diff --git a/docs/developer-guide/alibabacloud-details.mdx b/docs/developer-guide/alibabacloud-details.mdx index 3877b8349a..0d22b604d5 100644 --- a/docs/developer-guide/alibabacloud-details.mdx +++ b/docs/developer-guide/alibabacloud-details.mdx @@ -68,7 +68,7 @@ The generic service pattern is described in [service page](/developer-guide/serv - Directly in the code, in location [`prowler/providers/alibabacloud/services/`](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers/alibabacloud/services) - In the [Prowler Hub](https://hub.prowler.com/) for a more human-readable view. -The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In next subsection you can find a list of common patterns that are used across all Alibaba Cloud services. +The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In the next subsection you can find a list of common patterns that are used across all Alibaba Cloud services. ### Alibaba Cloud Service Common Patterns diff --git a/docs/developer-guide/aws-details.mdx b/docs/developer-guide/aws-details.mdx index a653148a4c..113f6f1df5 100644 --- a/docs/developer-guide/aws-details.mdx +++ b/docs/developer-guide/aws-details.mdx @@ -8,7 +8,7 @@ By default, Prowler will audit just one account and organization settings per sc ## AWS Provider Classes Architecture -The AWS provider implementation follows the general [Provider structure](/developer-guide/provider). This section focuses on the AWS-specific implementation, highlighting how the generic provider concepts are realized for AWS in Prowler. For a full overview of the provider pattern, base classes, and extension guidelines, see [Provider documentation](/developer-guide/provider). In next subsection you can find a list of the main classes of the AWS provider. +The AWS provider implementation follows the general [Provider structure](/developer-guide/provider). This section focuses on the AWS-specific implementation, highlighting how the generic provider concepts are realized for AWS in Prowler. For a full overview of the provider pattern, base classes, and extension guidelines, see [Provider documentation](/developer-guide/provider). In the next subsection you can find a list of the main classes of the AWS provider. ### `AwsProvider` (Main Class) @@ -59,7 +59,7 @@ The generic service pattern is described in [service page](/developer-guide/serv - Directly in the code, in location [`prowler/providers/aws/services/`](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers/aws/services) - In the [Prowler Hub](https://hub.prowler.com/) for a more human-readable view. -The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In next subsection you can find a list of common patterns that are used across all AWS services. +The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In the next subsection you can find a list of common patterns that are used across all AWS services. ### AWS Service Common Patterns @@ -67,8 +67,8 @@ The best reference to understand how to implement a new service is following the - Every AWS service class inherits from `AWSService`, ensuring access to session, identity, configuration, and threading utilities. - The constructor (`__init__`) always calls `super().__init__` with the service name and provider (e.g. `super().__init__(__class__.__name__, provider))`). Ensure that the service name in boto3 is the same that you use in the constructor. Usually is used the `__class__.__name__` to get the service name because it is the same as the class name. - Resource containers **must** be initialized in the constructor. They should be dictionaries, with the key being the resource ARN or equivalent unique identifier and the value being the resource object. -- Resource discovery and attribute collection are parallelized using `self.__threading_call__`, typically by region or resource, for performance. The first parameter of the method is the iterator, if not provided, it will be the region; but if present indicate an array of the resources to be processed. -- Resource filtering is consistently enforced using `self.audit_resources` attribute and `is_resource_filtered` function, it is used to see if user has provided some resource that is not in the audit scope, so we can skip it in the service logic. Normally it is used before storing the resource in the service container as follows: `if not self.audit_resources or (is_resource_filtered(resource["arn"], self.audit_resources)):`. +- Resource discovery and attribute collection are parallelized using `self.__threading_call__`, typically by region or resource, for performance. The first parameter of the method is the iterator, if not provided, it will be the region; but if present it indicates an array of the resources to be processed. +- Resource filtering is consistently enforced using `self.audit_resources` attribute and `is_resource_filtered` function, it is used to see if the user has provided some resource that is not in the audit scope, so we can skip it in the service logic. Normally it is used before storing the resource in the service container as follows: `if not self.audit_resources or (is_resource_filtered(resource["arn"], self.audit_resources)):`. - All AWS resources are represented as Pydantic `BaseModel` classes, providing type safety and structured access to resource attributes. - AWS API calls are wrapped in try/except blocks, with specific handling for `ClientError` and generic exceptions, always logging errors. - If ARN is not present for some resource, it can be constructed using string interpolation, always including partition, service, region, account, and resource ID. @@ -162,7 +162,7 @@ When you instantiate `Check_Report_AWS`, you must provide the check metadata and If the resource object does not contain the required attributes, you must set them manually in the check logic. -Other attributes are inherited from the `Check_Report` class, from those you **always** have to set the `status` and `status_extended` attributes in the check logic. +Other attributes are inherited from the `Check_Report` class, from which you **always** have to set the `status` and `status_extended` attributes in the check logic. #### Example Usage diff --git a/docs/developer-guide/azure-details.mdx b/docs/developer-guide/azure-details.mdx index 9247b3b45d..6f49706646 100644 --- a/docs/developer-guide/azure-details.mdx +++ b/docs/developer-guide/azure-details.mdx @@ -8,7 +8,7 @@ By default, Prowler will audit all the subscriptions that it is able to list in ## Azure Provider Classes Architecture -The Azure provider implementation follows the general [Provider structure](/developer-guide/provider). This section focuses on the Azure-specific implementation, highlighting how the generic provider concepts are realized for Azure in Prowler. For a full overview of the provider pattern, base classes, and extension guidelines, see [Provider documentation](/developer-guide/provider). In next subsection you can find a list of the main classes of the Azure provider. +The Azure provider implementation follows the general [Provider structure](/developer-guide/provider). This section focuses on the Azure-specific implementation, highlighting how the generic provider concepts are realized for Azure in Prowler. For a full overview of the provider pattern, base classes, and extension guidelines, see [Provider documentation](/developer-guide/provider). In the next subsection you can find a list of the main classes of the Azure provider. ### `AzureProvider` (Main Class) @@ -57,13 +57,13 @@ The generic service pattern is described in [service page](/developer-guide/serv - Directly in the code, in location [`prowler/providers/azure/services/`](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers/azure/services) - In the [Prowler Hub](https://hub.prowler.com/) for a more human-readable view. -The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In next subsection you can find a list of common patterns that are used across all Azure services. +The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In the next subsection you can find a list of common patterns that are used across all Azure services. ### Azure Service Common Patterns - Services communicate with Azure using the Azure Python SDK, mainly using the Azure Management Client (except for the Microsoft Entra ID service, that is using the Microsoft Graph API), you can find the documentation with all the management services [here](https://learn.microsoft.com/en-us/python/api/overview/azure/?view=azure-python). - Every Azure service class inherits from `AzureService`, ensuring access to session, identity, configuration, and client utilities. -- The constructor (`__init__`) always calls `super().__init__` with the service Azure Management Client and Prowler provider object (e.g `super().__init__(WebSiteManagementClient, provider)`). +- The constructor (`__init__`) always calls `super().__init__` with the service Azure Management Client and Prowler provider object (e.g. `super().__init__(WebSiteManagementClient, provider)`). - Resource containers **must** be initialized in the constructor, and they should be dictionaries, with the key being the subscription ID, the value being a dictionary with the resource ID as key and the resource object as value. - All Azure resources are represented as Pydantic `BaseModel` classes, providing type safety and structured access to resource attributes. Some are represented as dataclasses due to legacy reasons, but new resources should be represented as Pydantic `BaseModel` classes. - Azure SDK functions are wrapped in try/except blocks, with specific handling for errors, always logging errors. It is a best practice to create a custom function for every Azure SDK call, in that way we can handle the errors in a more specific way. diff --git a/docs/developer-guide/checks.mdx b/docs/developer-guide/checks.mdx index 6f500ae9ec..1fae8cdf79 100644 --- a/docs/developer-guide/checks.mdx +++ b/docs/developer-guide/checks.mdx @@ -103,7 +103,7 @@ class (Check): # Set required fields and implement check logic report.status = "PASS" report.status_extended = f"" - # If some of the information needed for the report is not inside the resource, it can be set it manually here. + # If some of the information needed for the report is not inside the resource, it can be set manually here. # This depends on the provider and the resource that is being audited. # report.region = resource.region # report.resource_tags = getattr(resource, "tags", []) @@ -437,7 +437,7 @@ For the complete list of available categories, see [Categories Guidelines](/deve #### DependsOn -List of check IDs of checks that if are compliant, this check will be a compliant too or it is not going to give any finding. +List of check IDs of checks that if they are compliant, this check will be compliant too or it is not going to give any finding. #### RelatedTo diff --git a/docs/developer-guide/gcp-details.mdx b/docs/developer-guide/gcp-details.mdx index dd48daca20..275040b1b5 100644 --- a/docs/developer-guide/gcp-details.mdx +++ b/docs/developer-guide/gcp-details.mdx @@ -102,7 +102,7 @@ The generic service pattern is described in [service page](/developer-guide/serv - Directly in the code, in location [`prowler/providers/gcp/services/`](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers/gcp/services) - In the [Prowler Hub](https://hub.prowler.com/) for a more human-readable view. -The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In next subsection you can find a list of common patterns that are used across all GCP services. +The best reference to understand how to implement a new service is following the [service implementation documentation](/developer-guide/services#adding-a-new-service) and taking other services already implemented as reference. In the next subsection you can find a list of common patterns that are used across all GCP services. ### GCP Service Common Patterns @@ -161,7 +161,7 @@ When you instantiate `Check_Report_GCP`, you must provide the check metadata and - Defaults to "global" if none are available. All these attributes can be overridden by passing the corresponding argument to the constructor. If the resource object does not contain the required attributes, you must set them manually. -Other attributes are inherited from the `Check_Report` class, from those you **always** have to set the `status` and `status_extended` attributes in the check logic. +Other attributes are inherited from the `Check_Report` class, from which you **always** have to set the `status` and `status_extended` attributes in the check logic. #### Example Usage diff --git a/docs/developer-guide/provider.mdx b/docs/developer-guide/provider.mdx index 3d96e41ab5..9829a62154 100644 --- a/docs/developer-guide/provider.mdx +++ b/docs/developer-guide/provider.mdx @@ -17,7 +17,7 @@ A provider is any platform or service that offers resources, data, or functional For providers supported by Prowler, refer to [Prowler Hub](https://hub.prowler.com/). - There are some custom providers added by the community, like [NHN Cloud](https://www.nhncloud.com/), that are not maintained by the Prowler team, but can be used in the Prowler CLI. The main purpose of this documentation is to guide you through creating a new provider and integrating it not only in the CLI, but also in the API and UI. Non official providers can be checked directly at the [Prowler GitHub repository](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers). + There are some custom providers added by the community, like [NHN Cloud](https://www.nhncloud.com/), that are not maintained by the Prowler team, but can be used in the Prowler CLI. The main purpose of this documentation is to guide you through creating a new provider and integrating it not only in the CLI, but also in the API and UI. Non-official providers can be checked directly at the [Prowler GitHub repository](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers). --- @@ -105,8 +105,8 @@ Once you have decided the provider you want or need to add to Prowler, the next #### Implementation Complexity - **SDK Providers**: Low complexity. You have mature examples like AWS, Azure, GCP, Kubernetes, etc. that you can leverage to implement your provider. -- **API Providers**: Medium complexity. You need to implement the authentication and session management, and the API calls to the provider. You now have NHN and MongoDB Atlas as example to follow. -- **Tool/Wrapper Providers**: High complexity. You need to implement the argument/output mapping to the provider and handle problems that the tool/wrapper may have. You now have IAC and the PowerShell wrapper as example to follow. +- **API Providers**: Medium complexity. You need to implement the authentication and session management, and the API calls to the provider. You now have NHN and MongoDB Atlas as examples to follow. +- **Tool/Wrapper Providers**: High complexity. You need to implement the argument/output mapping to the provider and handle problems that the tool/wrapper may have. You now have IAC and the PowerShell wrapper as examples to follow. - **Hybrid Providers**: High complexity. You need to "customize" your provider, mixing the other types of providers to achieve the desired result. You have M365 (msgraph SDK + PowerShell wrapper) and GitHub (PyGithub SDK + graphql API requests) as examples. ### Determining Regional vs Non-Regional Architecture @@ -1756,7 +1756,7 @@ Argument validation ensures that the API provider receives valid configuration p **File:** `prowler/providers//lib/arguments/arguments.py` -Arguments depends on the provider and not the type, so the pattern for this step is the same as the [SDK providers](#step-4-implement-arguments). +Arguments depend on the provider and not the type, so the pattern for this step is the same as the [SDK providers](#step-4-implement-arguments). #### Step 5: Implement Mutelist @@ -2397,7 +2397,7 @@ class ToolProvider(Provider): # Build the tool command tool_command = [ "your_tool_command", - # Add your tool-specific arguments here, this are just examples + # Add your tool-specific arguments here, these are just examples "-d", directory, "-o", diff --git a/docs/developer-guide/services.mdx b/docs/developer-guide/services.mdx index beda2dcd56..4cacfcbc74 100644 --- a/docs/developer-guide/services.mdx +++ b/docs/developer-guide/services.mdx @@ -5,7 +5,7 @@ title: 'Prowler Services' Here you can find how to create a new service, or to complement an existing one, for a [Prowler Provider](/developer-guide/provider). -First ensure that the provider you want to add the service is already created. It can be checked [here](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers). If the provider is not present, please refer to the [Provider](./provider.md) documentation to create it from scratch. +First ensure that the provider you want to add the service to is already created. It can be checked [here](https://github.com/prowler-cloud/prowler/tree/master/prowler/providers). If the provider is not present, please refer to the [Provider](/developer-guide/provider) documentation to create it from scratch. ## Introduction @@ -102,7 +102,7 @@ class (ServiceParentClass): # A try-except block must be created in each function. try: - # If pagination is supported by the provider, is always better to use it, call to the provider API to retrieve the desired data. + # If pagination is supported by the provider, it is always better to use it, call to the provider API to retrieve the desired data. describe__paginator = regional_client.get_paginator("describe_") # Paginator to get every item. @@ -133,7 +133,7 @@ class (ServiceParentClass): # When handling exceptions, use the following approach to log errors appropriately based on the cloud provider being used: except Exception as error: - # Depending on each provider we can must use different fields in the logger, e.g.: AWS: regional_client.region or self.region, GCP: project_id and location, Azure: subscription + # Depending on each provider we must use different fields in the logger, e.g.: AWS: regional_client.region or self.region, GCP: project_id and location, Azure: subscription logger.error( f"{} -- {error.__class__.__name__}[{error.__traceback__.tb_lineno}]: {error}" ) diff --git a/docs/developer-guide/unit-testing.mdx b/docs/developer-guide/unit-testing.mdx index 0a07257b0b..52b63a2d8a 100644 --- a/docs/developer-guide/unit-testing.mdx +++ b/docs/developer-guide/unit-testing.mdx @@ -284,7 +284,7 @@ class Test_iam_password_policy_uppercase: assert len(results) == 1 assert result[0].status == "FAIL" - assert result[0].status_extended == "IAM password policy does not srequire at least one uppercase letter." + assert result[0].status_extended == "IAM password policy does not require at least one uppercase letter." assert result[0].resource_arn == f"arn:aws:iam::{AWS_ACCOUNT_NUMBER}:root" assert result[0].resource_id == AWS_ACCOUNT_NUMBER assert result[0].resource_tags == [] @@ -882,7 +882,7 @@ from unittest import mock from uuid import uuid4 -# Import some constans values needed in almost every check +# Import some constant values needed in almost every check from tests.providers.azure.azure_fixtures import ( AZURE_SUBSCRIPTION_ID, @@ -1024,7 +1024,7 @@ from prowler.providers.azure.services.appinsights.appinsights_service import ( Component, ) -# Import some constans values needed in almost every check +# Import some constant values needed in almost every check from tests.providers.azure.azure_fixtures import ( AZURE_SUBSCRIPTION_ID, diff --git a/docs/getting-started/products/prowler-cloud-aws-marketplace.mdx b/docs/getting-started/products/prowler-cloud-aws-marketplace.mdx index 63d66ff249..51eef03b22 100644 --- a/docs/getting-started/products/prowler-cloud-aws-marketplace.mdx +++ b/docs/getting-started/products/prowler-cloud-aws-marketplace.mdx @@ -6,7 +6,7 @@ This section contains the instructions to subscribe to **Prowler Cloud** through ## How to Subscribe -To get to the **Prowler Cloud** product listing in the AWS Marketplace, and click the `View purchase options` button: +Go to the **Prowler Cloud** product listing in the AWS Marketplace, and click the `View purchase options` button: 1. Use this link to be taken directly to the [Prowler Cloud Marketplace Listing](https://aws.amazon.com/marketplace/pp/prodview-6ochhig5kxpok): @@ -24,7 +24,7 @@ After you have subscribed to the **Prowler Cloud** product, you will need to set ![](/images/aws-marketplace/marketplace-message.png) -2. You will be redirected to **Prowler Cloud Sign In** page. You can sign in with an existing account or sign up with a new account: +2. You will be redirected to the **Prowler Cloud Sign In** page. You can sign in with an existing account or sign up with a new account: ![](/images/aws-marketplace/marketplace-sign-up.png) diff --git a/docs/getting-started/products/prowler-cloud-lighthouse.mdx b/docs/getting-started/products/prowler-cloud-lighthouse.mdx index 8c09d80a62..5ec8bb8985 100644 --- a/docs/getting-started/products/prowler-cloud-lighthouse.mdx +++ b/docs/getting-started/products/prowler-cloud-lighthouse.mdx @@ -5,7 +5,7 @@ title: 'Overview' import { SubscriptionBanner } from "/snippets/subscription-banner.mdx" import { VersionBadge } from "/snippets/version-badge.mdx" -Prowler Cloud runs an enhanced version of Lighthouse AI in Open Source repository, the Agentic Cloud Defender that helps teams understand, prioritize, and remediate security findings across cloud environments. +Prowler Cloud runs an enhanced version of Lighthouse AI in the Open Source repository, the Agentic Cloud Defender that helps teams understand, prioritize, and remediate security findings across cloud environments. diff --git a/docs/getting-started/products/prowler-cloud.mdx b/docs/getting-started/products/prowler-cloud.mdx index 337117d517..8e6996b7f8 100644 --- a/docs/getting-started/products/prowler-cloud.mdx +++ b/docs/getting-started/products/prowler-cloud.mdx @@ -10,7 +10,7 @@ Prowler Cloud automates scanning single or multiple accounts and has all of the -With 100% consistency across our open source policies and APIs. Prowler Cloud provides the following added benefits: +With 100% consistency across our open source policies and APIs, Prowler Cloud provides the following added benefits:
  • Immediate sign-up and account provisioning, including a trial period with zero billing details needed at registration.
  • @@ -20,5 +20,5 @@ With 100% consistency across our open source policies and APIs. Prowler Cloud pr
  • Zero touch third party notifications to Slack, Jira, and more.
-The team who built [Prowler](https://github.com/prowler-cloud/prowler), has helped thousands of companies get Cloud Security under control, is now making it easier by taking +The team who built [Prowler](https://github.com/prowler-cloud/prowler), which has helped thousands of companies get Cloud Security under control, is now making it easier by taking [Prowler](https://github.com/prowler-cloud/prowler) to the [Cloud](https://prowler.com)! diff --git a/docs/getting-started/products/prowler-hub.mdx b/docs/getting-started/products/prowler-hub.mdx index b84d48b7d5..37f4841d0c 100644 --- a/docs/getting-started/products/prowler-hub.mdx +++ b/docs/getting-started/products/prowler-hub.mdx @@ -2,7 +2,7 @@ title: "Overview" --- -**Prowler Hub** is our growing public library of versioned checks, cloud service artifacts, and compliance frameworks with its mappings. It’s searchable, explainable, and built to serve the community. +**Prowler Hub** is our growing public library of versioned checks, cloud service artifacts, and compliance frameworks with their mappings. It’s searchable, explainable, and built to serve the community. **Why this matters**: Every engineer has asked, “What does this check actually do?” Prowler Hub answers that question in one place, lets you pin to a specific version, and pulls definitions into your own tools or dashboards. diff --git a/docs/getting-started/products/prowler-lighthouse-ai.mdx b/docs/getting-started/products/prowler-lighthouse-ai.mdx index a095f39b48..61d99a0818 100644 --- a/docs/getting-started/products/prowler-lighthouse-ai.mdx +++ b/docs/getting-started/products/prowler-lighthouse-ai.mdx @@ -62,7 +62,7 @@ Prowler Lighthouse AI is powerful, but there are limitations: - **Continuous improvement**: Please report any issues, as the feature may make mistakes or encounter errors, despite extensive testing. - **Access limitations**: Lighthouse AI can only access data the logged-in user can view. If you can't see certain information, Lighthouse AI can't see it either. - **NextJS session dependence**: If your Prowler application session expires or logs out, Lighthouse AI will error out. Refresh and log back in to continue. -- **Response quality**: The response quality depends on the selected LLM provider and model. Choose models with strong tool-calling capabilities for best results. We recommend `gpt-5` model from OpenAI. +- **Response quality**: The response quality depends on the selected LLM provider and model. Choose models with strong tool-calling capabilities for best results. We recommend the `gpt-5` model from OpenAI. ## Architecture @@ -82,7 +82,7 @@ If you encounter issues with Prowler Lighthouse AI or have suggestions for impro ### What Data Is Shared to LLM Providers? -The following API endpoints are accessible to Prowler Lighthouse AI. Data from the following API endpoints could be shared with LLM provider depending on the scope of user's query: +The following API endpoints are accessible to Prowler Lighthouse AI. Data from the following API endpoints could be shared with the LLM provider depending on the scope of the user's query: ## FAQs @@ -110,7 +110,7 @@ Lighthouse AI [automatically filters](https://github.com/prowler-cloud/prowler/b **3. Is my security data shared with LLM providers?** -Minimal data is shared to generate useful responses. Agent can access security findings and remediation details when needed. Provider secrets are protected by design and cannot be read. The LLM provider credentials configured with Lighthouse AI are only accessible to the Next.js server and are never sent to the LLM providers. Resource metadata (names, tags, account/project IDs, etc.) may be shared with the configured LLM provider based on query requirements. +Minimal data is shared to generate useful responses. The agent can access security findings and remediation details when needed. Provider secrets are protected by design and cannot be read. The LLM provider credentials configured with Lighthouse AI are only accessible to the Next.js server and are never sent to the LLM providers. Resource metadata (names, tags, account/project IDs, etc.) may be shared with the configured LLM provider based on query requirements. **4. Can the Lighthouse AI change my cloud environment?** diff --git a/docs/troubleshooting.mdx b/docs/troubleshooting.mdx index 8b23550c4b..c17b69206c 100644 --- a/docs/troubleshooting.mdx +++ b/docs/troubleshooting.mdx @@ -14,7 +14,7 @@ In macOS Ventura, the default value for the `file descriptors` is `256`. With th If you have a different OS and you are experiencing the same, please increase the value of your `file descriptors`. You can check it running `ulimit -a | grep "file descriptors"`. -This error is also related with a lack of system requirements. To improve performance, Prowler stores information in memory so it may need to be run in a system with more than 1GB of memory. +This error is also related to a lack of system requirements. To improve performance, Prowler stores information in memory so it may need to be run in a system with more than 1GB of memory. See section [Logging](/user-guide/cli/tutorials/logging) for further information or [contact us](/contact). diff --git a/docs/user-guide/ai-agents/claude-code.mdx b/docs/user-guide/ai-agents/claude-code.mdx index 84763bf173..754202a7f9 100644 --- a/docs/user-guide/ai-agents/claude-code.mdx +++ b/docs/user-guide/ai-agents/claude-code.mdx @@ -239,7 +239,7 @@ The **Code** tab in the Claude desktop app runs the same Claude Code as the CLI, - Open a **Code** tab session and ask for a Prowler tool: "Do you have access to the Prowler MCP tools?", it should respond with a list of available tools or confirming that it has access. + Open a **Code** tab session and ask for a Prowler tool: "Do you have access to the Prowler MCP tools?", it should respond with a list of available tools or confirm that it has access. diff --git a/docs/user-guide/ai-agents/cursor.mdx b/docs/user-guide/ai-agents/cursor.mdx index 5e28eeeb1f..ab8212ab54 100644 --- a/docs/user-guide/ai-agents/cursor.mdx +++ b/docs/user-guide/ai-agents/cursor.mdx @@ -31,7 +31,7 @@ For Prowler, the **global** scope is usually the right choice — your findings - From Agent Window open **Customize** in the Cursor sidebar, then select the MCP section. + From the Agent Window open **Customize** in the Cursor sidebar, then select the MCP section. On earlier versions, press `Cmd + Shift + J` (macOS) or `Ctrl + Shift + J` (Windows/Linux) to open Cursor Settings, then click **Tools & MCP** in the sidebar. diff --git a/docs/user-guide/ai-agents/index.mdx b/docs/user-guide/ai-agents/index.mdx index ca05419050..e14d12ecac 100644 --- a/docs/user-guide/ai-agents/index.mdx +++ b/docs/user-guide/ai-agents/index.mdx @@ -16,7 +16,7 @@ Pick your agent below. Each guide is a full walkthrough with screenshots, verifi The Chat tab, via a local bridge
- ChatGPT Desktop App, Codex CLI, the VS Code extension through same config file + ChatGPT Desktop App, Codex CLI, the VS Code extension through the same config file Agentic code editor. Global and project scopes diff --git a/docs/user-guide/cli/tutorials/configuration_file.mdx b/docs/user-guide/cli/tutorials/configuration_file.mdx index ac21f5bc6c..a03e847157 100644 --- a/docs/user-guide/cli/tutorials/configuration_file.mdx +++ b/docs/user-guide/cli/tutorials/configuration_file.mdx @@ -4,7 +4,7 @@ title: "Configuration File" import { VersionBadge } from "/snippets/version-badge.mdx" -Several Prowler's checks have user configurable variables that can be modified in a common **configuration file**. This file can be found in the following [path](https://github.com/prowler-cloud/prowler/blob/master/prowler/config/config.yaml): +Several Prowler checks have user configurable variables that can be modified in a common **configuration file**. This file can be found in the following [path](https://github.com/prowler-cloud/prowler/blob/master/prowler/config/config.yaml): ``` prowler/config/config.yaml @@ -351,7 +351,7 @@ This is the new Prowler configuration file format. The old one without provider # AWS Configuration aws: # AWS Global Configuration - # aws.mute_non_default_regions --> Set to True to muted failed findings in non-default regions for AccessAnalyzer, GuardDuty, SecurityHub, DRS and Config + # aws.mute_non_default_regions --> Set to True to mute failed findings in non-default regions for AccessAnalyzer, GuardDuty, SecurityHub, DRS and Config mute_non_default_regions: False # AWS Resource Scan Limit Configuration diff --git a/docs/user-guide/cli/tutorials/custom-checks-metadata.mdx b/docs/user-guide/cli/tutorials/custom-checks-metadata.mdx index f658432782..92c0d95e05 100644 --- a/docs/user-guide/cli/tutorials/custom-checks-metadata.mdx +++ b/docs/user-guide/cli/tutorials/custom-checks-metadata.mdx @@ -10,7 +10,7 @@ You can use `--custom-checks-metadata-file` followed by the path to your custom ## Available Fields -The list of supported check's metadata fields that can be overridden are listed as follows: +The list of supported check's metadata fields that can be overridden is listed as follows: - Severity - CheckTitle diff --git a/docs/user-guide/cli/tutorials/dashboard.mdx b/docs/user-guide/cli/tutorials/dashboard.mdx index 2a24644e68..f19194a668 100644 --- a/docs/user-guide/cli/tutorials/dashboard.mdx +++ b/docs/user-guide/cli/tutorials/dashboard.mdx @@ -65,7 +65,7 @@ This page shows all the info related to the compliance selected. Multiple filter -To add your own compliance to compliance page, add a file with the compliance name (using `_` instead of `.`) to the path `/dashboard/compliance`. +To add your own compliance to the compliance page, add a file with the compliance name (using `_` instead of `.`) to the path `/dashboard/compliance`. In this file use the format present in the other compliance files to create the table. Example for CIS 2.0: diff --git a/docs/user-guide/cli/tutorials/mutelist.mdx b/docs/user-guide/cli/tutorials/mutelist.mdx index b11a41f1c9..0bb01cdd9c 100644 --- a/docs/user-guide/cli/tutorials/mutelist.mdx +++ b/docs/user-guide/cli/tutorials/mutelist.mdx @@ -163,7 +163,7 @@ Mutelist: Resources: - "test" Tags: - - "environment=prod" # Will mute every resource except in account 123456789012 except the ones containing the string "test" and tag environment=prod + - "environment=prod" # Will mute every resource in account 123456789012 except the ones containing the string "test" and tag environment=prod "*": Checks: diff --git a/docs/user-guide/cli/tutorials/quick-inventory.mdx b/docs/user-guide/cli/tutorials/quick-inventory.mdx index d412bfd572..5e29ea01dc 100644 --- a/docs/user-guide/cli/tutorials/quick-inventory.mdx +++ b/docs/user-guide/cli/tutorials/quick-inventory.mdx @@ -26,4 +26,4 @@ By default, it extracts resources from all the regions, you could use `-f`/`--fi ## Objections -The inventorying process is carried out with `resourcegroupstaggingapi` calls, which means that only resources they have or have had tags will appear (except for the IAM and S3 resources which are done with Boto3 API calls). +The inventorying process is carried out with `resourcegroupstaggingapi` calls, which means that only resources that have or have had tags will appear (except for the IAM and S3 resources which are done with Boto3 API calls). diff --git a/docs/user-guide/cli/tutorials/reporting.mdx b/docs/user-guide/cli/tutorials/reporting.mdx index 3405c9260d..a54383cb06 100644 --- a/docs/user-guide/cli/tutorials/reporting.mdx +++ b/docs/user-guide/cli/tutorials/reporting.mdx @@ -114,7 +114,7 @@ The CSV format follows a standardized structure across all providers. The follow #### CSV Headers Mapping -The following table shows the mapping between the CSV headers and the providers fields: +The following table shows the mapping between the CSV headers and the providers' fields: | Open Source Consolidated| AWS| GCP| AZURE| KUBERNETES |----------|----------|----------|----------|---------- @@ -134,7 +134,7 @@ The following table shows the mapping between the CSV headers and the providers ### JSON-OCSF -The JSON-OCSF output format implements the [Detection Finding](https://schema.ocsf.io/classes/detection_finding) from the [OCSF](https://schema.ocsf.io) +The JSON-OCSF output format implements the [Detection Finding](https://schema.ocsf.io/classes/detection_finding) from the [OCSF](https://schema.ocsf.io). ```json [{ diff --git a/docs/user-guide/compliance/tutorials/compliance.mdx b/docs/user-guide/compliance/tutorials/compliance.mdx index aad275862d..be9507ba42 100644 --- a/docs/user-guide/compliance/tutorials/compliance.mdx +++ b/docs/user-guide/compliance/tutorials/compliance.mdx @@ -253,7 +253,7 @@ Standard results plus the framework breakdown are printed to the terminal. A ded -If Prowler cannot find a resource related with a check from a compliance requirement, that requirement is omitted from the output. +If Prowler cannot find a resource related to a check from a compliance requirement, that requirement is omitted from the output. ### List Available Compliance Frameworks diff --git a/docs/user-guide/providers/aws/authentication.mdx b/docs/user-guide/providers/aws/authentication.mdx index 35c37548ea..e5fb4c48f4 100644 --- a/docs/user-guide/providers/aws/authentication.mdx +++ b/docs/user-guide/providers/aws/authentication.mdx @@ -167,7 +167,7 @@ The same `External ID` entered in the Prowler UI must match the `ExternalId` par ``` - Check the aws documentation [here](https://docs.aws.amazon.com/IAM/latest/UserGuide/sts_example_sts_GetSessionToken_section.html) + Check the AWS documentation [here](https://docs.aws.amazon.com/IAM/latest/UserGuide/sts_example_sts_GetSessionToken_section.html) 2. Copy the output containing: diff --git a/docs/user-guide/providers/aws/securityhub.mdx b/docs/user-guide/providers/aws/securityhub.mdx index 1589c46793..08384b1f9b 100644 --- a/docs/user-guide/providers/aws/securityhub.mdx +++ b/docs/user-guide/providers/aws/securityhub.mdx @@ -38,7 +38,7 @@ If AWS Security Hub is already enabled, you can proceed to the [next section](#e If the Prowler integration is already enabled in AWS Security Hub, you can proceed to the [next section](#sending-findings-to-aws-security-hub) and begin sending findings. -Once **AWS Security Hub** is activated, **Prowler** must be enabled as partner integration to allow security findings to be sent to it. +Once **AWS Security Hub** is activated, **Prowler** must be enabled as a partner integration to allow security findings to be sent to it. 1. Enabling AWS Security Hub via Console Open the **AWS Security Hub** console: https://console.aws.amazon.com/securityhub/. @@ -51,7 +51,7 @@ Open the **AWS Security Hub** console: https://console.aws.amazon.com/securityhu 5. A new modal will appear to confirm that the integration with **Prowler** is being enabled. ![](/images/providers/enable-partner-integration-3.png) -6. Click “**Accept Findings**”, to authorize **AWS Security Hub** to receive findings from Prowler. ![](/images/providers/enable-partner-integration-4.png) +6. Click “**Accept Findings**” to authorize **AWS Security Hub** to receive findings from Prowler. ![](/images/providers/enable-partner-integration-4.png) ### Using AWS CLI @@ -71,7 +71,7 @@ This command requires the `securityhub:EnableSecurityHub` permission. Ensure you **Step 2: Enable Prowler Integration** -Once **AWS Security Hub** is activated, **Prowler** must be enabled as partner integration to allow security findings to be sent to it. Run the following AWS CLI commands: +Once **AWS Security Hub** is activated, **Prowler** must be enabled as a partner integration to allow security findings to be sent to it. Run the following AWS CLI commands: ```shell aws securityhub enable-import-findings-for-product --region eu-west-1 --product-arn arn:aws:securityhub:::product/prowler/prowler @@ -151,7 +151,7 @@ prowler --security-hub --status FAIL **Configuring Findings Output** -Instead of using `--status FAIL`, the `--send-sh-only-fails` argument to store all findings in Prowler outputs while sending only FAIL findings to AWS Security: +Instead of using `--status FAIL`, use the `--send-sh-only-fails` argument to store all findings in Prowler outputs while sending only FAIL findings to AWS Security Hub: ```sh prowler --security-hub --send-sh-only-fails diff --git a/docs/user-guide/providers/gcp/getting-started-gcp.mdx b/docs/user-guide/providers/gcp/getting-started-gcp.mdx index f40542a151..404119b5f1 100644 --- a/docs/user-guide/providers/gcp/getting-started-gcp.mdx +++ b/docs/user-guide/providers/gcp/getting-started-gcp.mdx @@ -55,7 +55,7 @@ For Google Cloud, first enter your `GCP Project ID` and then select the authenti - [Generate a key for a service account](https://cloud.google.com/iam/docs/creating-managing-service-account-keys) GCP Service Account Credentials - For detailed instructions on how to setup Service Account authentication, see the [Authentication](/user-guide/providers/gcp/authentication#service-account-authentication) page. + For detailed instructions on how to set up Service Account authentication, see the [Authentication](/user-guide/providers/gcp/authentication#service-account-authentication) page. 1. Run the following command in your terminal to authenticate with GCP: diff --git a/docs/user-guide/providers/microsoft365/authentication.mdx b/docs/user-guide/providers/microsoft365/authentication.mdx index e543427e1b..5fc305d1a1 100644 --- a/docs/user-guide/providers/microsoft365/authentication.mdx +++ b/docs/user-guide/providers/microsoft365/authentication.mdx @@ -396,7 +396,7 @@ Installing PowerShell is different depending on your OS: - [Ubuntu](https://learn.microsoft.com/es-es/powershell/scripting/install/install-ubuntu?view=powershell-7.5#installation-via-package-repository-the-package-repository): The required version for installing PowerShell +7.4 on Ubuntu are Ubuntu 22.04 and Ubuntu 24.04. + [Ubuntu](https://learn.microsoft.com/es-es/powershell/scripting/install/install-ubuntu?view=powershell-7.5#installation-via-package-repository-the-package-repository): The required versions for installing PowerShell +7.4 on Ubuntu are Ubuntu 22.04 and Ubuntu 24.04. The recommended way to install it is downloading the package available on PMC. Follow these steps: @@ -482,7 +482,7 @@ Installing PowerShell is different depending on your OS: - [Debian](https://learn.microsoft.com/es-es/powershell/scripting/install/install-debian?view=powershell-7.5#installation-on-debian-11-or-12-via-the-package-repository): The required version for installing PowerShell +7.4 on Debian are Debian 11 and Debian 12. The recommended way to install it is downloading the package available on PMC. + [Debian](https://learn.microsoft.com/es-es/powershell/scripting/install/install-debian?view=powershell-7.5#installation-on-debian-11-or-12-via-the-package-repository): The required versions for installing PowerShell +7.4 on Debian are Debian 11 and Debian 12. The recommended way to install it is downloading the package available on PMC. Follow these steps: @@ -521,7 +521,7 @@ Installing PowerShell is different depending on your OS: - [Rhel](https://learn.microsoft.com/es-es/powershell/scripting/install/install-rhel?view=powershell-7.5#installation-via-the-package-repository): The required version for installing PowerShell +7.4 on Red Hat are RHEL 8 and RHEL 9. The recommended way to install it is downloading the package available on PMC. + [Rhel](https://learn.microsoft.com/es-es/powershell/scripting/install/install-rhel?view=powershell-7.5#installation-via-the-package-repository): The required versions for installing PowerShell +7.4 on Red Hat are RHEL 8 and RHEL 9. The recommended way to install it is downloading the package available on PMC. Follow these steps: diff --git a/docs/user-guide/providers/openstack/getting-started-openstack.mdx b/docs/user-guide/providers/openstack/getting-started-openstack.mdx index 1ff80c3e2e..896c4f9882 100644 --- a/docs/user-guide/providers/openstack/getting-started-openstack.mdx +++ b/docs/user-guide/providers/openstack/getting-started-openstack.mdx @@ -7,7 +7,7 @@ import { VersionBadge } from "/snippets/version-badge.mdx" Prowler supports OpenStack both from the CLI and from Prowler Cloud. This guide walks you through the requirements, how to connect the provider in the UI, and how to run scans from the command line. -Prowler currently supports **public cloud OpenStack providers** (OVH, Infomaniak, Vexxhost, etc.). Support for self-deployed OpenStack environments is not yet available, if you are interested in this feature, please [open an issue](https://github.com/prowler-cloud/prowler/issues/new) or [contact us](https://prowler.com/contact). +Prowler currently supports **public cloud OpenStack providers** (OVH, Infomaniak, Vexxhost, etc.). Support for self-deployed OpenStack environments is not yet available. If you are interested in this feature, please [open an issue](https://github.com/prowler-cloud/prowler/issues/new) or [contact us](https://prowler.com/contact). ## Prerequisites diff --git a/docs/user-guide/tutorials/prowler-app-jira-integration.mdx b/docs/user-guide/tutorials/prowler-app-jira-integration.mdx index bc9fdeb504..48e91cce65 100644 --- a/docs/user-guide/tutorials/prowler-app-jira-integration.mdx +++ b/docs/user-guide/tutorials/prowler-app-jira-integration.mdx @@ -154,7 +154,7 @@ Each Jira integration provides management actions through dedicated buttons: |--------|---------|------------------|-------| | **Test** | Verify integration connectivity | • Test Jira API access
• Validate credentials
• Check project permissions
• Verify work item creation capability | Results displayed in notification message | | **Credentials** | Update authentication settings | • Change API token
• Update email
• Update Jira domain | Click "Update Credentials" to save changes | -| **Enable/Disable** | Toggle integration status | • Enable or disable integration
| Status change takes effect immediately | +| **Enable/Disable** | Toggle integration status | • Enable or disable integration | Status change takes effect immediately | | **Delete** | Remove integration permanently | • Permanently delete integration
• Remove all configuration data | ⚠️ **Cannot be undone** - confirm before deleting | ## Known Limitations diff --git a/docs/user-guide/tutorials/prowler-app-s3-integration.mdx b/docs/user-guide/tutorials/prowler-app-s3-integration.mdx index 9b7d7a9a2e..7251748e10 100644 --- a/docs/user-guide/tutorials/prowler-app-s3-integration.mdx +++ b/docs/user-guide/tutorials/prowler-app-s3-integration.mdx @@ -330,8 +330,8 @@ Once the required permissions are set up, proceed to configure the S3 integratio ![Configuration form](/images/prowler-app/s3/s3-integration-ui-4.png) -6. Click "Next" to configure credentials -7. Configure AWS authentication using one of the supported methods: +5. Click "Next" to configure credentials +6. Configure AWS authentication using one of the supported methods: - **AWS SDK Default:** Use default AWS credentials from the environment. For Prowler Cloud users, this is the recommended option as the service has AWS credentials to assume IAM roles with ARNs matching `arn:aws:iam::*:role/Prowler*` or `arn:aws:iam::*:role/prowler*` - **Access Keys:** Provide AWS access key ID and secret access key @@ -339,14 +339,14 @@ Once the required permissions are set up, proceed to configure the S3 integratio ![Credentials configuration](/images/prowler-app/s3/s3-integration-ui-5.png) -8. Optional - For IAM role authentication, complete the required fields: +7. Optional - For IAM role authentication, complete the required fields: - **Role ARN:** The Amazon Resource Name of the IAM role - **External ID:** Unique identifier for additional security (defaults to Tenant/Organization ID) - mandatory and automatically filled - **Role Session Name:** Optional - name for the assumed role session - **Session Duration:** Optional - duration in seconds for the session -9. Click "Create Integration" to verify the connection and complete the setup +8. Click "Create Integration" to verify the connection and complete the setup Once credentials are configured and the connection test passes, the S3 integration will be active. Scan results will automatically be exported to the specified bucket after each scan completes. Run a new scan and check the S3 bucket to verify the integration is working.