Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
aws-security-assessment-solution — An AWS tool to help you create a point in time assessment of your AWS account using Prowler. | Kitploit
Tools/GitHubGitHub/awslabs/aws-security-assessment-solution
Cloud Infrastructure SecurityVulnerability ScannersConfiguration AuditingCloud SecurityDevSecOps
GitHubawslabs/aws-security-assessment-solution

aws-security-assessment-solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
615118314 days agoReviewed by Kitploit
Share

Self-Service Security Assessment Solutions (v2.0)

Cybersecurity remains a very important topic and point of concern for many CIOs, CISOs, and their customers. To meet these important concerns, AWS has developed a primary set of services customers should use to aid in protecting their accounts. Amazon GuardDuty, AWS Security Hub, AWS Config, and AWS Well-Architected reviews help customers maintain a strong security posture over their AWS accounts. As more organizations deploy to the cloud, especially if they are doing so quickly, and they have not yet implemented the recommended AWS Services, there may be a need to conduct a rapid security assessment of the cloud environment.

We have developed an inexpensive, easy to deploy, secure, and fast solution to provide our customers with a security assessment report. These reports are generated using the open source project Prowler. Prowler performs point in time security assessment based on AWS best practices and can help quickly identify any potential risk areas in a customer’s deployed environment. If you are interested in conducting these assessments on a continuous basis, AWS recommends enabling Security Hub’s Foundational Security Best Practices standard. If you are interested in integrating your Prowler assessment results with Security Hub, you can follow the instructions in the Prowler Documentation.

Note: Prowler is not an AWS owned solution. Customers should independently review Prowler before running this solution. Any dependencies associated with Prowler should be kept up to date. This solution installs a pinned version of Prowler (currently 5.41.0) from the pip package installer, so that a change to Prowler's output format cannot break a scan without warning. To move to a newer release, edit the pip3 install prowler== line in 2-sat2-codebuild-prowler.yaml.

📕 For more in depth step-by-step instructions, visit module 2 in the SHIP Workshop.

Table of Contents

  • Overview
  • Parameters
  • Deployment
  • Single account scan
    • AWS CloudShell
      • Deploy the solution
    • AWS Console
      • Deploy the solution
  • Multi-account scan
    • AWS CloudShell
      • Step 1: Deploy prerequisite role
      • Step 2: Deploy the SATv2 solution
    • AWS Console
      • Step 1: Deploy prerequisite role
      • Step 2: Enable delegated administrator for AWS Organizations
      • Step 3: Deploy the SATv2 solution
  • Review the results
    • SATv2 Dashboard (recommended)
    • Prowler Dashboard
  • Scan types
    • Basic Scan
    • Intermediate scan
    • Full scan
    • Secrets checks
  • Notifications
  • Reporting Summary
    • How the Athena table is built
    • Scan history and duplicates
  • Frequently Asked Questions (FAQ)
  • Clean Up
  • Security
  • License

Overview

The solution is deployed with AWS CloudFormation. When deployed, an AWS CodeBuild project and an Amazon S3 bucket to store the Prowler generated reports are created. An AWS Lambda function is then used to start the AWS CodeBuild project.

The parameter (user input) defaults will run a basic scan in a single account. However, you can choose different parameters to run more extensive scans or to scan multiple accounts. The deployment process takes less than 5 minutes to complete. The solution’s AWS CloudFormation templates are provided for review in this Github repository.

Once the template is deployed, the CodeBuild project will run. The default assessment takes around 5 minutes to complete. The time to complete a security assessment will vary depending on the number of resources and the scan options selected. At the end of the assessments the reports are delivered to the created S3 Bucket.

architecture diagram

Parameters

SATv2 can be customized by updating the CloudFormation parameters. This section summarizes the available options and provides a link to the section with more information.

Download Tool