Prowler Cloud Security Scanner

Provides AWS/Azure/GCP/OCI cloud security and compliance scanning via Prowler. Integrates cloud security findings into the GRC platform with full dashboard, scan management, and reporting capabilities. Automatically map cloud security findings to GRC framework controls for comprehensive compliance coverage.

Version 2.0.0MIT License

Key Features

Comprehensive capabilities designed to extend your GRC platform.

Multi-cloud support (AWS, Azure, GCP, OCI, GitHub, Kubernetes, MongoDB, M365)

Automated security and compliance scanning

Integration with GRC frameworks (NIST, GDPR, COBIT, ISO27001, CIS, HIPAA, PCI, SOC2)

Interactive dashboard with findings viewer

Scheduled scan capabilities

Export and reporting integration

Isolated Python environment for security

Credential management with encryption

Use Cases

Real-world scenarios where this plugin delivers value

  • Continuous cloud security monitoring across multiple providers
  • Compliance scanning for SOC 2, ISO 27001, and other frameworks
  • Identify misconfigurations and security gaps in cloud infrastructure
  • Map cloud findings to GRC framework controls
  • Generate compliance reports from cloud security scans
  • Maintain cloud security posture across hybrid environments

Benefits

Value propositions and advantages of using this plugin

  • Unified view of cloud security across multiple providers
  • Automated compliance mapping to GRC frameworks
  • Reduced manual effort in cloud security assessments
  • Continuous monitoring with scheduled scans
  • Better visibility into cloud security posture
  • Integration with existing GRC workflows

Integrations

Frameworks and modules this plugin integrates with

Frameworks

NISTGDPRCOBITISO27001CISHIPAAPCISOC2

Modules

assetsriskreportsassessments

Requirements

System requirements and dependencies

Python

>=3.9

Environment Variables

  • AWS_ACCESS_KEY_ID
  • AWS_SECRET_ACCESS_KEY

Security & Permissions

Security considerations and permission requirements

Permissions

cloud:readcloud:scan

Network Access

Required

File System Access

Required

Notes

This plugin requires cloud provider credentials and network access to scan cloud infrastructure. Ensure credentials are securely stored and encrypted.

Ready to Get Started?

All plugins are included with your RiskFortress license. Contact us to learn more or request a demo.