Compare commits

...
44 changed files with 86 additions and 84 deletions
+7 -7
View File
@@ -368,7 +368,7 @@ rss: true
This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
</Note>
Azure subscriptions no longer onboard one at a time. Choose "Add Multiple Subscriptions With Azure Management Group" in the add-provider wizard, enter the Microsoft Entra tenant ID, and authenticate once with a single tenant-wide service principal: Prowler discovers the entire management-group hierarchy under the tenant root, lets you select the subscriptions to onboard, and creates their providers with the management-group structure preserved. Azure now matches the one-step onboarding that AWS Organizations and GCP organizations already have.
Azure subscriptions no longer onboard one at a time. Select "Add Multiple Subscriptions With Azure Management Group" in the add-provider wizard, enter the Microsoft Entra tenant ID, and authenticate once with a single tenant-wide service principal: Prowler discovers the entire management-group hierarchy under the tenant root, lets you select the subscriptions to onboard, and creates their providers with the management-group structure preserved. Azure now matches the one-step onboarding that AWS Organizations and GCP organizations already have.
![Azure onboarding method selector with the Management Group option](/images/changelog/v5.39.0-azure-mg-selector.png)
@@ -573,7 +573,7 @@ rss: true
Read more in the [Prowler MCP tools reference](/getting-started/basic-usage/prowler-mcp-tools#prowler-cloud-tools).
### 🧭 Compliance — Grouped by provider of the same type
### 🧭 Compliance — Grouped by Provider of the Same Type
<Note>
This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
@@ -781,7 +781,7 @@ rss: true
Read more in the [Lighthouse AI capabilities](/getting-started/products/prowler-cloud-lighthouse#capabilities).
### ☁️ One-step AWS Organizations onboarding
### ☁️ One-Step AWS Organizations Onboarding
<Note>
This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
@@ -795,7 +795,7 @@ rss: true
Read more in the [AWS Organizations documentation](/user-guide/tutorials/prowler-cloud-aws-organizations).
### 🎯 Scan configurations: exclude checks and services
### 🎯 Scan Configurations: Exclude Checks and Services
<Note>
This feature is available exclusively in **Prowler Cloud** and **Prowler Private Cloud** with a [subscription](https://prowler.com/pricing).
@@ -805,7 +805,7 @@ rss: true
Read more in the [Scan Configuration documentation](/user-guide/tutorials/prowler-app-scan-configuration#limiting-the-scan-scope).
### 🧭 Redesigned sidebar navigation
### 🧭 Redesigned Sidebar Navigation
The sidebar was redesigned around how you actually work: grouped sections for security, settings, and help, a Home/Chat switch at the top, collapsible configuration entries, clearer active states, and a responsive mobile overlay.
@@ -833,7 +833,7 @@ rss: true
</Update>
<Update label="v5.34.0" description="July 15, 2026">
### 🏷️ New product names
### 🏷️ New Product Names
The Prowler family has grown, and the names now say what each product is. Same products, clearer names:
@@ -1097,7 +1097,7 @@ rss: true
-H 'Accept: application/vnd.api+json'
```
### 🕸️ Attack Paths — Neptune as a persistent sink
### 🕸️ Attack Paths — Neptune as a Persistent Sink
Attack Paths can now persist its graph in **AWS Neptune** in addition to Neo4j, selectable via `ATTACK_PATHS_SINK_DATABASE=neptune` (default `neo4j`). Cartography's per-scan ingest database stays on Neo4j. The scan task preflights the ingest database and the configured sink before ingestion, and provider graph cleanup now deletes relationships in directed batches before deleting nodes.
@@ -40,7 +40,8 @@ The former build-time variables map to the new runtime variables as follows:
`UI_CLOUD_ENABLED` is a plain runtime boolean flag that enables Prowler Cloud behavior when set to the exact string `"true"` and defaults to off; unlike the other renamed variables it has no legacy fallback, so `NEXT_PUBLIC_IS_CLOUD_ENV` is no longer read.
`UI_SELF_REGISTRATION_ENABLED` is a runtime opt-out flag that Prowler Local Server reads only when `UI_CLOUD_ENABLED` is `"true"`. It defaults to on and turns off when set to `"false"`, matched case-insensitively so the same value can be shared with a backend setting written `False`. When it is off, the sign-up page only opens with an invitation token, the sign-in page drops its "Sign up" link, and the profile hides "Create organization"; invited users can still complete their registration. Outside a Prowler Cloud deployment the flag is ignored and account creation stays open.
`UI_SELF_REGISTRATION_ENABLED` is a runtime opt-out flag that Prowler Local Server reads only when `UI_CLOUD_ENABLED` is `"true"`. It defaults to on and turns off when set to `"false"`, matched case-insensitively so the same value can be shared with a backend setting written `False`. When it is off, the sign-up page only opens with an invitation token, the sign-in page drops its "Sign up" link, and the profile hides "Create organization". Invited users can still complete their registration. Outside a Prowler Cloud deployment the flag is ignored and account creation stays open.
## Registry UI Rollout and Rollback
`UI_REGISTRY_ENABLED` is an optional runtime flag for Prowler Cloud and Private Cloud. Registry is eligible only when both `UI_CLOUD_ENABLED` and `UI_REGISTRY_ENABLED` are the exact string `"true"` and the current user has the backend-authorized `manage_registry` permission. Unset, `"false"`, or malformed values fail closed. The flag defaults to off and is not a replacement for backend authorization. Registry access is independent of billing; Private Cloud can use it with `CLOUD_BILLING_ENABLED=false`.
+1 -1
View File
@@ -1,5 +1,5 @@
---
title: 'Introduction to developing in Prowler'
title: 'Introduction to Developing in Prowler'
---
Thanks for your interest in contributing to Prowler!
+1 -1
View File
@@ -468,7 +468,7 @@ For complete installation and deployment options, see:
- [Installation Guide](/getting-started/installation/prowler-mcp#from-source-development) - Development setup instructions
- [Configuration Guide](/getting-started/basic-usage/prowler-mcp) - MCP client configuration
For development I recommend to use the [Model Context Protocol Inspector](https://github.com/modelcontextprotocol/inspector) as MCP client to test and debug your tools.
For development, use the [Model Context Protocol Inspector](https://github.com/modelcontextprotocol/inspector) as MCP client to test and debug your tools.
## Testing
+1 -1
View File
@@ -72,7 +72,7 @@ StackIT uses service account keys for API authentication. Service account keys a
- Select your service account
- Navigate to **Service Account Keys**
- Click **Create key**
- Choose one of the following options:
- Select one of the following options:
- **STACKIT-generated key pair** (Recommended): Let STACKIT automatically generate an RSA key-pair
- **User-provided key pair**: Upload your own RSA 2048 public key
@@ -23,7 +23,7 @@ Most users should use the **Cloud MCP Server** — it needs no installation and
- **Cloud MCP Server (HTTP)**: the managed server at `https://mcp.prowler.com/mcp` (or your own self-hosted HTTP server).
- **Local MCP Server (STDIO)**: local installation only (runs as a subprocess of your MCP client).
### Step-by-Step Guides Per Agent
### Step-by-Step Guides per Agent
The tabs below are a quick configuration reference. For a walkthrough with screenshots, troubleshooting, and client-specific caveats, follow the dedicated guide for your agent:
@@ -33,7 +33,7 @@ The fastest way to get started is the **Cloud MCP Server** at `https://mcp.prowl
Prefer to run it yourself? The **Local MCP Server** runs on your own machine or infrastructure. The Cloud MCP Server additionally provides the `prowler_cloud_*` tools for Prowler Cloud-specific features: [Alerts](/user-guide/tutorials/prowler-alerts), [Findings Triage](/user-guide/tutorials/prowler-app-findings-triage), [Scan Scheduling](/user-guide/tutorials/prowler-scan-scheduling), and Scan Configurations. See [Cloud vs Local MCP Server](#cloud-vs-local-mcp-server).
</Note>
## What is the Model Context Protocol?
## What Is the Model Context Protocol?
The [Model Context Protocol (MCP)](https://modelcontextprotocol.io) is an open standard developed by Anthropic that enables AI assistants to securely connect to external data sources and tools. It functions as a universal adapter enabling AI assistants to interact with various services through a standardized interface.
+1 -1
View File
@@ -1,4 +1,4 @@
# What is Prowler?
# What Is Prowler?
**Prowler** is the world’s most widely used open-source cloud security platform that **automates security and compliance** across any cloud environment. With thousands of ready-to-use security checks, remediation guidance, and compliance frameworks, Prowler delivers AI-driven, customizable, and easy-to-use monitoring and integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.
+2 -2
View File
@@ -23,7 +23,7 @@ Security controls cover six domains, each detailed below:
Every GitHub Actions workflow uses runner hardening, pinned action versions, and audited permissions.
### Runner Hardening With StepSecurity
### Runner Hardening with StepSecurity
- [**`step-security/harden-runner`**](https://github.com/step-security/harden-runner) runs as the first step in every workflow, pinned by commit SHA.
- Workflows are being migrated to explicit egress controls: some already declare an egress allow-list with `egress-policy: block`, while others still run in `egress-policy: audit` until their allowed endpoints are fully defined.
@@ -39,7 +39,7 @@ Every GitHub Actions workflow uses runner hardening, pinned action versions, and
- Workflows declare `permissions: {}` at the top level and grant the minimum required scopes per job.
- Code review covers permission changes; zizmor enforces the rules (see below).
### Workflow Security Audit With Zizmor
### Workflow Security Audit with Zizmor
- **[zizmor](https://github.com/zizmorcore/zizmor)** audits every workflow file for known security anti-patterns. Runs on every pull request and push.
- Triggers on every push, every pull request that touches `.github/`, and on a daily schedule.
+1 -1
View File
@@ -270,7 +270,7 @@ Chat reads `claude_desktop_config.json` and reaches the Prowler MCP Server throu
| Skill not invoked when expected | The prompt didn't match any skill's description | Name the task explicitly. For compliance triage, mention the framework plus "compliance" or "compliant". |
| "Framework not supported" | Prowler Hub does not list the framework for that provider | Open an issue or PR at [github.com/prowler-cloud/prowler](https://github.com/prowler-cloud/prowler). |
### Authentication Fails With 401
### Authentication Fails with 401
- Confirm the header value includes the `Bearer ` prefix.
- Check that `PROWLER_API_KEY` was set when you ran `claude mcp add` — the shell expands it at that moment and stores the resulting literal value. If the variable was empty, the stored header reads `Bearer ` with nothing after it. Verify with `claude mcp get prowler`.
+1 -1
View File
@@ -110,7 +110,7 @@ Open a Chat conversation and ask questions that use the Prowler tools:
Expected. The Chat tab does not read `~/.claude.json`, so servers added with `claude mcp add` never appear here. The Chat tab needs an entry in `claude_desktop_config.json`, which is what this guide sets up.
### Authentication Fails With 401
### Authentication Fails with 401
- Confirm the header value includes the `Bearer ` prefix.
- Confirm the key has not been revoked in Prowler Cloud.
+3 -3
View File
@@ -45,7 +45,7 @@ Each tab below is a complete setup — follow the one that matches the surface y
<Tab title="Codex / ChatGPT desktop app">
1. Open **Settings** and select **Plugins → MCPs**
2. Click **Add server**
3. Enter `prowler` as the name and choose type **Streamable HTTP**
3. Enter `prowler` as the name and select type **Streamable HTTP**
4. Enter the URL `https://mcp.prowler.com/mcp`
5. Add two headers:
@@ -135,7 +135,7 @@ Ask Codex questions that use the Prowler tools:
## Troubleshooting
### Startup Fails With HTTP 403 Forbidden
### Startup Fails with HTTP 403 Forbidden
Codex reports a handshake failure on startup, with an HTML error page rather than a JSON response:
@@ -147,7 +147,7 @@ Codex reports a handshake failure on startup, with an HTML error page rather tha
The `User-Agent` header is missing. Codex's HTTP client does not send one, and requests without it are rejected before reaching the MCP server. Note this is a **403**, not a 401 — so it is not an API key problem. Add the header as shown in [Step 2](#step-2-add-the-prowler-mcp-server); the value itself does not matter, only that the header is present.
### Authentication Fails With 401
### Authentication Fails with 401
- Run `codex mcp get prowler` and confirm the entry has the headers you expect. Values are masked, but a missing header shows as `-`.
- If you used a literal header, confirm the value starts with `Bearer ` and contains the full key.
+1 -1
View File
@@ -139,7 +139,7 @@ You can toggle individual tools on or off from the tools list at the top of the
- Open **MCP Logs** in the Output panel for the specific error.
- Confirm the URL is exactly `https://mcp.prowler.com/mcp`.
### Authentication Fails With 401
### Authentication Fails with 401
- Verify the header value includes the `Bearer ` prefix: `"Bearer pk_..."`, not just the key.
- Confirm the key has not been revoked in Prowler Cloud.
+1 -1
View File
@@ -116,7 +116,7 @@ Copilot asks for confirmation before running an MCP tool for the first time.
- Check that `mcp.json` is valid JSON.
- Verify your VS Code version is 1.102 or later.
### Authentication Fails With 401
### Authentication Fails with 401
- Verify the header value includes the `Bearer ` prefix.
- Confirm the key has not been revoked in Prowler Cloud.
@@ -164,7 +164,7 @@ This split is intentional. It reduces expensive per-resource analysis calls with
| `max_ecs_task_definitions` | ECS task definitions (`ecs_task_definitions_*`) | Integer |
| `max_codeartifact_packages` | CodeArtifact packages (`codeartifact_packages_*`) | Integer |
#### Resource Limit Behavior By Resource Path
#### Resource Limit Behavior by Resource Path
| Resource Path | What Prowler Discovers | What A Positive Limit Selects For Analysis | Ordering And Latest Behavior | AWS Calls Reduced | Drawbacks And Consequences |
|---------------|------------------------|--------------------------------------------|------------------------------|-------------------|----------------------------|
@@ -81,7 +81,7 @@ When the selected scan includes Prowler ThreatScore data, a dedicated card appea
<img src="/images/compliance/prowler-app-compliance-threatscore-card.png" alt="Prowler ThreatScore badge on the Compliance overview showing the overall score and per-pillar bars" width="900" />
Selecting the card opens the ThreatScore framework detail page, covered in [Working With the Framework Detail Page](#working-with-the-framework-detail-page).
Selecting the card opens the ThreatScore framework detail page, covered in [Working with the Framework Detail Page](#working-with-the-framework-detail-page).
For a complete explanation of the methodology, formula, and weighting, see [Prowler ThreatScore](/user-guide/compliance/tutorials/threatscore).
@@ -103,7 +103,7 @@ Select any card to open the framework detail page.
Score color coding follows three thresholds: red for severely low compliance, amber for partial compliance, and green for healthy posture. Hover over the score for the exact percentage.
</Note>
### Tracking Frameworks With the Compliance Watchlist
### Tracking Frameworks with the Compliance Watchlist
<VersionBadge version="5.38.0" />
@@ -125,7 +125,7 @@ Every framework card carries a pin button in its top-right corner. Select the pi
Universal frameworks (CSA CCM, CIS Controls, DORA) are a single watchlist entry. Pinning one of them from any surface shows it as pinned on the others.
</Note>
#### Filtering With the Watchlist
#### Filtering with the Watchlist
Two controls sit above the tabs, because both tabs read the same watchlist:
@@ -146,7 +146,7 @@ The **Compliance Watchlist** card on the Overview page lists exactly the pinned
In Prowler Local Server, where the watchlist is not available, the card keeps its previous behavior and ranks every framework with scan data.
</Note>
### Working With the Framework Detail Page
### Working with the Framework Detail Page
The detail page provides everything needed to evaluate a single framework: aggregate metrics, top failure sections, and a requirement-by-requirement view.
@@ -176,7 +176,7 @@ Select a requirement to open the detail panel and review the failing checks, the
<img src="/images/compliance/prowler-app-compliance-requirements-accordion.png" alt="Expanded CIS requirement showing description, rationale, remediation procedure, audit procedure, profile and assessment tags, references, and the underlying check" width="900" />
##### Frameworks With Custom Detail Layouts
##### Frameworks with Custom Detail Layouts
Several frameworks include enriched detail panels that highlight fields specific to the standard:
@@ -209,7 +209,7 @@ The cap is configurable per deployment via the `DJANGO_PDF_MAX_FINDINGS_PER_CHEC
Only **failed** findings are rendered in the detail section. PASS findings for the same check are excluded at query time. The PDF surfaces what needs attention, and the CSV/JSON exports surface everything for forensic review.
</Note>
#### Downloading From the Detail Page
#### Downloading from the Detail Page
Inside any framework detail page, the **CSV** and **PDF** buttons in the header trigger the same downloads as the overview dropdown. The PDF button only appears for frameworks that support it.
@@ -80,7 +80,7 @@ To confirm which providers made it into an aggregation, read the coverage summar
The **Providers** filter on the detail page lists every provider of the type, including ones that have never been scanned. Narrowing to providers with no completed scan leaves the view with no evidence to aggregate: the coverage card reports nothing scanned, requirements show no per-provider status, and any report generated for that selection is empty. Clear the filter or select providers that have already been scanned.
</Warning>
## Working With the Framework Detail Page
## Working with the Framework Detail Page
Selecting a card opens a detail page with the same layout as the cross-provider-type detail, with the column axis swapped from provider type to provider:
@@ -102,7 +102,7 @@ Select **Clear filters** to reset all filters. Filters applied on the overview a
Filters narrow **which providers contribute** to the aggregation. They do not change how a requirement rolls up (see [Understanding the Roll-Up Status](#understanding-the-roll-up-status)).
</Note>
## Working With the Framework Detail Page
## Working with the Framework Detail Page
The detail page provides the full breakdown for a single universal framework: aggregate metrics, provider coverage, top failing sections, and a requirement-by-requirement view with per-provider status.
@@ -16,21 +16,21 @@ Prowler supports multiple Alibaba Cloud authentication flows. If more than one i
Do not use the AccessKey pair of the main Alibaba Cloud account for Prowler. Use a RAM user, a RAM role, or another temporary credential flow instead.
</Warning>
## Choose The Right Method
## Choose the Right Method
| Where Prowler runs | What you need to create | Recommended method |
| --- | --- | --- |
| Local workstation | RAM user + AccessKey pair | [RAM User And AccessKey](#ram-user-and-accesskey) |
| Local workstation | RAM user + AccessKey pair | [RAM User and AccessKey](#ram-user-and-accesskey) |
| CI runner outside Alibaba Cloud | RAM user + AccessKey pair, optionally a target RAM role | [RAM Role Assumption](#ram-role-assumption-recommended) |
| ECS instance | ECS RAM role attached to the instance | [ECS RAM Role](#ecs-ram-role) |
| ACK / Kubernetes | OIDC IdP + RAM role + OIDC token file | [OIDC Role Authentication](#oidc-role-authentication) |
| Internal credential broker | An HTTP endpoint that returns STS credentials | [Credentials URI](#credentials-uri) |
## RAM User And AccessKey
## RAM User and AccessKey
This is the simplest setup for a workstation or a basic CI runner.
### Create The RAM User
### Create the RAM User
1. Open the [RAM console](https://ram.console.alibabacloud.com/).
2. Go to `Identities` > `Users`.
@@ -51,7 +51,7 @@ Alibaba Cloud walkthroughs with current console screenshots:
- [Create an AccessKey pair](https://www.alibabacloud.com/help/en/ram/user-guide/create-an-accesskey-pair)
- [Grant permissions to a RAM user](https://www.alibabacloud.com/help/en/ram/user-guide/grant-permissions-to-the-ram-user)
### Use The AccessKey With Prowler
### Use the AccessKey with Prowler
```bash
export ALIBABA_CLOUD_ACCESS_KEY_ID="your-access-key-id"
@@ -62,7 +62,7 @@ prowler alibabacloud
Prowler also accepts `ALIYUN_ACCESS_KEY_ID` and `ALIYUN_ACCESS_KEY_SECRET` for compatibility, but `ALIBABA_CLOUD_*` is the preferred naming.
### Use The Default Credential Chain
### Use the Default Credential Chain
If you prefer not to export credentials in every shell, you can store them with the Alibaba Cloud CLI and let Prowler reuse the default credential chain from `~/.aliyun/config.json`.
@@ -87,17 +87,17 @@ This flow has two parts:
1. A source identity that can call `sts:AssumeRole`.
2. A target RAM role that has the scan permissions.
### Create The Source Identity
### Create the Source Identity
Create a RAM user with an AccessKey pair by following the steps in [RAM User And AccessKey](#ram-user-and-accesskey), or reuse an existing automation identity.
Create a RAM user with an AccessKey pair by following the steps in [RAM User and AccessKey](#ram-user-and-accesskey), or reuse an existing automation identity.
### Create The Target Role
### Create the Target Role
1. Open the [RAM console](https://ram.console.alibabacloud.com/).
2. Go to `Identities` > `Roles`.
3. Click `Create Role`.
4. Set `Principal Type` to `Cloud Account`.
5. Choose:
5. Select:
- `Current Account` if the RAM user and the role are in the same account.
- `Other Account` if the RAM user belongs to a different Alibaba Cloud account.
6. Give the role a name such as `ProwlerAuditRole`.
@@ -111,7 +111,7 @@ Helpful references:
- [Create a RAM role for a trusted Alibaba Cloud account](https://www.alibabacloud.com/help/en/ram/user-guide/create-a-ram-role-for-a-trusted-alibaba-cloud-account)
- [Assume a RAM role](https://www.alibabacloud.com/help/doc-detail/116820.html)
### Allow The Source Identity To Assume The Role
### Allow the Source Identity to Assume the Role
The source RAM user must be able to call `sts:AssumeRole`.
@@ -164,7 +164,7 @@ Prowler does not mint standalone STS sessions for you. If you use this method, y
Use this when Prowler runs on an ECS instance and you do not want to store any AccessKeys on disk.
### Create And Attach The Role
### Create and Attach the Role
1. Open the [RAM console](https://ram.console.alibabacloud.com/).
2. Go to `Identities` > `Roles`.
@@ -196,7 +196,7 @@ prowler alibabacloud
Use this when Prowler runs in ACK or another Kubernetes environment that provides an OIDC token file.
### Create The OIDC Identity Provider
### Create the OIDC Identity Provider
1. Open the [RAM console](https://ram.console.alibabacloud.com/).
2. Go to `Integrations` > `SSO`.
@@ -214,13 +214,13 @@ Alibaba Cloud guides:
- [Manage an OIDC IdP](https://www.alibabacloud.com/help/en/ram/manage-an-oidc-idp)
- [Overview of role-based OIDC SSO](https://www.alibabacloud.com/help/en/ram/overview-of-oidc-based-sso)
### Create The RAM Role Trusted By That IdP
### Create the RAM Role Trusted by That IdP
Create a RAM role whose trusted entity is the OIDC IdP, then attach the scan permissions to that role.
If you are running in ACK with RRSA, this is typically the role bound to the service account that runs Prowler.
### Provide The OIDC Variables To Prowler
### Provide the OIDC Variables to Prowler
Prowler currently expects:
@@ -284,7 +284,7 @@ The exact minimum policy depends on the checks and services you enable.
If you are using the RAM console's `Grant Permission` screen, search for the **system policy names** below. Alibaba Cloud often uses product policy names that differ from the service name shown in Prowler.
### System Policies In The RAM Console
### System Policies in the RAM Console
| Prowler use case | Policy name in RAM console | Notes |
| --- | --- | --- |
@@ -44,7 +44,7 @@ This method grants permanent access and is the recommended setup for production
![Create Stack](/images/providers/create-stack.png)
4. In **Specify Template**, choose "Upload a template file" and select the downloaded file
4. In **Specify Template**, select "Upload a template file" and select the downloaded file
![Upload a template file](/images/providers/upload-template-file.png)
![Upload file from downloads](/images/providers/upload-template-from-downloads.png)
@@ -25,7 +25,7 @@ export PROWLER_AWS_BOTO3_READ_TIMEOUT=30
CLI flags take precedence over the environment variables. Prowler sets both timeouts explicitly, so `AWS_DEFAULTS_MODE` and a `connect_timeout` in `~/.aws/config` are ignored; use the flag or the environment variable instead.
<Note>
Boto3 defaults both timeouts to 60 seconds. In networks with restricted egress (for example VPC endpoints for a subset of services, GovCloud or private deployments), every AWS service without a reachable endpoint used to cost up to 4 attempts × 60 seconds (the first call plus the 3 retries) for each region. Prowler lowers the connect timeout to 10 seconds so unreachable endpoints fail fast; lower it further together with `--aws-retries-max-attempts 0`, which disables retries and leaves a single attempt per call, if a scan still spends most of its time waiting on unreachable services.
Boto3 defaults both timeouts to 60 seconds. In networks with restricted egress (for example VPC endpoints for a subset of services, GovCloud or private deployments), every AWS service without a reachable endpoint used to cost up to 4 attempts × 60 seconds (the first call plus the 3 retries) for each region. Prowler lowers the connect timeout to 10 seconds so unreachable endpoints fail fast. If a scan still spends most of its time waiting on unreachable services, lower it further together with `--aws-retries-max-attempts 0`, which disables retries and leaves a single attempt per call.
</Note>
@@ -42,7 +42,7 @@ export PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS=0
The CLI flag takes precedence over the environment variable. The value must be a non-negative integer; when neither is set, Prowler uses 3 retries.
<Warning>
The environment variable is process-wide: it applies to every AWS provider built in the process where it is set, not only to a connection check. A scan started in that same process picks it up too. Boto3's Standard retry mode, which Prowler uses, also retries service-side throttling responses (see the errors listed below), so `0` disables retries for those as well. On a large account a scan can hit throttling under normal load, and with retries disabled that throttling becomes a hard failure instead of a retried call. Set the variable only on the processes that run connection checks; leave scan workers on the default, or raise their retry count instead of lowering it.
The environment variable is process-wide: it applies to every AWS provider built in the process where it is set, not only to a connection check. A scan started in that same process picks it up too. Boto3's Standard retry mode, which Prowler uses, also retries service-side throttling responses (see the errors listed below), so `0` disables retries for those as well. On a large account a scan can hit throttling under normal load, and with retries disabled that throttling becomes a hard failure instead of a retried call. Set the variable only on the processes that run connection checks. Leave scan workers on the default, or raise their retry count instead of lowering it.
</Warning>
## Retry Behavior Overview
@@ -83,7 +83,7 @@ When onboarding multiple AWS accounts into Prowler Cloud, it is important to dep
The [Prowler Scan IAM Role CloudFormation template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/cloudformation/prowler-scan-role.yml) can deploy the role across your entire AWS Organization on its own—no third-party modules required. When launched in the **Management Account** (or a **Delegated Administrator** account) with `DeployStackSet=true` and `EnableOrganizations=true`, it creates a service-managed CloudFormation StackSet that rolls the ProwlerScan role out to every account under the target Organizational Unit (or the organization root), and keeps new accounts covered automatically through auto-deployment.
To deploy from the CloudFormation console: open **CloudFormation → Create stack → With new resources**, choose **Upload a template file** and select `prowler-scan-role.yml` (or paste its S3 URL), then set the parameters below on the **Specify stack details** step. Leave the **Configure stack options** step at its defaults.
To deploy from the CloudFormation console: open **CloudFormation → Create stack → With new resources**, select **Upload a template file** and select `prowler-scan-role.yml` (or paste its S3 URL), then set the parameters below on the **Specify stack details** step. Leave the **Configure stack options** step at its defaults.
Deploy a single CloudFormation Stack in the Management Account with the following parameters:
@@ -27,6 +27,7 @@ When scanning the China (`aws-cn`), European Sovereign Cloud (`aws-eusc`) or Gov
Refer to: https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html#configuring-credentials for more information about the AWS credential configuration.
</Note>
### Declaring the Partition
`PROWLER_AWS_PARTITION` tells Prowler which partition the scan runs against, without relying on a region being configured:
@@ -35,11 +36,11 @@ Refer to: https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credenti
export PROWLER_AWS_PARTITION="aws-us-gov"
```
It matters most where nothing else says. Resolving an identity means calling STS before anything is known about the credentials, and with no region configured Prowler would otherwise start from the commercial endpoints. Declaring the partition makes that first call go to the right place, which is the difference between a scan that starts and one that fails on an endpoint the credentials cannot use.
The variable matters most when nothing else declares the partition. Resolving an identity means calling STS before anything is known about the credentials, and with no region configured Prowler would otherwise start from the commercial endpoints. Declaring the partition makes that first call go to the right place, which is the difference between a scan that starts and one that fails on an endpoint the credentials cannot use.
A region configured for the session still wins when it belongs to the declared partition, so a deployment in `us-gov-west-1` is not sent to `us-gov-east-1`. A region belonging to a different partition is ignored, since a partition that has been declared explicitly is the more deliberate statement of the two.
When no configured region says which one to prefer, the first region of the partition is tried, and up to two more follow if it cannot be reached. A network that routes to only one region of its partition therefore works without having to declare which one that is. Only a connection failure moves on to the next region: a credential error is reported from the first, since it would be the same everywhere. A region excluded from the scan is tried last, so it is avoided whenever another region of the partition answers.
When no configured region indicates which one to prefer, Prowler tries the first region of the partition, and up to two more follow if it cannot be reached. A network that routes to only one region of its partition therefore works without having to declare which one that is. Only a connection failure moves on to the next region: a credential error is reported from the first, since it would be the same everywhere. A region excluded from the scan is tried last, so it is avoided whenever another region of the partition answers.
<Note>
Set it wherever the scan runs. For deployments that scan from containers, that means the environment of the containers doing the scanning, not only the one accepting the request.
@@ -32,7 +32,7 @@ If AWS Security Hub is already enabled, you can proceed to the [next section](#e
3. In the “Security Standards” section, review the supported security standards. Select the checkbox for each standard you want to enable, or clear it to disable a standard.
4. Choose “**Enable Security Hub**”. ![](/images/providers/enable-2.png)
4. Select “**Enable Security Hub**”. ![](/images/providers/enable-2.png)
#### Enabling Prowler Integration in AWS Security Hub
@@ -1,5 +1,5 @@
---
title: 'Tag-based scan'
title: 'Tag-based Scan'
---
Prowler provides the capability to scan only resources containing specific tags. To execute this, use the designated flag `--resource-tags` followed by the tags `Key=Value`, separated by spaces.
@@ -121,7 +121,7 @@ The checks requiring this `ProwlerRole` can be found in this [section](/user-gui
![IAM Page](/images/providers/iam-azure-page.png)
4. Click "+ Add" > "Add custom role", choose "Start from JSON" and upload the modified file
4. Click "+ Add" > "Add custom role", select "Start from JSON" and upload the modified file
![Add custom role via JSON](/images/providers/add-custom-role-json.png)
@@ -144,7 +144,7 @@ To use this service account with `--organization-id`, additionally grant `roles/
### Step 3: Generate a JSON Key
1. Open the newly created service account, move to the **Keys** tab, and choose **Add key > Create new key**.
1. Open the newly created service account, move to the **Keys** tab, and select **Add key > Create new key**.
![Add a new key to the service account](/user-guide/providers/gcp/img/create-new-key.png)
@@ -116,7 +116,7 @@ A host with no internet access needs a pre-populated vulnerability database in a
Trivy tries to refresh the database when it considers it stale, and that download fails without network access. Set `TRIVY_SKIP_DB_UPDATE=true` (and `TRIVY_SKIP_JAVA_DB_UPDATE=true` if Java scanning is enabled) so it uses the supplied database as is.
The database ages. A scan run against an old one reports only the vulnerabilities known when it was built, and nothing in the output says so, so keep track of when it was last refreshed.
The database ages. A scan run against an old one reports only the vulnerabilities known when it was built, and nothing in the output says so. Keep track of when the database was last refreshed.
</Note>
@@ -151,7 +151,7 @@ To scan multiple images, repeat the `-I` flag:
prowler image -I nginx:latest -I redis:7 -I python:3.12-slim
```
#### Scan From an Image List File
#### Scan from an Image List File
For large-scale scanning, provide a file containing one image per line:
@@ -18,7 +18,7 @@ The following steps apply to Prowler Cloud and Prowler Local Server.
1. Navigate to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler Local Server](/user-guide/tutorials/prowler-app).
2. Go to **Configuration** → **Providers** and click **Add Provider**.
![Add OCI Provider](./images/oci-add-cloud-provider.png)
3. Select **Oracle Cloud** and enter the **Tenancy OCID** and an optional alias, then choose **Next**.
3. Select **Oracle Cloud** and enter the **Tenancy OCID** and an optional alias, then select **Next**.
![Add OCI Cloud Tenancy](./images/oci-add-tenancy.png)
### Step 3: Add OCI API Key Credentials
@@ -430,7 +430,7 @@ clouds:
identity_api_version: "3"
```
## Creating a User With Reader Role
## Creating a User with Reader Role
For security auditing, Prowler only needs **read-only access** to your OpenStack resources.
@@ -16,7 +16,7 @@ StackIT uses RSA key-pair based service account keys. They are issued once, must
- `iaas.viewer` for the IaaS security group checks currently shipped, or
- `project.owner` if you want to cover any future service Prowler adds.
4. Open the service account and go to **Service Account Keys**.
5. Click **Create key** and choose **STACKIT-generated key pair** (recommended). Download the resulting JSON file and store it securely (for example, `~/.stackit/sa-key.json`). The private material is only shown once.
5. Click **Create key** and select **STACKIT-generated key pair** (recommended). Download the resulting JSON file and store it securely (for example, `~/.stackit/sa-key.json`). The private material is only shown once.
### Option 2: Create the Key via the StackIT CLI
@@ -161,7 +161,7 @@ Prowler for Vercel includes security checks across the following services:
| **Security** | Web Application Firewall (WAF), rate limiting, IP blocking, and managed rulesets |
| **Team** | SSO enforcement, directory sync, member access, and invitation hygiene |
## Checks With Explicit Plan-Based Behavior
## Checks with Explicit Plan-Based Behavior
Prowler currently includes 26 Vercel checks. The 11 checks below have explicit billing-plan handling in the provider metadata or check logic. When the scanned scope reports a billing plan, Prowler adds plan-aware context to findings for these checks. If the API does not expose the required configuration, Prowler may return `MANUAL` and require verification in the Vercel dashboard.
+1 -1
View File
@@ -39,7 +39,7 @@ Alerts run on one of three schedules:
| Daily digest | Evaluates the Alert once per day and sends a digest when findings match. |
| After each scan and daily | Evaluates the Alert after every scan and in the daily digest. |
## Creating an Alert From Findings
## Creating an Alert from Findings
To create an Alert:
@@ -75,7 +75,7 @@ To send every Finding in a Finding Group:
![A complete Finding Group selected with the Send Finding Group to Jira action highlighted](/images/prowler-app/jira/select-group.png)
4. Select the Jira project and issue type.
5. Choose an issue creation mode:
5. Select an issue creation mode:
* **Create one Jira issue for all selected Findings in this Finding Group:** Keeps the complete Finding Group in one Jira issue.
* **Create separate Jira issues:** Creates one Jira issue per selected Finding so that each affected resource can be tracked independently.
6. Click **Send to Jira**.
@@ -134,7 +134,7 @@ When invited to join an organization, the invited user receives a link to accept
2. If already authenticated, the invitation is accepted automatically and the user is redirected to Prowler Cloud.
3. If not authenticated, choose **I have an account -- Sign in**, authenticate with existing credentials, and the invitation is accepted upon sign-in.
3. If not authenticated, select **I have an account -- Sign in**, authenticate with existing credentials, and the invitation is accepted upon sign-in.
<img src="/images/prowler-app/multi-tenant/sign-in-invitation.png" alt="Sign in screen after choosing I have an account from invitation" width="700" />
@@ -142,7 +142,7 @@ When invited to join an organization, the invited user receives a link to accept
1. Open the invitation link.
2. Choose **I'm new -- Create an account**.
2. Select **I'm new -- Create an account**.
3. Complete the sign-up process. Upon account creation, the invitation is accepted and the user joins the inviter's organization.
@@ -151,7 +151,7 @@ Invitations expire after 7 days. If an invitation has expired, contact the organ
</Note>
## Expelling a User From an Organization
## Expelling a User from an Organization
Organization owners can expel a member from the organization. Expelling removes the membership immediately, revoking access to all providers, scans, and findings scoped to that organization. Owners expelling themselves are blocked if they are the last remaining owner of the organization.
@@ -159,8 +159,8 @@ Because a provider can belong to only one configuration, associating a provider
On the **Scan Config** page, open the **⋮** menu on a configuration row:
- **Edit:** Choose **Edit** to open the editor, change its name, YAML, or attached providers, and click **Update**. Editing the YAML always happens here, never from the provider row.
- **Delete:** Choose **Delete** (in the danger zone) and confirm. Providers that were attached fall back to the built-in defaults from `config.yaml` on their next scan.
- **Edit:** Select **Edit** to open the editor, change its name, YAML, or attached providers, and click **Update**. Editing the YAML always happens here, never from the provider row.
- **Delete:** Select **Delete** (in the danger zone) and confirm. Providers that were attached fall back to the built-in defaults from `config.yaml` on their next scan.
## How It's Applied
@@ -63,7 +63,7 @@ To configure AWS Security Hub integration in Prowler Cloud:
4. Configure authentication:
Choose the appropriate authentication method:
Select the appropriate authentication method:
* **Use Provider Credentials** (recommended): Leverages the AWS provider's existing credentials
@@ -181,7 +181,7 @@ The Prowler app has not been invited to it. In Slack, run `/invite @Prowler Clou
* For a private authorized channel, confirm the Prowler app is still a member of it.
* Confirm the Prowler app is still installed in the workspace.
### A Channel Is Missing From an Alert's Channel List
### A Channel Is Missing from an Alert's Channel List
The channel is authorized here but not confirmed yet. Click **Test connection**: it confirms every authorized channel it has not confirmed, and confirmed channels become selectable on Alerts.
@@ -55,7 +55,7 @@ The Prowler wizard walks you through the entire flow: deploying both roles from
<img src="/images/organizations/select-aws-provider.png" alt="Provider selection modal with Amazon Web Services highlighted" />
</Frame>
3. Choose **Add Multiple Accounts With AWS Organizations**.
3. Select **Add Multiple Accounts With AWS Organizations**.
<Frame>
<img src="/images/organizations/select-organizations-method.png" alt="Method selector showing Add Multiple Accounts With AWS Organizations option highlighted" />
@@ -295,7 +295,7 @@ Organizational unit rows carry the same **Test Connections** and **Delete Organi
To refresh the account membership of an existing AWS Organization, repeat the same discovery flow used during onboarding:
1. Navigate to **Providers**, click **Add Provider**, and select **Amazon Web Services**.
2. Choose **Add Multiple Accounts With AWS Organizations**.
2. Select **Add Multiple Accounts With AWS Organizations**.
3. Enter the existing **Organization ID**, proceed to **Authentication Details**, and use the existing deployment account **Role ARN**.
4. Confirm that the stack is deployed and click **Authenticate**. Prowler reuses the existing organization and starts a new discovery instead of creating a duplicate.
@@ -478,7 +478,7 @@ Deploy the ProwlerScan role to every member account with a [CloudFormation Stack
</Note>
1. In your management account, navigate to **CloudFormation > StackSets > Create StackSet** ([open directly](https://us-east-1.console.aws.amazon.com/cloudformation/home?region=us-east-1#/stacksets/create)).
2. Choose **Service-managed permissions**.
2. Select **Service-managed permissions**.
3. Enable **Automatic deployment** so CloudFormation deploys the role to accounts added to the targeted root or OUs. Configure the account removal behavior based on whether the stack and its resources should be retained when an account leaves the target.
4. Select **Amazon S3 URL** as the template source and paste:
```
@@ -109,7 +109,7 @@ In the Azure portal, the same value sits on your service principal's **App regis
<img src="/images/organizations/azure/select-azure-provider.png" alt="Provider selection modal with Microsoft Azure highlighted" />
</Frame>
3. Choose **Add Multiple Subscriptions With Azure Management Group**.
3. Select **Add Multiple Subscriptions With Azure Management Group**.
<Frame>
<img src="/images/organizations/azure/select-azure-management-groups-method.png" alt="Method selector showing the Add Multiple Subscriptions With Azure Management Group option highlighted" />
@@ -107,7 +107,7 @@ In the Google Cloud console, the ID sits in the **ID** column next to the organi
<img src="/images/organizations/gcp/select-gcp-provider.png" alt="Provider selection modal with Google Cloud highlighted" />
</Frame>
3. Choose **Add Multiple Projects With GCP Organization**.
3. Select **Add Multiple Projects With GCP Organization**.
<Frame>
<img src="/images/organizations/gcp/select-gcp-organizations-method.png" alt="Method selector showing Add Multiple Projects With GCP Organization option highlighted" />
@@ -21,7 +21,7 @@ The annual plan is paid upfront for a fixed number of cloud provider accounts, b
## Change a Customer's Plan
Open the actions menu on a customer's row and choose **Change plan**.
Open the actions menu on a customer's row and select **Change plan**.
<Warning>
**Plan changes are one way: trial to paid.** The action is only offered while a customer is on trial or its trial has expired. Once a customer holds a paid subscription, **Change plan** no longer appears on the row, and the trial is never a valid target.
@@ -60,7 +60,7 @@ Above the table, search by name and filter by provider or status. The download b
## Open a Customer's Prowler Cloud Tenant
Open the actions menu at the end of a customer's row and choose **Access Organization**. You are redirected into that customer's tenant in Prowler Cloud, signed in as yourself acting on their behalf.
Open the actions menu at the end of a customer's row and select **Access Organization**. You are redirected into that customer's tenant in Prowler Cloud, signed in as yourself acting on their behalf.
While you are in the tenant you see what a customer administrator sees, and every action is recorded in the Prowler Cloud audit log against both your identity and the customer you are acting for.
@@ -72,7 +72,7 @@ Opening a tenant requires a role with **Access tenants**. The action fails with
## Edit a Customer
Choose **Edit** from the row actions to open the **Edit customer** panel and rename the customer. The new name must still be unique within the partner organization.
Select **Edit** from the row actions to open the **Edit customer** panel and rename the customer. The new name must still be unique within the partner organization.
## Link an Existing Customer with Your Partner Code
@@ -33,7 +33,7 @@ A Prowler Cloud or Prowler Private Cloud subscription supports the following cus
The scan time is always selected on the hour (for example, 14:00); minutes cannot be set. The schedule time uses the browser timezone when the schedule is saved. Prowler displays the next scheduled scan in that timezone.
## Create a Schedule From Scans
## Create a Schedule from Scans
To create a schedule from the **Scans** page:
@@ -41,7 +41,7 @@ To create a schedule from the **Scans** page:
2. Click **Launch Scan**.
3. Select a connected provider.
4. Select **On a schedule**.
5. Choose the **Scan Time** and **Repeats** values.
5. Select the **Scan Time** and **Repeats** values.
6. Optional: select **Launch an initial scan now for immediate findings** to run a scan immediately after saving the recurring schedule.
7. Click **Save Schedule**.
@@ -51,7 +51,7 @@ To create a schedule from the **Scans** page:
After the schedule is saved, Prowler shows a confirmation toast with a link to the **Scheduled** tab.
## Edit Schedules From Providers
## Edit Schedules from Providers
The **Providers** page shows each provider's current schedule in the **Scan Schedule** column. Providers without a recurring schedule show **None**.