Prowler - Maximize your Cloud Security Compliance Assessments with Open Source and a pinch of AI

Cloud Village @ DEF CON 33 · Day 1 · Cloud Village

Overview

In this comprehensive talk at Cloud Village, Toni de la Fuente, CEO and Founder of Prowler, unveiled how the open-source cloud security tool, Prowler, is revolutionizing compliance assessments and continuous monitoring across multi-cloud environments. The presentation delved into Prowler's extensive capabilities, from traditional runtime scanning to cutting-edge Infrastructure as Code (IaC) analysis and the innovative integration of Artificial Intelligence (AI) through Lighthouse AI. The core message emphasized providing an accessible, transparent, and powerful alternative to expensive commercial Cloud Security Posture Management (CSPM) solutions, empowering organizations of all sizes to enhance their security posture.

Watch on YouTube

Visual summary for Prowler - Maximize your Cloud Security Compliance Assessments with Open Source and a pinch of AI
Visual summary for Prowler - Maximize your Cloud Security Compliance Assessments with Open Source and a pinch of AI

Key moments

  1. 0:00 Prowler's PII detection capabilities
  2. 2:00 Prowler's support for Kubernetes and multi-cloud environments
  3. 3:15 New GitHub security best practices checks
  4. 4:00 Exploring Prowler Hub: Checks, details, and custom rule creation
  5. 5:25 Optimizing scan duration and customizing checks
  6. 6:40 Consistent output formats and integration with other tools
  7. 8:05 Using the local Prowler dashboard for quick assessments

Prowler - Maximize your Cloud Security Compliance Assessments with Open Source and a pinch of AI

Speakers: Toni de la Fuente, CEO & Founder, Prowler

Conference: Cloud Village

YouTube: https://www.youtube.com/watch?v=YOGSrvMqCJk

Overview

In this comprehensive talk at Cloud Village, Toni de la Fuente, CEO and Founder of Prowler, unveiled how the open-source cloud security tool, Prowler, is revolutionizing compliance assessments and continuous monitoring across multi-cloud environments. The presentation delved into Prowler's extensive capabilities, from traditional runtime scanning to cutting-edge Infrastructure as Code (IaC) analysis and the innovative integration of Artificial Intelligence (AI) through Lighthouse AI. The core message emphasized providing an accessible, transparent, and powerful alternative to expensive commercial Cloud Security Posture Management (CSPM) solutions, empowering organizations of all sizes to enhance their security posture.

De la Fuente highlighted Prowler's commitment to community-driven development, supporting a vast array of cloud providers including AWS, Azure, Google Cloud, Kubernetes, Microsoft 365, and GitHub. The talk showcased how Prowler helps security professionals, DevOps engineers, and auditors efficiently identify misconfigurations, detect sensitive data exposure, and ensure adherence to various compliance frameworks like CIS benchmarks and SOC 2. By combining robust open-source principles with intelligent AI assistance, Prowler aims to simplify the complex landscape of cloud security, making it actionable and affordable for a wider audience.

The significance of Prowler lies in its dual approach: offering a powerful command-line interface (CLI) for practitioners needing quick, on-demand assessments, and a comprehensive web application for continuous monitoring and advanced analytics. This talk serves as a vital resource for anyone looking to understand modern cloud security challenges and how an open-source solution, bolstered by AI, can effectively address them, ultimately maximizing compliance and minimizing risk in dynamic cloud environments.

Background

▶ Watch: Prowler's PII detection capabilities (0:00)

The rapid adoption of cloud computing has introduced unprecedented complexity and scale, making effective security posture management a significant challenge for organizations. Traditional security tools often struggle to keep pace with the ephemeral nature of cloud resources, the proliferation of new services, and the intricate web of interdependencies across multi-cloud environments. This complexity is further compounded by the stringent requirements of regulatory compliance frameworks, which demand continuous vigilance and evidence of adherence.

Existing commercial Cloud Security Posture Management (CSPM) solutions, while powerful, often come with substantial licensing costs, lack transparency in their underlying logic ("black boxes"), and can create vendor lock-in. This financial and technical barrier leaves many organizations, particularly smaller businesses, startups, or those with limited budgets, struggling to implement robust cloud security. The problem extends to Infrastructure as Code (IaC) practices, where security vulnerabilities can be baked into templates long before deployment, necessitating a "shift-left" approach to security.

Prowler emerged from this landscape as an open-source project designed to democratize cloud security. Its philosophy, as articulated by de la Fuente, mirrors the trajectory of tools like Elasticsearch in challenging proprietary solutions like Splunk – proving that open-source alternatives can not only compete but also innovate. Prowler addresses the need for a tool that is transparent, extensible, and community-driven, allowing users to inspect its checks, contribute improvements, and tailor it to specific organizational needs. Initially focused on runtime assessments, Prowler has continuously evolved to incorporate IaC scanning and, most recently, AI capabilities, positioning itself as a comprehensive solution for the modern cloud security professional.

Key Findings

▶ Watch: New GitHub security best practices checks (3:15)

The presentation highlighted several key findings and advancements that position Prowler as a leading tool in cloud security and compliance:

  • Extensive Multi-Cloud and IaC Support: Prowler now offers comprehensive scanning capabilities across a broad spectrum of cloud providers, including AWS, Azure, Google Cloud, Kubernetes, Microsoft 365, and GitHub. Crucially, it has expanded its reach to Infrastructure as Code (IaC), allowing organizations to scan Terraform, CloudFormation, Dockerfiles, and GitHub Actions for security misconfigurations before deployment, effectively shifting security left in the development lifecycle.
  • Vast and Customizable Check Database: With over a thousand controls available in Prowler Hub, the tool covers a multitude of security best practices and compliance frameworks, including CIS benchmarks (e.g., CIS AWS Foundations Benchmark v1.5.0 Level 2), SOC 2, PCI, HIPAA, and custom frameworks. This extensive library, coupled with the ability for users to create their own checks and compliance frameworks via simple JSON files, ensures adaptability to unique organizational requirements.
  • Lighthouse AI for Intelligent Assistance: A significant new contribution is Lighthouse AI, which integrates AI capabilities into Prowler. This AI is designed to assist users in creating new checks, analyzing scan results, and generating detailed remediation guidance, including AWS Service Control Policies (SCPs) and Terraform code snippets. De la Fuente explicitly clarified that Lighthouse AI is a "Cloud Security Analyst" companion, providing intelligent suggestions rather than automated, trustless remediation actions.
  • Prowler Threat Score for Nuanced Posture Assessment: Moving beyond simplistic percentage-based compliance scores, Prowler introduces the Prowler Threat Score. This innovative scoring mechanism assigns weights to different risk levels (e.g., high-risk findings like exposed S3 buckets carry more weight), providing a more realistic and actionable understanding of an organization's security posture across four key pillars: Identity and Access Management (IAM), Encryption, Attack Surface, and Logging & Monitoring.
  • Open-Source Accessibility and Community-Driven Development: Prowler remains committed to its open-source roots, offering a powerful alternative to proprietary solutions. The project boasts over 300 contributors and actively encourages community engagement through GitHub pull requests, issue reporting, and feedback on platforms like Slack. This model fosters transparency, rapid development, and ensures the tool remains current with emerging threats and cloud services.

Technical Deep Dive

▶ Watch: Exploring Prowler Hub: Checks, details, and custom rule creation (4:00)

Prowler's architecture is designed for flexibility, supporting both on-demand command-line operations and continuous monitoring through its cloud platform. At its core, Prowler is written in Python, leveraging libraries like Pandas for efficient data processing of scan results.

The tool offers a Command Line Interface (CLI) that can be run locally, within Docker containers, or integrated into CI/CD pipelines. For authentication across various cloud providers, Prowler supports multiple methods:

  • AWS: IAM roles (recommended AssumeRole), CloudFormation quick links for easy deployment of necessary roles, and external IDs.
  • Azure: Environment variables, service principal credentials, and read-all policies for directories, users, and authentication methods.
  • Google Cloud: gcloud CLI credentials, and explicit credential file paths. Prowler can scan all projects by default or specific ones.
  • Kubernetes: In-cluster or outside-cluster scanning, supporting local Kubernetes, AKS, EKS, and GKE. It can use kubeconfig files and tokens, with a Helm chart available for deployment. Access can be restricted to Prowler's public IP for enhanced security.
  • Microsoft 365: Similar to Azure, relying on environment variables.
  • GitHub: Personal Access Tokens (PATs), OAuth tokens, or GitHub App credentials for scanning repositories and organizations.

Prowler's scanning capabilities are granular and extensive:

  • Runtime Scanning: Assesses live cloud environments for misconfigurations, exposed secrets (e.g., in Lambda functions, user data, ECR image versions), PII in resource names or logs (e.g., CloudWatch Logs, SNS topics), and adherence to security best practices. Users can scan entire organizations, specific accounts/projects/subscriptions, or narrow down to specific services, regions, or even categories like "internet exposed" resources. The "internet exposed" category can integrate with Shodan using an API key for external validation.
  • Infrastructure as Code (IaC) Scanning: Prowler integrates with Checkov (an open-source static analysis tool) to scan IaC templates before deployment. This includes Terraform, CloudFormation, Dockerfiles, and GitHub Actions. It can analyze local repositories or remote ones, providing findings with file paths and line numbers.

Output and Integrations are a strong suit of Prowler:

  • Formats: Scan results are generated in various formats: JSON, CSV, HTML (convenient for quick sharing), and OCSF (Open Cybersecurity Schema Framework). OCSF is Prowler's native format and is highly beneficial for integrations, being supported by major cloud providers and security vendors like AWS, Microsoft, Google, and Splunk.
  • Local Dashboard: A convenient web dashboard can be launched locally (typically on port 1666) to visualize scan results, compliance reports, and historical data from local CSV files. This allows for quick analysis without needing a full cloud deployment.
  • Cloud Integrations: Prowler integrates with cloud-native services like AWS Security Hub (sending only stale findings to optimize billing), and pulls findings from AWS GuardDuty. A recent feature allows automated export of scan results to an S3 bucket for centralized storage, facilitating integration with SIEMs like Splunk or ElasticSearch, or data visualization tools like AWS QuickSight or Excel (using provided templates).

Advanced Features:

  • Custom Checks and Compliance Frameworks: Users can define their own checks and compliance frameworks using simple JSON metadata files, linking requirements to specific Prowler checks. This allows for highly tailored security policies.
  • Mute List: To manage alert fatigue, Prowler provides a flexible mute list (configurable via a YAML file or the UI). Users can mute specific accounts, checks, tags, or individual findings. While currently basic, future roadmap items include time-bound muting.
  • "Scan Any Services" Flag: By default, Prowler might skip checks for unused or empty services to save time. The scan-any-services flag forces Prowler to include all services, even if empty, for the most comprehensive assessment.
  • API: The Prowler platform provides a full API for programmatic interaction, enabling automation of scans, retrieval of findings, and integration with third-party systems, all secured with Role-Based Access Control (RBAC).
  • Prowler Threat Score: This custom scoring mechanism assigns weights to findings based on their risk level and impact across four critical security pillars: IAM, Encryption, Attack Surface, and Logging & Monitoring. This offers a more accurate representation of an organization's actual security posture compared to simple compliance percentages.

Demo / Proof of Concept

▶ Watch: Consistent output formats and integration with other tools (6:40)

Toni de la Fuente provided several live demonstrations throughout the talk, showcasing Prowler's versatility and key features across both its CLI and the Prowler Cloud web application.

  1. Prowler Hub and Check Exploration: The talk began with a quick tour of Prowler Hub, the online database of Prowler checks. This demonstrated how users can browse all available checks, view their details, remediation steps, and even see how to write their own custom checks. This highlighted the transparency and extensibility of Prowler.
  1. Infrastructure as Code (IaC) Scanning with CLI: A compelling demonstration involved scanning IaC templates. De la Fuente used a repository called Terraote, known for intentionally misconfigured Terraform templates. He ran Prowler from the CLI, specifying an IaC scan. The output, presented as an HTML report, clearly showed failures related to Terraform, Dockerfiles, and secrets (e.g., access keys in various files). The report allowed filtering by failed checks, providing specific file paths and line numbers where vulnerabilities were found, emphasizing Prowler's "shift-left" security capabilities.
  1. Local Dashboard Visualization: After a CLI scan, the speaker launched Prowler's local dashboard, accessible via a web browser on port 1666. This dashboard dynamically loaded the generated CSV output, providing an interactive view of compliance results (e.g., for CIS AWS Foundations Benchmark Level 2). It showcased how quickly users can visualize their security posture and drill down into specific findings without needing a persistent cloud deployment.
  1. Prowler Cloud Web UI and Provider Onboarding: The presentation then shifted to the Prowler Cloud web application. De la Fuente demonstrated the process of adding an AWS account as a provider. He showed the recommended method of assuming a role, which provides a CloudFormation quick link to deploy the necessary IAM role in the target AWS account, along with an external ID for secure authentication. This streamlined onboarding process highlighted the ease of integrating new cloud environments.
  1. Continuous Monitoring and Findings Analysis: Once an AWS account was added, the demo showed how to trigger a manual scan and view the results. The Prowler Cloud UI displayed findings, allowing filtering by severity, service, resource type, and even a "delta" view to see changes since the last scan. A specific example of an S3 bucket exposed to the internet was shown, detailing the finding ID, affected resource, remediation steps (for both CLI and AI-generated), and crucially, the evidence in JSON format, which is invaluable for auditors. The UI also demonstrated the mute findings feature, showing how to hide findings related to AWS Control Tower that are often unfixable or low priority.
  1. Lighthouse AI in Action: The most impressive part of the demo was the Lighthouse AI integration. De la Fuente queried the AI with natural language questions like "Are there any exposed S3 buckets?" and "How to fix this with AWS Organizations?" The AI responded by identifying the exposed bucket, generating an AWS Service Control Policy (SCP) example to prevent public S3 access, and then, upon further request, provided the equivalent Terraform code to deploy that SCP. This showcased AI's ability to act as an intelligent companion, offering practical, context-aware remediation guidance.
  1. Prowler Threat Score Dashboard: Finally, the speaker presented the Prowler Threat Score dashboard, illustrating how this weighted scoring mechanism provides a more realistic security posture. He showed how a single critical finding, like an open S3 bucket, could significantly impact the overall score, even if other areas were 99% compliant. This demonstrated the value of a risk-based approach over simple compliance percentages across the four pillars: IAM, Encryption, Attack Surface, and Logging & Monitoring.

These demonstrations collectively underscored Prowler's evolution from a robust CLI tool to a comprehensive, AI-enhanced platform for multi-cloud security and compliance.

Defensive Implications

▶ Watch: Using the local Prowler dashboard for quick assessments (8:05)

The insights and capabilities presented in the Prowler talk offer several critical defensive implications for organizations operating in cloud environments:

  1. Proactive Security with Shift-Left IaC Scanning: Prowler's ability to scan Infrastructure as Code (IaC) templates (Terraform, CloudFormation, Dockerfiles, GitHub Actions) before deployment is a game-changer. This allows security teams to identify and remediate misconfigurations and vulnerabilities early in the development lifecycle, significantly reducing the cost and effort of fixing issues post-deployment. Integrating Prowler into CI/CD pipelines ensures that security is baked in, not bolted on.
  1. Continuous Multi-Cloud Visibility and Monitoring: The comprehensive support for AWS, Azure, Google Cloud, Kubernetes, and Microsoft 365 enables organizations to maintain a unified and continuous security posture view across their entire cloud footprint. Regular runtime scans help detect new misconfigurations, drift from desired states, and emerging threats, ensuring that security controls remain effective as environments evolve.
  1. Robust Compliance Adherence and Evidence Collection: Prowler automates checks against numerous compliance frameworks (CIS, SOC 2, PCI, HIPAA) and supports custom policies. This not only streamlines the auditing process but also provides detailed evidence in formats like JSON and OCSF, which auditors frequently request. The Prowler Threat Score offers a more sophisticated metric for understanding compliance, highlighting critical risks rather than just broad percentages.
  1. AI-Assisted Remediation and Skill Augmentation: Lighthouse AI acts as a "Cloud Security Analyst" companion, providing intelligent remediation guidance. By generating Service Control Policies (SCPs) or Terraform code to fix identified issues, Prowler helps security teams and developers implement fixes more efficiently and consistently. This augments human capabilities, allowing engineers to focus on higher-level strategic tasks rather than manually researching remediation steps.
  1. Enhanced Threat Detection and Risk Prioritization: Prowler's ability to detect exposed secrets, PII, and internet-exposed resources (potentially with Shodan integration) helps defenders identify critical attack vectors. The Prowler Threat Score further aids in prioritizing remediation efforts by highlighting findings with the highest risk impact, enabling teams to allocate resources where they matter most.
  1. Cost-Effective Security Operations: As an open-source solution, Prowler offers a highly cost-effective alternative to expensive commercial CSPM tools, making robust cloud security accessible to a wider range of organizations. Additionally, its intelligent integration with AWS Security Hub (sending only stale findings) helps optimize cloud billing costs associated with security services.
  1. Reduced Alert Fatigue and Improved Focus: The flexible mute list allows security teams to suppress known, unfixable, or low-priority findings (e.g., from AWS Control Tower), thereby reducing alert fatigue and allowing analysts to focus on genuinely actionable and high-impact security issues.
  1. Transparency and Extensibility: The open-source nature of Prowler means defenders can inspect the underlying logic of every check, build custom checks, and integrate the tool deeply into their existing security ecosystem via its comprehensive API. This transparency fosters trust and allows for greater control over security assessments.

Key Takeaways

  • Comprehensive Multi-Cloud & IaC Security: Prowler offers extensive security and compliance assessments across AWS, Azure, Google Cloud, Kubernetes, Microsoft 365, and GitHub, crucially extending its capabilities to Infrastructure as Code (IaC) scanning for Terraform, CloudFormation, Dockerfiles, and GitHub Actions to enable "shift-left" security.
  • AI for Analysis and Remediation Guidance: The new Lighthouse AI feature enhances Prowler by assisting with check creation, intelligent analysis of findings, and generating practical remediation guidance such as AWS Service Control Policies (SCPs) and Terraform code, acting as a "Cloud Security Analyst" companion, though not for automated remediation yet.
  • Nuanced Risk-Based Scoring: Prowler introduces the Prowler Threat Score, a weighted scoring mechanism that provides a more realistic and actionable security posture assessment across four key pillars: IAM, Encryption, Attack Surface, and Logging & Monitoring, moving beyond simplistic compliance percentages.
  • Open-Source and Community-Driven: As a fully open-source project, Prowler provides a transparent and cost-effective alternative to proprietary CSPM solutions, benefiting from over 300 contributors and actively encouraging community feedback and contributions for continuous improvement and adaptation to new threats.
  • Flexible Deployment and Rich Output: Prowler can be run via CLI, Docker, or its comprehensive Prowler Cloud platform, offering various output formats including JSON, CSV, HTML, and OCSF (Open Cybersecurity Schema Framework), along with a local dashboard and integrations with services like AWS Security Hub and S3 for centralized reporting and analysis.
  • Empowering Defenders: The tool equips security professionals with capabilities for continuous monitoring, proactive vulnerability detection, streamlined compliance auditing, and efficient remediation, significantly enhancing an organization's ability to manage cloud security effectively.

About the Speaker(s)

The talk was delivered by Toni de la Fuente, the CEO & Founder of Prowler. His presentation showcased a deep technical understanding of cloud security challenges, compliance frameworks, and the practicalities of implementing robust security measures across diverse cloud environments. De la Fuente's insights into the evolution of Prowler from an open-source project to a venture-backed company, while maintaining its community-driven ethos, reflect his commitment to accessible and transparent cloud security solutions. His experience, likely spanning incident response and security assessments, underpins the practical and effective design of Prowler, addressing real-world security needs.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This is a vendor product demo dressed in conference clothing. The founder of Prowler pitching Prowler at Cloud Village is not a research talk — it's a sales presentation with live demos, and it should be evaluated as such. There's nothing here that advances the field, challenges assumptions, or teaches practitioners something they couldn't learn from the Prowler docs in 20 minutes.

Heather Calloway (CISO) — WEAK

Competent tool walkthrough by the founder, technically detailed but never escapes the gravity of its own product pitch. Practitioners may find tactical value, but there is nothing here for security leaders making governance or program decisions.

→ Top-rated talks at Cloud Village @ DEF CON 33

All talks from Cloud Village @ DEF CON 33