docs(tutorials): improve quality redrive (#7915)

Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com>
This commit is contained in:
Rubén De la Torre Vico
2025-07-29 11:03:52 +02:00
committed by GitHub
parent 1bdcf2c7f1
commit 9ca1899ebf
45 changed files with 1305 additions and 872 deletions
+81 -34
View File
@@ -1,50 +1,81 @@
# Miscellaneous
## Prowler Version
Show Prowler version:
### Showing the Prowler version:
```console
prowler <provider> -V/-v/--version
```
## Verbose
Execute Prowler in verbose mode (like in Version 2):
## Prowler Execution Options
Prowler provides various execution settings.
### Verbose Execution
To enable verbose mode in Prowler, similar to Version 2, use:
```console
prowler <provider> --verbose
```
## Filter findings by status
Prowler can filter the findings by their status, so you can see only in the CLI and in the reports the findings with a specific status:
### Filter findings by status
Prowler allows filtering findings based on their status, ensuring reports and CLI display only relevant findings:
```console
prowler <provider> --status [PASS, FAIL, MANUAL]
```
## Disable Exit Code 3
Prowler does not trigger exit code 3 with failed checks:
### Disable Exit Code 3
By default, Prowler triggers exit code 3 for failed checks. To disable this behavior:
```console
prowler <provider> -z/--ignore-exit-code-3
```
## Hide Prowler Banner
Prowler can run without showing its banner:
### Hide Prowler Banner
To run Prowler without displaying the banner:
```console
prowler <provider> -b/--no-banner
```
## Disable Colors
Prowler can run without showing colors:
### Disable Colors in Output
To run Prowler without color formatting:
```console
prowler <provider> --no-color
```
## Checks
Prowler has checks per provider, there are options related with them:
- List the available checks in the provider:
### Checks in Prowler
Prowler provides various security checks per cloud provider. Use the following options to list, execute, or exclude specific checks:
- **List Available Checks**: To display all available checks for the chosen provider:
```console
prowler <provider> --list-checks
```
- Execute specific check(s):
- **Execute Specific Checks**: Run one or more specific security checks using:
```console
prowler <provider> -c/--checks s3_bucket_public_access iam_root_mfa_enabled
prowler <provider> -c/--checks s3_bucket_public_access
```
- Exclude specific check(s):
- **Exclude Specific Checks**: Exclude checks from execution with:
```console
prowler <provider> -e/--excluded-checks s3_bucket_public_access iam_root_mfa_enabled
prowler <provider> -e/--excluded-checks ec2 rds
```
- Execute checks that appears in a json file:
- **Execute Checks from a JSON File**: To run checks defined in a JSON file, structure the file as follows:
```json
<checks_list>.json
@@ -58,37 +89,42 @@ prowler <provider> -e/--excluded-checks s3_bucket_public_access iam_root_mfa_ena
...
}
```
```console
prowler <provider> -C/--checks-file <checks_list>.json
```
## Custom Checks
Prowler allows you to include your custom checks with the flag:
## Custom Checks in Prowler
Prowler supports custom security checks, allowing users to define their own logic.
```console
prowler <provider> -x/--checks-folder <custom_checks_folder>
```
???+ note
S3 URIs are also supported as folders for custom checks, e.g. `s3://bucket/prefix/checks_folder/`. Make sure that the used credentials have `s3:GetObject` permissions in the S3 path where the custom checks are located.
S3 URIs are also supported for custom check folders (e.g., `s3://bucket/prefix/checks_folder/`). Ensure the credentials used have `s3:GetObject` permissions in the specified S3 path.
The custom checks folder must contain one subfolder per check, each subfolder must be named as the check and must contain:
**Folder Structure for Custom Checks**
- An empty `__init__.py`: to make Python treat this check folder as a package.
- A `check_name.py` containing the check's logic.
- A `check_name.metadata.json` containing the check's metadata.
Each check must reside in a dedicated subfolder, following this structure:
- `__init__.py` (empty file) Ensures Python treats the check folder as a package.
- `check_name.py` (name file) Defines the checks logic for contextual information.
- `check_name.metadata.json` (metadata file) Defines the checks metadata for contextual information.
???+ note
The check name must start with the service name followed by an underscore (e.g., ec2_instance_public_ip).
The check name must start with the service name followed by an underscore (e.g., ec2\_instance\_public\_ip).
To see more information about how to write checks see the [Developer Guide](../developer-guide/checks.md#create-a-new-check-for-a-provider).
To see more information about how to write checks, refer to the [Developer Guide](../developer-guide/checks.md#create-a-new-check-for-a-provider).
???+ note
If you want to run ONLY your custom check(s), import it with -x (--checks-folder) and then run it with -c (--checks), e.g.:
```console
prowler aws -x s3://bucket/prowler/providers/aws/services/s3/s3_bucket_policy/ -c s3_bucket_policy
```
If you want to run ONLY your custom check(s), import it with -x (--checks-folder) and then run it with -c (--checks), e.g.: `console prowler aws -x s3://bucket/prowler/providers/aws/services/s3/s3_bucket_policy/ -c s3_bucket_policy`
## Severities
Each of Prowler's checks has a severity, which can be:
Each of Prowler's checks has a severity, which can be one of the following:
- informational
- low
- medium
@@ -96,34 +132,45 @@ Each of Prowler's checks has a severity, which can be:
- critical
To execute specific severity(s):
```console
prowler <provider> --severity critical high
```
## Service
Prowler has services per provider, there are options related with them:
- List the available services in the provider:
```console
prowler <provider> --list-services
```
- Execute specific service(s):
```console
prowler <provider> -s/--services s3 iam
```
- Exclude specific service(s):
```console
prowler <provider> --excluded-services ec2 rds
```
## Categories
Prowler groups checks in different categories, there are options related with them:
Prowler groups checks in different categories. There are options related with said categories:
- List the available categories in the provider:
```console
prowler <provider> --list-categories
```
- Execute specific category(s):
```console
prowler <provider> --categories secrets
```