Prowler is the Open Cloud Security Platform trusted by thousands to automate security and compliance in any cloud environment. With thousands of ready-to-use checks and compliance frameworks, Prowler delivers real-time, customizable monitoring and seamless integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.
The Agentic Cloud Defender
Prowler is the world’s most widely used Open-Source Cloud Security Platform that automates security and compliance across any cloud environment. With thousands of ready-to-use security checks, remediation guidance, and compliance frameworks, Prowler is built to “Secure ANY Cloud at AI Speed”. Prowler delivers AI-driven, customizable, and easy-to-use assessments, dashboards, reports, and integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.
Prowler includes hundreds of built-in controls to ensure compliance with standards and frameworks, including:
- Prowler ThreatScore: Weighted risk prioritization scoring that helps you focus on the most critical security findings first
- Industry Standards: CIS, NIST 800, NIST CSF, CISA, and MITRE ATT&CK
- Regulatory Compliance and Governance: RBI, FedRAMP, PCI-DSS, and NIS2
- Frameworks for Sensitive Data and Privacy: GDPR, HIPAA, and FFIEC
- Frameworks for Organizational Governance and Quality Control: SOC2, GXP, and ISO 27001
- Cloud-Specific Frameworks: AWS Foundational Technical Review (FTR), AWS Well-Architected Framework, and BSI C5
- National Security Standards: ENS (Spanish National Security Scheme) and KISA ISMS-P (Korean)
- Custom Security Frameworks: Tailored to your needs
Prowler Cloud & Prowler Local Server
Prowler Cloud and Prowler Local Server, its self-hosted open-source version, are web applications that simplify running Prowler across your cloud provider accounts. They provide a user-friendly interface to visualize the results and streamline your security assessments.



For more details, refer to the Prowler Local Server documentation
Prowler CLI
prowler <provider>

Prowler Local Dashboard
prowler dashboard

Attack Paths
Attack Paths automatically extends every completed AWS scan with a graph that combines Cartography’s cloud inventory with Prowler findings. The feature runs in the API worker after each scan.
Two graph backends are supported as the long-lived sink:
- Neo4j (default; the Docker Compose files already ship a
neo4jservice). - Amazon Neptune (cloud-managed; opt-in).
Select the sink with ATTACK_PATHS_SINK_DATABASE (neo4j or neptune; default neo4j).
Note: Cartography ingestion always uses a temporary Neo4j database, regardless of the configured sink. The
NEO4J_*variables below must remain set even whenATTACK_PATHS_SINK_DATABASE=neptune.
Neo4j sink
| Variable | Description | Default |
|---|---|---|
NEO4J_HOST |
Hostname used by the API containers. | neo4j |
NEO4J_PORT |
Bolt port exposed by Neo4j. | 7687 |
NEO4J_USER / NEO4J_PASSWORD |
Credentials with rights to create per-tenant databases. | neo4j / neo4j_password |
Neptune sink
Source : KitPloit – PenTest Tools!
