Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
prowler — Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud Defender. | Kitploit
工具/GitHubGitHub/prowler-cloud/prowler
Cloud Infrastructure SecurityDefensive ToolsVulnerability ScannersVulnerability AnalysisServerless SecurityConfiguration AuditingForensicsNetwork SecurityCloud SecurityDevSecOpsThreat Intelligence
14.3k2.3k1.7k1天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
Misconfiguration
Database Security
Cloud Infrastructure Security 分类第 1 名
Cloud Security 分类第 1 名
Configuration Auditing 分类第 3 名
Database Security 分类第 12 名
Defensive Tools 分类第 17 名
Misconfiguration 分类第 3 名
Network Security 分类第 19 名
Serverless Security 分类第 1 名
Vulnerability Analysis 分类第 7 名
Vulnerability Scanners 分类第 7 名
GitHubprowler-cloud/prowler

prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud Defender.

查看仓库网站
内容在请求的语言中不可用。显示英文版本。

Prowler logo Prowler logo

Prowler is the Open Cloud Security Platform trusted by thousands to automate security and compliance in any cloud environment. With thousands of ready-to-use checks and compliance frameworks, Prowler delivers real-time, customizable monitoring and seamless integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.

The Agentic Cloud Defender

Try Prowler Cloud

Prowler community on Slack
Join our Prowler community!


Slack Shield Python Version Python Version PyPI Downloads Docker Pulls AWS ECR Gallery Codecov coverage Linux Foundation insights health score

Version Version Contributors Issues License Twitter Twitter


Prowler Cloud demo

Description

Prowler is the world’s most widely used Open-Source Cloud Security Platform that automates security and compliance across any cloud environment. With thousands of ready-to-use security checks, remediation guidance, and compliance frameworks, Prowler is built to “Secure ANY Cloud at AI Speed”. Prowler delivers AI-driven, customizable, and easy-to-use assessments, dashboards, reports, and integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.

Prowler includes hundreds of built-in controls to ensure compliance with standards and frameworks, including:

  • Prowler ThreatScore: Weighted risk prioritization scoring that helps you focus on the most critical security findings first
  • Industry Standards: CIS, NIST 800, NIST CSF, CISA, and MITRE ATT&CK
  • Regulatory Compliance and Governance: RBI, FedRAMP, PCI-DSS, and NIS2
  • Frameworks for Sensitive Data and Privacy: GDPR, HIPAA, and FFIEC
  • Frameworks for Organizational Governance and Quality Control: SOC2, GXP, and ISO 27001
  • Cloud-Specific Frameworks: AWS Foundational Technical Review (FTR), AWS Well-Architected Framework, and BSI C5
  • National Security Standards: ENS (Spanish National Security Scheme) and KISA ISMS-P (Korean)
  • Custom Security Frameworks: Tailored to your needs

Prowler Cloud & Prowler Local Server

Prowler Cloud and Prowler Local Server, its self-hosted open-source version, are web applications that simplify running Prowler across your cloud provider accounts. They provide a user-friendly interface to visualize the results and streamline your security assessments.

Prowler Cloud Risk Pipeline Threat Map

For more details, refer to the Prowler Local Server documentation

Prowler CLI

prowler <provider>

Prowler CLI Execution

Prowler Local Dashboard

prowler dashboard

Prowler Local Dashboard

Attack Paths

Attack Paths automatically extends every completed AWS scan with a graph that combines Cartography's cloud inventory with Prowler findings. The feature runs in the API worker after each scan.

Two graph backends are supported as the long-lived sink:

  • Neo4j (default; the Docker Compose files already ship a neo4j service).
  • Amazon Neptune (cloud-managed; opt-in).

Select the sink with ATTACK_PATHS_SINK_DATABASE (neo4j or neptune; default neo4j).

Note: Cartography ingestion always uses a temporary Neo4j database, regardless of the configured sink. The NEO4J_* variables below must remain set even when ATTACK_PATHS_SINK_DATABASE=neptune.

Neo4j sink

VariableDescriptionDefault
NEO4J_HOSTHostname used by the API containers.neo4j
NEO4J_PORTBolt port exposed by Neo4j.7687
NEO4J_USER / NEO4J_PASSWORDCredentials with rights to create per-tenant databases.neo4j / neo4j_password

Neptune sink

下载工具