Unused Services'
title: 'Scan unused AWS services with Prowler'
description: 'Enable --scan-unused-services in Prowler to audit AWS resources that are provisioned but idle, such as unused ACM certificates and dormant services.'
---
<Note>
@@ -1,6 +1,6 @@
---
title: 'Compliance'
description: 'Run security checks against compliance frameworks, review posture across providers, and download CSV or PDF reports from Prowler Cloud, Prowler App, and Prowler CLI.'
title: 'Prowler compliance frameworks and reports'
description: 'Run Prowler compliance scans against CIS, NIST, ISO 27001, PCI-DSS, SOC 2, and more, then download CSV or PDF reports from Prowler Cloud, App, or CLI.'
---
Prowler maps every security check to one or more industry-standard compliance frameworks, so a single scan produces both technical findings and framework-aligned evidence. The same evaluation runs identically whether scans are launched from Prowler Cloud, Prowler App, or Prowler CLI.
@@ -1,5 +1,6 @@
---
title: "Prowler ThreatScore Documentation"
title: "Prowler ThreatScore: unified compliance scoring"
description: "Prowler ThreatScore aggregates pass rate, severity, weight, and prevalence into a 0-100 compliance score for tracking cloud security posture over time."
---
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Run Prowler in CI/CD and Send Findings to Prowler Cloud'
title: 'Run Prowler in CI/CD and send findings to Prowler Cloud'
description: 'Integrate Prowler CLI into GitHub Actions and GitLab CI pipelines, then push scan findings to Prowler Cloud with --push-to-cloud and an API key.'
---
<Warning>
@@ -1,5 +1,6 @@
---
title: 'Run Kubernetes In-Cluster and Send Findings to Prowler Cloud'
title: 'Run Prowler in a Kubernetes CronJob and push findings'
description: 'Deploy Prowler as a scheduled Kubernetes CronJob with ServiceAccount and RBAC, then send in-cluster scan findings to Prowler Cloud automatically.'
---
This cookbook walks through deploying Prowler inside a Kubernetes cluster on a recurring schedule and automatically sending findings to Prowler Cloud via [Import Findings](/user-guide/tutorials/prowler-import-findings). By the end, security scan results from the cluster appear in Prowler Cloud without any manual file uploads.
@@ -1,6 +1,6 @@
---
title: "Visualize Multi-Cloud CIS Benchmarks With Power BI"
description: "Ingest Prowler compliance CSV exports into a ready-made Microsoft Power BI template that surfaces CIS Benchmark posture across AWS, Azure, Google Cloud, and Kubernetes."
description: "Load Prowler compliance CSV exports into a ready-made Power BI template that shows CIS Benchmark posture across AWS, Azure, GCP, and Kubernetes."
---
The Multi-Cloud CIS Benchmarks Power BI template turns Prowler compliance CSV exports into an interactive dashboard. The template ingests scan results from Prowler CLI or Prowler Cloud and renders cross-provider CIS Benchmark coverage, profile-level breakdowns, regional drill-downs, and time-series trends. Center for Internet Security (CIS) Benchmarks are industry-standard configuration baselines maintained by CIS.
@@ -1,5 +1,6 @@
---
title: 'Alibaba Cloud Authentication in Prowler'
description: 'Configure Alibaba Cloud authentication for Prowler using RAM roles, STS credentials, ECS RAM roles, OIDC, access keys, or the default credential chain.'
---
Prowler supports multiple Alibaba Cloud authentication flows. If more than one is configured at the same time, the provider resolves them in this order:
@@ -1,5 +1,6 @@
---
title: 'Getting Started With Alibaba Cloud on Prowler'
description: 'Onboard Alibaba Cloud to Prowler with prerequisites, RAM user or role setup, and step-by-step instructions to run scans from Prowler Cloud or the CLI.'
---
import { VersionBadge } from "/snippets/version-badge.mdx"
@@ -1,5 +1,6 @@
---
title: 'AWS Authentication in Prowler'
description: 'Configure AWS authentication in Prowler using static IAM credentials or assumed roles, with the required SecurityAudit and ViewOnlyAccess policies.'
---
Prowler requires AWS credentials to function properly. Authentication is available through the following methods:
@@ -1,5 +1,6 @@
---
title: "Boto3 Retrier Configuration in Prowler"
title: 'Boto3 Retry Configuration for AWS Scans'
description: 'Tune Prowler AWS scans with Boto3 standard retry mode: adjust max attempts, handle throttling errors, and validate retries with debug logs.'
---
Prowler's AWS Provider leverages Boto3's [Standard](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/retries.html) retry mode to automatically retry client calls to AWS services when encountering errors or exceptions.
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Installing Prowler in AWS CloudShell'
title: 'Install and Run Prowler in AWS CloudShell'
description: 'Install Prowler in AWS CloudShell on Amazon Linux 2023, run AWS security scans, and download output reports directly from the browser shell.'
---
## Following the migration of AWS CloudShell from Amazon Linux 2 to Amazon Linux 2023
@@ -1,5 +1,6 @@
---
title: 'Getting Started With AWS on Prowler'
description: 'Onboard an AWS account to Prowler Cloud: locate your account ID, add the AWS provider, and choose IAM credentials or assume role authentication.'
---
## Prowler Cloud
@@ -1,5 +1,6 @@
---
title: 'Scanning Multiple AWS Accounts with Prowler'
title: 'Scan Multiple AWS Accounts with Prowler'
description: 'Run Prowler across many AWS accounts sequentially or in parallel using IAM assume role, ideal for auditing several accounts from one entry point.'
---
Prowler enables security scanning across multiple AWS accounts by utilizing the [Assume Role feature](/user-guide/providers/aws/role-assumption) and [integration with AWS Organizations feature](/user-guide/providers/aws/organizations).
@@ -1,5 +1,6 @@
---
title: 'AWS Organizations in Prowler'
title: 'AWS Organizations Integration with Prowler'
description: 'Integrate Prowler with AWS Organizations to auto-discover member accounts, enrich findings with account metadata, and deploy scan roles via StackSets.'
---
<Info>
@@ -1,5 +1,6 @@
---
title: 'AWS Regions and Partitions'
title: 'AWS Regions and Partitions in Prowler'
description: 'Scan specific AWS regions and partitions with Prowler, including commercial, China, European Sovereign Cloud, and GovCloud (US) endpoints.'
---
By default Prowler is able to scan the following AWS partitions:
@@ -1,5 +1,6 @@
---
title: 'Resource ARN-based Scanning'
title: 'AWS Resource ARN-Based Scanning'
description: 'Scan specific AWS resources by ARN with the Prowler --resource-arn flag to target individual IAM users, EC2 VPCs, or other services on demand.'
---
Prowler enables scanning of resources based on specific AWS Resource ARNs.
@@ -1,5 +1,6 @@
---
title: 'AWS Assume Role in Prowler (CLI)'
title: 'AWS Assume Role for the Prowler CLI'
description: 'Run Prowler CLI with AWS IAM assume role using custom Boto3 profiles, role chaining, MFA, external IDs, and cross-account role ARNs.'
---
## Authentication Overview
+2 -1
View File
@@ -1,5 +1,6 @@
---
title: 'Sending Reports to an AWS S3 Bucket'
title: 'Send Prowler Reports to an AWS S3 Bucket'
description: 'Upload Prowler AWS scan reports directly to Amazon S3 using --output-bucket, and customize the folder, filename, and output format per scan.'
---
To save reports directly in an S3 bucket, use: `-B`/`--output-bucket`.
@@ -1,5 +1,6 @@
---
title: 'AWS Security Hub Integration with Prowler'
description: 'Send Prowler findings to AWS Security Hub by enabling the integration per region, then push results into ASFF for centralized security posture.'
---
Prowler natively supports **official integration** with [AWS Security Hub](https://aws.amazon.com/security-hub), allowing security findings to be sent directly. This integration enables **Prowler** to import its findings into AWS Security Hub.
@@ -1,5 +1,6 @@
---
title: 'Tag-based scan'
title: 'AWS Tag-Based Scanning with Prowler'
description: 'Filter Prowler AWS scans to resources with specific tags using --resource-tags Key=Value, useful for auditing by environment, team, or project.'
---
Prowler provides the capability to scan only resources containing specific tags. To execute this, use the designated flag `--resource-tags` followed by the tags `Key=Value`, separated by spaces.
@@ -1,5 +1,6 @@
---
title: 'Threat Detection in AWS with Prowler'
title: 'AWS Threat Detection Checks in Prowler'
description: 'Detect AWS threats with Prowler CloudTrail-based checks for privilege escalation, enumeration attacks, and LLM jacking using the threat-detection category.'
---
Prowler enables threat detection in AWS by analyzing CloudTrail log records. To execute threat detection checks, use the following command:
@@ -1,5 +1,6 @@
---
title: 'Check Mapping Prowler v4/v3 to v2'
title: 'Prowler v4/v3 to v2 AWS Check ID Mapping'
description: 'Map Prowler v4 and v3 AWS check IDs back to legacy v2 check numbers to migrate suppressions, dashboards, or compliance reports between versions.'
---
Prowler v3 and v4 introduce distinct identifiers while preserving the checks originally implemented in v2. This change was made because, in previous versions, check names were primarily derived from the CIS Benchmark for AWS. Starting with v3 and v4, all checks are independent of any security framework and have unique names and IDs.
@@ -1,5 +1,6 @@
---
title: 'Azure Authentication in Prowler'
description: 'Authenticate Prowler for Azure with a service principal, az CLI, browser login, or managed identity, and grant the required Entra and RBAC permissions.'
---
Prowler for Azure supports multiple authentication types. Authentication methods vary between Prowler App and Prowler CLI:
@@ -1,5 +1,6 @@
---
title: 'Creating a Prowler Service Principal Application'
title: 'Create a Prowler Service Principal in Azure'
description: 'Create an Azure service principal for Prowler via the Azure Portal or az CLI, register the app, add a client secret, and capture tenant and client IDs.'
---
To enable Prowler to assume an identity for scanning with the required privileges, a Service Principal must be created. This Service Principal authenticates against Azure and retrieves necessary metadata for checks.

Some files were not shown because too many files have changed in this diff Show More