Commit 1a30844
committed
File tree
- .claude-plugin
- .config
- .github
- actions
- osv-scanner
- setup-python-poetry
- setup-python-uv
- trivy-scan
- scripts
- workflows
- api
- docs
- src/backend
- api
- attack_paths
- queries
- management/commands
- migrations
- specs
- sse
- tests
- v1
- serializer_utils
- config
- django
- settings
- tasks
- jobs
- attack_paths
- reports
- tests
- claude_plugins/prowler
- .claude-plugin
- skills/framework-compliance-triage
- contrib
- PowerBI/Multicloud CIS Benchmarks
- aws/multi-account-securityhub
- inventory-graph
- examples
- lib
- extractors
- k8s/helm
- prowler-api
- prowler-app
- templates/ui
- prowler-ui
- reverse-proxy
- dashboard
- compliance
- lib
- pages
- docs
- developer-guide
- getting-started
- basic-usage
- installation
- products
- images
- compliance
- powerbi
- prowler-app/alerts
- security
- snippets
- user-guide
- cli/tutorials
- compliance/tutorials
- cookbooks
- providers
- aws
- cloudflare
- gcp
- github
- googleworkspace
- linode
- llm
- oci
- okta
- images
- scaleway
- stackit
- tutorials
- mcp_server
- prowler_mcp_server
- prowler_app
- models
- tools
- utils
- tests
- permissions
- templates
- cloudformation
- terraform
- prowler
- compliance
- alibabacloud
- aws
- azure
- gcp
- googleworkspace
- linode
- m365
- okta
- oraclecloud
- stackit
- config
- schema
- lib
- check
- cli
- outputs
- compliance
- asd_essential_eight
- aws_well_architected
- c5
- ccc
- cisa_scuba
- cis
- csa
- ens
- generic
- iso27001
- kisa_ismsp
- mitre_attack
- okta_idaas_stig
- prowler_threatscore
- universal
- html
- jira
- ocsf
- slack
- scan
- utils
- providers
- aws
- lib/ip_ranges
- services
- acmpca
- acmpca_certificate_authority_pqc_key_algorithm
- apigateway
- apigateway_domain_name_pqc_tls_enabled
- bedrock
- bedrock_agent_role_least_privilege
- bedrock_api_key_no_long_term_credentials
- bedrock_prompt_encrypted_with_cmk
- bedrock_prompt_management_exists
- cloudfront
- cloudfront_distributions_pqc_tls_enabled
- cloudtrail/cloudtrail_bedrock_logging_enabled
- cloudwatch
- cloudwatch_changes_to_network_acls_alarm_configured
- cloudwatch_changes_to_network_gateways_alarm_configured
- cloudwatch_changes_to_network_route_tables_alarm_configured
- cloudwatch_changes_to_vpcs_alarm_configured
- cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled
- cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled
- cloudwatch_log_metric_filter_authentication_failures
- cloudwatch_log_metric_filter_aws_organizations_changes
- cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk
- cloudwatch_log_metric_filter_for_s3_bucket_policy_changes
- cloudwatch_log_metric_filter_policy_changes
- cloudwatch_log_metric_filter_security_group_changes
- cloudwatch_log_metric_filter_sign_in_without_mfa
- lib
- codepipeline/codepipeline_project_repo_private
- config
- config_delegated_admin_and_org_aggregator_all_regions
- elbv2/elbv2_alb_drop_invalid_header_fields_enabled
- iam
- iam_no_custom_policy_permissive_role_assumption
- iam_policy_allows_privilege_escalation
- iam_policy_no_full_access_to_cloudtrail
- iam_policy_no_full_access_to_kms
- iam_policy_no_wildcard_marketplace_subscribe
- iam_role_access_not_stale_to_bedrock
- iam_user_access_not_stale_to_bedrock
- iam_user_access_not_stale_to_sagemaker
- lib
- rolesanywhere
- rolesanywhere_trust_anchor_pqc_pki
- route53/route53_dangling_ip_subdomain_takeover
- s3
- s3_bucket_default_encryption
- s3_bucket_shadow_resource_vulnerability
- sagemaker
- sagemaker_clarify_exists
- sagemaker_domain_sso_configured
- sagemaker_models_monitor_enabled
- sagemaker_models_registry_in_use
- securityhub
- securityhub_delegated_admin_enabled_all_regions
- ses
- ses_identity_dkim_enabled
- transfer
- transfer_server_pqc_ssh_kex_enabled
- azure
- lib
- mutelist
- regions
- service
- services
- aisearch
- aisearch_service_not_publicly_accessible
- aks
- aks_cluster_auto_upgrade_enabled
- aks_cluster_azure_monitor_enabled
- aks_cluster_defender_enabled
- aks_cluster_local_accounts_disabled
- aks_cluster_rbac_enabled
- aks_clusters_created_with_private_nodes
- aks_clusters_public_access_disabled
- aks_network_policy_enabled
- apim
- apim_threat_detection_llm_jacking
- appinsights
- appinsights_ensure_is_configured
- app
- app_client_certificates_on
- app_ensure_auth_is_set_up
- app_ensure_http_is_redirected_to_https
- app_ensure_java_version_is_latest
- app_ensure_php_version_is_latest
- app_ensure_python_version_is_latest
- app_ensure_using_http20
- app_ftp_deployment_disabled
- app_function_access_keys_configured
- app_function_application_insights_enabled
- app_function_ftps_deployment_disabled
- app_function_identity_is_configured
- app_function_identity_without_admin_privileges
- app_function_latest_runtime_version
- app_function_not_publicly_accessible
- app_function_vnet_integration_enabled
- app_http_logs_enabled
- app_minimum_tls_version_12
- app_register_with_identity
- containerregistry
- containerregistry_admin_user_disabled
- containerregistry_not_publicly_accessible
- containerregistry_uses_private_link
- cosmosdb
- cosmosdb_account_automatic_failover_enabled
- cosmosdb_account_backup_policy_continuous
- cosmosdb_account_firewall_use_selected_networks
- cosmosdb_account_minimum_tls_version
- cosmosdb_account_public_network_access_disabled
- cosmosdb_account_use_aad_and_rbac
- cosmosdb_account_use_private_endpoints
- databricks
- databricks_workspace_cmk_encryption_enabled
- databricks_workspace_no_public_ip_enabled
- databricks_workspace_public_network_access_disabled
- databricks_workspace_vnet_injection_enabled
- defender
- defender_additional_email_configured_with_a_security_contact
- defender_assessments_vm_endpoint_protection_installed
- defender_attack_path_notifications_properly_configured
- defender_auto_provisioning_log_analytics_agent_vms_on
- defender_auto_provisioning_vulnerabilty_assessments_machines_on
- defender_container_images_resolved_vulnerabilities
- defender_container_images_scan_enabled
- defender_ensure_defender_cspm_is_on
- defender_ensure_defender_for_app_services_is_on
- defender_ensure_defender_for_arm_is_on
- defender_ensure_defender_for_azure_sql_databases_is_on
- defender_ensure_defender_for_containers_is_on
- defender_ensure_defender_for_cosmosdb_is_on
- defender_ensure_defender_for_databases_is_on
- defender_ensure_defender_for_dns_is_on
- defender_ensure_defender_for_keyvault_is_on
- defender_ensure_defender_for_os_relational_databases_is_on
- defender_ensure_defender_for_server_is_on
- defender_ensure_defender_for_sql_servers_is_on
- defender_ensure_defender_for_storage_is_on
- defender_ensure_iot_hub_defender_is_on
- defender_ensure_mcas_is_enabled
- defender_ensure_notify_alerts_severity_is_high
- defender_ensure_notify_emails_to_owners
- defender_ensure_system_updates_are_applied
- defender_ensure_wdatp_is_enabled
- entra
- entra_app_registration_credential_not_expired
- entra_authentication_methods_policy_strong_auth_enforced
- entra_user_with_vm_access_has_mfa
- iam
- iam_custom_role_has_permissions_to_administer_resource_locks
- iam_role_user_access_admin_restricted
- iam_subscription_roles_owner_custom_not_created
- keyvault
- keyvault_access_only_through_private_endpoints
- keyvault_key_expiration_set_in_non_rbac
- keyvault_key_rotation_enabled
- keyvault_logging_enabled
- keyvault_non_rbac_secret_expiration_set
- keyvault_private_endpoints
- keyvault_rbac_enabled
- keyvault_rbac_key_expiration_set
- keyvault_rbac_secret_expiration_set
- keyvault_recoverable
- monitor
- monitor_alert_create_policy_assignment
- monitor_alert_create_update_nsg
- monitor_alert_create_update_public_ip_address_rule
- monitor_alert_create_update_security_solution
- monitor_alert_create_update_sqlserver_fr
- monitor_alert_delete_nsg
- monitor_alert_delete_policy_assignment
- monitor_alert_delete_public_ip_address_rule
- monitor_alert_delete_security_solution
- monitor_alert_delete_sqlserver_fr
- monitor_alert_service_health_exists
- monitor_diagnostic_setting_with_appropriate_categories
- monitor_diagnostic_settings_exists
- monitor_storage_account_with_activity_logs_cmk_encrypted
- monitor_storage_account_with_activity_logs_is_private
- mysql
- mysql_flexible_server_audit_log_connection_activated
- mysql_flexible_server_audit_log_enabled
- mysql_flexible_server_geo_redundant_backup_enabled
- mysql_flexible_server_high_availability_enabled
- mysql_flexible_server_minimum_tls_version_12
- mysql_flexible_server_ssl_connection_enabled
- network
- network_bastion_host_exists
- network_flow_log_captured_sent
- network_flow_log_more_than_90_days
- network_http_internet_access_restricted
- network_public_ip_shodan
- network_rdp_internet_access_restricted
- network_ssh_internet_access_restricted
- network_subnet_nsg_associated
- network_udp_internet_access_restricted
- network_vnet_ddos_protection_enabled
- network_watcher_enabled
- policy
- policy_ensure_asc_enforcement_enabled
- postgresql
- postgresql_flexible_server_allow_access_services_disabled
- postgresql_flexible_server_connection_throttling_on
- postgresql_flexible_server_enforce_ssl_enabled
- postgresql_flexible_server_entra_id_authentication_enabled
- postgresql_flexible_server_geo_redundant_backup_enabled
- postgresql_flexible_server_high_availability_enabled
- postgresql_flexible_server_log_checkpoints_on
- postgresql_flexible_server_log_connections_on
- postgresql_flexible_server_log_disconnections_on
- postgresql_flexible_server_log_retention_days_greater_3
- recovery
- recovery_vault_backup_policy_retention_adequate
- recovery_vault_has_protected_items
- sqlserver
- sqlserver_auditing_enabled
- sqlserver_auditing_retention_90_days
- sqlserver_azuread_administrator_enabled
- sqlserver_microsoft_defender_enabled
- sqlserver_recommended_minimal_tls_version
- sqlserver_tde_encrypted_with_cmk
- sqlserver_tde_encryption_enabled
- sqlserver_unrestricted_inbound_access
- sqlserver_va_emails_notifications_admins_enabled
- sqlserver_va_periodic_recurring_scans_enabled
- sqlserver_va_scan_reports_configured
- sqlserver_vulnerability_assessment_enabled
- storage
- storage_account_key_access_disabled
- storage_account_public_network_access_disabled
- storage_blob_public_access_level_is_disabled
- storage_blob_versioning_is_enabled
- storage_cross_tenant_replication_disabled
- storage_default_network_access_rule_is_denied
- storage_default_to_entra_authorization_enabled
- storage_ensure_azure_services_are_trusted_to_access_is_enabled
- storage_ensure_encryption_with_customer_managed_keys
- storage_ensure_minimum_tls_version_12
- storage_ensure_private_endpoints_in_storage_accounts
- storage_ensure_soft_delete_is_enabled
- storage_geo_redundant_enabled
- storage_infrastructure_encryption_is_enabled
- storage_key_rotation_90_days
- storage_secure_transfer_required_is_enabled
- storage_smb_channel_encryption_with_secure_algorithm
- storage_smb_protocol_version_is_latest
- vm
- vm_backup_enabled
- vm_desired_sku_size
- vm_ensure_attached_disks_encrypted_with_cmk
- vm_ensure_unattached_disks_encrypted_with_cmk
- vm_ensure_using_approved_images
- vm_ensure_using_managed_disks
- vm_jit_access_enabled
- vm_linux_enforce_ssh_authentication
- vm_scaleset_associated_with_load_balancer
- vm_scaleset_not_empty
- vm_sufficient_daily_backup_retention_period
- vm_trusted_launch_enabled
- cloudflare
- lib
- services/zone/zone_waf_enabled
- common
- gcp
- exceptions
- services
- cloudfunction
- cloudfunction_function_inside_vpc
- cloudfunction_function_not_publicly_accessible
- cloudsql
- cloudsql_instance_cmek_encryption_enabled
- cloudsql_instance_high_availability_enabled
- compute
- iam
- iam_service_account_unused
- kms
- kms_key_rotation_enabled
- kms_key_rotation_max_90_days
- logging
- logging_log_metric_filter_and_alert_for_audit_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_bucket_permission_changes_enabled
- logging_log_metric_filter_and_alert_for_compute_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_custom_role_changes_enabled
- logging_log_metric_filter_and_alert_for_project_ownership_changes_enabled
- logging_log_metric_filter_and_alert_for_sql_instance_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_firewall_rule_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_network_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_network_route_changes_enabled
- logging_sink_created
- secretmanager
- secretmanager_secret_not_publicly_accessible
- secretmanager_secret_rotation_enabled
- googleworkspace/services
- additionalservices
- additionalservices_external_groups_disabled
- calendar
- calendar_external_invitations_warning
- calendar_external_sharing_primary_calendar
- calendar_external_sharing_secondary_calendar
- chat
- chat_apps_installation_disabled
- chat_external_file_sharing_disabled
- chat_external_messaging_restricted
- chat_external_spaces_restricted
- chat_incoming_webhooks_disabled
- chat_internal_file_sharing_disabled
- directory
- directory_super_admin_count
- directory_super_admin_only_admin_roles
- drive
- drive_access_checker_recipients_only
- drive_desktop_access_disabled
- drive_external_sharing_warn_users
- drive_internal_users_distribute_content
- drive_publishing_files_disabled
- drive_sharing_allowlisted_domains
- drive_warn_sharing_with_allowlisted_domains
- gmail
- gmail_anomalous_attachment_protection_enabled
- gmail_auto_forwarding_disabled
- gmail_comprehensive_mail_storage_enabled
- gmail_domain_spoofing_protection_enabled
- gmail_employee_name_spoofing_protection_enabled
- gmail_encrypted_attachment_protection_enabled
- gmail_enhanced_pre_delivery_scanning_enabled
- gmail_external_image_scanning_enabled
- gmail_groups_spoofing_protection_enabled
- gmail_inbound_domain_spoofing_protection_enabled
- gmail_mail_delegation_disabled
- gmail_per_user_outbound_gateway_disabled
- gmail_pop_imap_access_disabled
- gmail_script_attachment_protection_enabled
- gmail_shortener_scanning_enabled
- gmail_unauthenticated_email_protection_enabled
- gmail_untrusted_link_warnings_enabled
- groups
- groups_creation_restricted
- groups_external_access_restricted
- groups_view_conversations_restricted
- marketplace
- marketplace_apps_access_restricted
- rules
- rules_admin_privilege_granted_alert_configured
- rules_gmail_employee_spoofing_alert_configured
- rules_government_backed_attacks_alert_configured
- rules_leaked_password_alert_configured
- rules_password_changed_alert_configured
- rules_suspicious_activity_suspension_alert_configured
- rules_suspicious_login_alert_configured
- rules_suspicious_programmatic_login_alert_configured
- security
- security_2sv_enforced
- security_2sv_hardware_keys_admins
- security_advanced_protection_configured
- security_app_access_restricted
- security_dlp_drive_rules_configured
- security_internal_apps_trusted
- security_less_secure_apps_disabled
- security_login_challenges_configured
- security_password_policy_strong
- security_session_duration_limited
- security_super_admin_recovery_disabled
- security_user_recovery_enabled
- sites
- sites_service_disabled
- iac
- image
- kubernetes/services/core
- core_cpu_limits_set
- core_cpu_requests_set
- core_image_tag_fixed
- core_liveness_probe_configured
- core_memory_limits_set
- core_memory_requests_set
- core_readiness_probe_configured
- linode
- exceptions
- lib
- arguments
- mutelist
- service
- services
- administration
- administration_user_2fa_enabled
- compute
- compute_instance_backups_enabled
- compute_instance_disk_encryption_enabled
- compute_instance_watchdog_enabled
- networking
- networking_firewall_assigned_to_devices
- networking_firewall_default_inbound_policy_drop
- networking_firewall_default_outbound_policy_drop
- networking_firewall_inbound_rules_configured
- networking_firewall_outbound_rules_configured
- networking_firewall_status_enabled
- m365
- lib/powershell
- services
- admincenter
- entra
- entra_app_registration_client_secret_unused
- entra_break_glass_account_fido2_security_key_registered
- entra_conditional_access_policy_no_deleted_object_references
- entra_directory_sync_object_takeover_blocked
- entra_emergency_access_exclusion
- entra_service_principal_no_secrets_for_permanent_tier0_roles
- entra_service_principal_privileged_role_no_owners
- entra_users_mfa_capable
- exchange
- exchange_mailbox_primary_smtp_uses_custom_domain
- okta
- exceptions
- lib
- arguments
- mutelist
- service
- services
- apitoken
- apitoken_not_super_admin
- apitoken_restricted_to_network_zone
- lib
- application
- application_admin_console_mfa_required
- application_admin_console_phishing_resistant_authentication
- application_admin_console_session_idle_timeout_15min
- application_authentication_policy_network_zone_enforced
- application_dashboard_mfa_required
- application_dashboard_phishing_resistant_authentication
- lib
- authenticator
- authenticator_okta_verify_fips_compliant
- authenticator_password_common_password_check
- authenticator_password_complexity_lowercase
- authenticator_password_complexity_number
- authenticator_password_complexity_symbol
- authenticator_password_complexity_uppercase
- authenticator_password_history_5
- authenticator_password_lockout_threshold_3
- authenticator_password_maximum_age_60d
- authenticator_password_minimum_age_24h
- authenticator_password_minimum_length_15
- authenticator_smart_card_active
- lib
- idp
- idp_smart_card_dod_approved_ca
- lib
- network
- lib
- network_zone_block_anonymized_proxies
- signon
- lib
- signon_dod_warning_banner_configured
- signon_global_session_cookies_not_persistent
- signon_global_session_idle_timeout_15min
- signon_global_session_lifetime_18h
- signon_global_session_policy_network_zone_enforced
- systemlog
- lib
- systemlog_streaming_enabled
- user
- lib
- user_inactivity_automation_35d_enabled
- openstack/exceptions
- oraclecloud
- services
- audit
- identity
- identity_storage_service_level_admins_scoped
- scaleway
- exceptions
- lib
- arguments
- mutelist
- service
- services
- iam
- iam_api_keys_no_root_owned
- stackit
- exceptions
- lib
- arguments
- mutelist
- service
- services
- iaas
- iaas_security_group_all_traffic_unrestricted
- iaas_security_group_database_unrestricted
- iaas_security_group_rdp_unrestricted
- iaas_security_group_ssh_unrestricted
- objectstorage
- objectstorage_access_key_expiration
- objectstorage_bucket_object_lock_enabled
- objectstorage_bucket_retention_policy
- vercel
- scripts
- development
- skills
- django-drf
- references
- django-migration-psql
- gh-aw
- jsonapi
- nextjs-15
- nextjs-16
- playwright
- postgresql-indexing
- prowler-api
- references
- prowler-attack-paths-query
- prowler-changelog
- assets
- prowler-commit
- prowler-compliance-review
- prowler-compliance
- references
- prowler-docs
- prowler-provider
- prowler-readme-table
- prowler-sdk-check
- prowler-test-api
- references
- prowler-test-sdk
- prowler-test-ui
- prowler-tour
- assets
- references
- prowler-ui
- prowler
- react-19
- skill-creator
- assets
- tailwind-4
- tdd
- vitest
- tests
- config
- fixtures
- schema
- dashboard
- compliance
- pages
- lib
- check
- cli
- outputs
- compliance
- asd_essential_eight
- c5
- ccc
- cis
- ens
- generic
- kisa_ismsp
- mitre_attack
- okta_idaas_stig
- prowler_threatscore
- universal
- html
- jira
- ocsf
- scan
- utils
- providers
- aws
- lib/ip_ranges
- services
- acmpca
- acmpca_certificate_authority_pqc_key_algorithm
- apigateway
- apigateway_domain_name_pqc_tls_enabled
- bedrock
- bedrock_agent_role_least_privilege
- bedrock_api_key_no_long_term_credentials
- bedrock_prompt_encrypted_with_cmk
- cloudfront
- cloudfront_distributions_pqc_tls_enabled
- cloudtrail/cloudtrail_bedrock_logging_enabled
- cloudwatch
- cloudwatch_changes_to_network_acls_alarm_configured
- cloudwatch_changes_to_network_gateways_alarm_configured
- cloudwatch_changes_to_network_route_tables_alarm_configured
- cloudwatch_changes_to_vpcs_alarm_configured
- cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled
- cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled
- cloudwatch_log_metric_filter_authentication_failures
- cloudwatch_log_metric_filter_aws_organizations_changes
- cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk
- cloudwatch_log_metric_filter_for_s3_bucket_policy_changes
- cloudwatch_log_metric_filter_policy_changes
- cloudwatch_log_metric_filter_security_group_changes
- cloudwatch_log_metric_filter_sign_in_without_mfa
- codepipeline/codepipeline_project_repo_private
- config/config_delegated_admin_and_org_aggregator_all_regions
- elbv2/elbv2_alb_drop_invalid_header_fields_enabled
- iam
- iam_no_custom_policy_permissive_role_assumption
- iam_policy_allows_privilege_escalation
- iam_policy_no_full_access_to_cloudtrail
- iam_policy_no_full_access_to_kms
- iam_policy_no_wildcard_marketplace_subscribe
- iam_role_access_not_stale_to_bedrock
- iam_user_access_not_stale_to_sagemaker
- rolesanywhere
- rolesanywhere_trust_anchor_pqc_pki
- s3/s3_bucket_shadow_resource_vulnerability
- sagemaker
- sagemaker_clarify_exists
- sagemaker_domain_sso_configured
- sagemaker_models_monitor_enabled
- sagemaker_models_registry_in_use
- securityhub/securityhub_delegated_admin_enabled_all_regions
- ses
- ses_identity_dkim_enabled
- transfer
- transfer_server_pqc_ssh_kex_enabled
- azure
- lib
- mutelist
- regions
- service
- services
- aisearch/aisearch_service_public_access_level_is_disabled
- aks
- aks_cluster_auto_upgrade_enabled
- aks_cluster_azure_monitor_enabled
- aks_cluster_defender_enabled
- aks_cluster_local_accounts_disabled
- aks_cluster_rbac_enabled
- aks_clusters_created_with_private_nodes
- aks_clusters_public_access_disabled
- aks_network_policy_enabled
- apim
- apim_threat_detection_llm_jacking
- appinsights/appinsights_ensure_is_configured
- app
- app_client_certificates_on
- app_ensure_auth_is_set_up
- app_ensure_http_is_redirected_to_https
- app_ensure_java_version_is_latest
- app_ensure_php_version_is_latest
- app_ensure_python_version_is_latest
- app_ensure_using_http20
- app_ftp_deployment_disabled
- app_function_access_keys_configured
- app_function_application_insights_enabled
- app_function_ftps_deployment_disabled
- app_function_identity_is_configured
- app_function_identity_without_admin_privileges
- app_function_latest_runtime_version
- app_function_not_publicly_accessible
- app_function_vnet_integration_enabled
- app_http_logs_enabled
- app_minimum_tls_version_12
- app_register_with_identity
- containerregistry
- containerregistry_admin_user_disabled
- containerregistry_not_publicly_accessible
- containerregistry_uses_private_link
- cosmosdb
- cosmosdb_account_automatic_failover_enabled
- cosmosdb_account_backup_policy_continuous
- cosmosdb_account_firewall_use_selected_networks
- cosmosdb_account_minimum_tls_version
- cosmosdb_account_public_network_access_disabled
- cosmosdb_account_use_aad_and_rbac
- cosmosdb_account_use_private_endpoints
- databricks
- databricks_workspace_cmk_encryption_enabled
- databricks_workspace_no_public_ip_enabled
- databricks_workspace_public_network_access_disabled
- databricks_workspace_vnet_injection_enabled
- defender
- defender_additional_email_configured_with_a_security_contact
- defender_assessments_vm_endpoint_protection_installed
- defender_attack_path_notifications_properly_configured
- defender_auto_provisioning_log_analytics_agent_vms_on
- defender_auto_provisioning_vulnerabilty_assessments_machines_on
- defender_container_images_resolved_vulnerabilities
- defender_container_images_scan_enabled
- defender_ensure_defender_cspm_is_on
- defender_ensure_defender_for_app_services_is_on
- defender_ensure_defender_for_arm_is_on
- defender_ensure_defender_for_azure_sql_databases_is_on
- defender_ensure_defender_for_containers_is_on
- defender_ensure_defender_for_cosmosdb_is_on
- defender_ensure_defender_for_databases_is_on
- defender_ensure_defender_for_dns_is_on
- defender_ensure_defender_for_keyvault_is_on
- defender_ensure_defender_for_os_relational_databases_is_on
- defender_ensure_defender_for_server_is_on
- defender_ensure_defender_for_sql_servers_is_on
- defender_ensure_defender_for_storage_is_on
- defender_ensure_iot_hub_defender_is_on
- defender_ensure_mcas_is_enabled
- defender_ensure_notify_alerts_severity_is_high
- defender_ensure_notify_emails_to_owners
- defender_ensure_system_updates_are_applied
- defender_ensure_wdatp_is_enabled
- entra
- entra_authentication_methods_policy_strong_auth_enforced
- entra_user_with_vm_access_has_mfa
- iam
- iam_custom_role_has_permissions_to_administer_resource_locks
- iam_role_user_access_admin_restricted
- iam_subscription_roles_owner_custom_not_created
- keyvault
- keyvault_access_only_through_private_endpoints
- keyvault_key_expiration_set_in_non_rbac
- keyvault_key_rotation_enabled
- keyvault_logging_enabled
- keyvault_non_rbac_secret_expiration_set
- keyvault_private_endpoints
- keyvault_rbac_enabled
- keyvault_rbac_key_expiration_set
- keyvault_rbac_secret_expiration_set
- keyvault_recoverable
- monitor
- monitor_alert_create_policy_assignment
- monitor_alert_create_update_nsg
- monitor_alert_create_update_public_ip_address_rule
- monitor_alert_create_update_security_solution
- monitor_alert_create_update_sqlserver_fr
- monitor_alert_delete_nsg
- monitor_alert_delete_policy_assignment
- monitor_alert_delete_public_ip_address_rule
- monitor_alert_delete_security_solution
- monitor_alert_delete_sqlserver_fr
- monitor_alert_service_health_exists
- monitor_diagnostic_setting_with_appropriate_categories
- monitor_diagnostic_settings_exists
- monitor_storage_account_with_activity_logs_cmk_encrypted
- monitor_storage_account_with_activity_logs_is_private
- mysql
- mysql_flexible_server_audit_log_connection_activated
- mysql_flexible_server_audit_log_enabled
- mysql_flexible_server_geo_redundant_backup_enabled
- mysql_flexible_server_high_availability_enabled
- mysql_flexible_server_minimum_tls_version_12
- mysql_flexible_server_ssl_connection_enabled
- network
- network_bastion_host_exists
- network_flow_log_captured_sent
- network_flow_log_more_than_90_days
- network_http_internet_access_restricted
- network_public_ip_shodan
- network_rdp_internet_access_restricted
- network_ssh_internet_access_restricted
- network_subnet_nsg_associated
- network_udp_internet_access_restricted
- network_vnet_ddos_protection_enabled
- network_watcher_enabled
- policy/policy_ensure_asc_enforcement_enabled
- postgresql
- postgresql_flexible_server_allow_access_services_disabled
- postgresql_flexible_server_connection_throttling_on
- postgresql_flexible_server_enforce_ssl_enabled
- postgresql_flexible_server_entra_id_authentication_enabled
- postgresql_flexible_server_geo_redundant_backup_enabled
- postgresql_flexible_server_high_availability_enabled
- postgresql_flexible_server_log_checkpoints_on
- postgresql_flexible_server_log_connections_on
- postgresql_flexible_server_log_disconnections_on
- postgresql_flexible_server_log_retention_days_greater_3
- recovery
- recovery_vault_backup_policy_retention_adequate
- recovery_vault_has_protected_items
- sqlserver
- sqlserver_auditing_enabled
- sqlserver_auditing_retention_90_days
- sqlserver_azuread_administrator_enabled
- sqlserver_microsoft_defender_enabled
- sqlserver_recommended_minimal_tls_version
- sqlserver_tde_encrypted_with_cmk
- sqlserver_tde_encryption_enabled
- sqlserver_unrestricted_inbound_access
- sqlserver_va_emails_notifications_admins_enabled
- sqlserver_va_periodic_recurring_scans_enabled
- sqlserver_va_scan_reports_configured
- sqlserver_vulnerability_assessment_enabled
- storage
- storage_account_key_access_disabled
- storage_account_public_network_access_disabled
- storage_blob_public_access_level_is_disabled
- storage_blob_versioning_is_enabled
- storage_cross_tenant_replication_disabled
- storage_default_network_access_rule_is_denied
- storage_default_to_entra_authorization_enabled
- storage_ensure_azure_services_are_trusted_to_access_is_enabled
- storage_ensure_encryption_with_customer_managed_keys
- storage_ensure_minimum_tls_version_12
- storage_ensure_private_endpoints_in_storage_accounts
- storage_ensure_soft_delete_is_enabled
- storage_geo_redundant_enabled
- storage_infrastructure_encryption_is_enabled
- storage_key_rotation_90_days
- storage_secure_transfer_required_is_enabled
- storage_smb_channel_encryption_with_secure_algorithm
- storage_smb_protocol_version_is_latest
- vm
- vm_backup_enabled
- vm_desired_sku_size
- vm_ensure_attached_disks_encrypted_with_cmk
- vm_ensure_unattached_disks_encrypted_with_cmk
- vm_ensure_using_approved_images
- vm_ensure_using_managed_disks
- vm_jit_access_enabled
- vm_linux_enforce_ssh_authentication
- vm_scaleset_associated_with_load_balancer
- vm_scaleset_not_empty
- vm_sufficient_daily_backup_retention_period
- vm_trusted_launch_enabled
- cloudflare/services/zone/zone_waf_enabled
- external
- gcp
- services
- cloudfunction
- cloudfunction_function_inside_vpc
- cloudfunction_function_not_publicly_accessible
- cloudsql
- cloudsql_instance_cmek_encryption_enabled
- cloudsql_instance_high_availability_enabled
- compute
- iam/iam_service_account_unused
- kms
- kms_key_rotation_enabled
- kms_key_rotation_max_90_days
- logging
- logging_log_metric_filter_and_alert_for_audit_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_bucket_permission_changes_enabled
- logging_log_metric_filter_and_alert_for_compute_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_custom_role_changes_enabled
- logging_log_metric_filter_and_alert_for_project_ownership_changes_enabled
- logging_log_metric_filter_and_alert_for_sql_instance_configuration_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_firewall_rule_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_network_changes_enabled
- logging_log_metric_filter_and_alert_for_vpc_network_route_changes_enabled
- logging_sink_created
- secretmanager
- secretmanager_secret_not_publicly_accessible
- secretmanager_secret_rotation_enabled
- googleworkspace/services
- additionalservices
- additionalservices_external_groups_disabled
- calendar
- calendar_external_invitations_warning
- calendar_external_sharing_primary_calendar
- calendar_external_sharing_secondary_calendar
- chat
- chat_apps_installation_disabled
- chat_external_file_sharing_disabled
- chat_external_messaging_restricted
- chat_external_spaces_restricted
- chat_incoming_webhooks_disabled
- chat_internal_file_sharing_disabled
- directory
- directory_super_admin_count
- directory_super_admin_only_admin_roles
- drive
- drive_access_checker_recipients_only
- drive_desktop_access_disabled
- drive_external_sharing_warn_users
- drive_internal_users_distribute_content
- drive_publishing_files_disabled
- drive_sharing_allowlisted_domains
- drive_warn_sharing_with_allowlisted_domains
- gmail
- gmail_anomalous_attachment_protection_enabled
- gmail_auto_forwarding_disabled
- gmail_comprehensive_mail_storage_enabled
- gmail_domain_spoofing_protection_enabled
- gmail_employee_name_spoofing_protection_enabled
- gmail_encrypted_attachment_protection_enabled
- gmail_enhanced_pre_delivery_scanning_enabled
- gmail_external_image_scanning_enabled
- gmail_groups_spoofing_protection_enabled
- gmail_inbound_domain_spoofing_protection_enabled
- gmail_mail_delegation_disabled
- gmail_per_user_outbound_gateway_disabled
- gmail_pop_imap_access_disabled
- gmail_script_attachment_protection_enabled
- gmail_shortener_scanning_enabled
- gmail_unauthenticated_email_protection_enabled
- gmail_untrusted_link_warnings_enabled
- groups
- groups_creation_restricted
- groups_external_access_restricted
- groups_view_conversations_restricted
- marketplace
- marketplace_apps_access_restricted
- rules
- rules_admin_privilege_granted_alert_configured
- rules_gmail_employee_spoofing_alert_configured
- rules_government_backed_attacks_alert_configured
- rules_leaked_password_alert_configured
- rules_password_changed_alert_configured
- rules_suspicious_activity_suspension_alert_configured
- rules_suspicious_login_alert_configured
- rules_suspicious_programmatic_login_alert_configured
- security
- security_2sv_enforced
- security_2sv_hardware_keys_admins
- security_advanced_protection_configured
- security_app_access_restricted
- security_dlp_drive_rules_configured
- security_internal_apps_trusted
- security_less_secure_apps_disabled
- security_login_challenges_configured
- security_password_policy_strong
- security_session_duration_limited
- security_super_admin_recovery_disabled
- security_user_recovery_enabled
- sites
- sites_service_disabled
- iac
- image
- kubernetes/services/core
- core_cpu_limits_set
- core_cpu_requests_set
- core_image_tag_fixed
- core_liveness_probe_configured
- core_memory_limits_set
- core_memory_requests_set
- core_readiness_probe_configured
- linode
- lib/mutelist
- fixtures
- services
- administration
- administration_user_2fa_enabled
- compute
- compute_instance_backups_enabled
- compute_instance_disk_encryption_enabled
- compute_instance_watchdog_enabled
- networking
- networking_firewall_assigned_to_devices
- networking_firewall_default_inbound_policy_drop
- networking_firewall_default_outbound_policy_drop
- networking_firewall_inbound_rules_configured
- networking_firewall_outbound_rules_configured
- networking_firewall_status_enabled
- m365
- lib/powershell
- services
- admincenter
- entra
- entra_app_registration_client_secret_unused
- entra_break_glass_account_fido2_security_key_registered
- entra_conditional_access_policy_no_deleted_object_references
- entra_directory_sync_object_takeover_blocked
- entra_emergency_access_exclusion
- entra_managed_device_required_for_authentication
- entra_service_principal_no_secrets_for_permanent_tier0_roles
- entra_service_principal_privileged_role_no_owners
- entra_users_mfa_capable
- exchange
- exchange_mailbox_primary_smtp_uses_custom_domain
- okta
- exceptions
- lib
- arguments
- mutelist
- fixtures
- service
- services
- api_token
- apitoken_not_super_admin
- apitoken_restricted_to_network_zone
- application
- application_admin_console_mfa_required
- application_admin_console_phishing_resistant_authentication
- application_admin_console_session_idle_timeout_15min
- application_authentication_policy_network_zone_enforced
- application_dashboard_mfa_required
- application_dashboard_phishing_resistant_authentication
- authenticator
- authenticator_okta_verify_fips_compliant
- authenticator_password_common_password_check
- authenticator_password_complexity_lowercase
- authenticator_password_complexity_number
- authenticator_password_complexity_symbol
- authenticator_password_complexity_uppercase
- authenticator_password_history_5
- authenticator_password_lockout_threshold_3
- authenticator_password_maximum_age_60d
- authenticator_password_minimum_age_24h
- authenticator_password_minimum_length_15
- authenticator_smart_card_active
- idp
- idp_smart_card_dod_approved_ca
- network_zone
- network_zone_block_anonymized_proxies
- signon
- signon_dod_warning_banner_configured
- signon_global_session_cookies_not_persistent
- signon_global_session_idle_timeout_15min
- signon_global_session_lifetime_18h
- signon_global_session_policy_network_zone_enforced
- systemlog
- systemlog_streaming_enabled
- user
- user_inactivity_automation_35d_enabled
- openstack
- oraclecloud
- services
- audit
- identity
- identity_storage_service_level_admins_scoped
- scaleway
- services/iam
- iam_api_keys_no_root_owned
- stackit
- lib
- arguments
- mutelist
- services
- iaas
- iaas_security_group_all_traffic_unrestricted
- iaas_security_group_database_unrestricted
- iaas_security_group_rdp_unrestricted
- iaas_security_group_ssh_unrestricted
- objectstorage
- objectstorage_access_key_expiration
- objectstorage_bucket_object_lock_enabled
- objectstorage_bucket_retention_policy
- vercel
- ui
- .husky
- __tests__
- msw
- handlers
- actions
- attack-paths
- auth
- compliances
- finding-groups
- findings
- integrations
- overview/regions
- providers
- resources
- roles
- scans
- schedules
- task
- app
- (auth)
- alerts
- confirm
- unsubscribe
- invitation
- _lib
- accept
- (prowler)
- _overview
- _components
- graphs-tabs
- risk-pipeline-view
- risk-plot
- alerts
- _actions
- _components
- __tests__
- _lib
- __tests__
- _types
- attack-paths
- (workflow)/query-builder
- _components
- graph
- nodes
- node-detail
- _hooks
- _lib
- compliance
- [compliancetitle]
- findings
- integrations
- amazon-s3
- aws-security-hub
- providers
- resources
- scans
- users
- api
- health
- scans/[scanId]/report
- components
- auth/oss
- compliance
- compliance-accordion
- compliance-charts
- compliance-custom-details
- compliance-header
- filters
- findings
- table
- resource-detail-drawer
- graphs
- icons
- compliance
- providers-badge
- integrations
- s3
- saml
- security-hub
- onboarding
- __tests__
- providers
- organizations
- table
- wizard
- hooks
- steps
- workflow/forms
- via-credentials
- resources
- table
- roles/workflow/forms
- runtime-config
- scans
- forms
- launch-workflow
- schedule
- table
- __tests__
- cells
- scans
- shadcn
- badge
- button
- card
- field
- file-upload
- input
- modal
- radio-group
- section
- select
- stacked-cell
- tabs
- textarea
- ui
- accordion
- breadcrumbs
- button
- content-layout
- entities
- form
- main-layout
- sidebar
- table
- toast
- users
- profile
- table
- docs/code-review
- hooks
- lib
- compliance
- lighthouse
- onboarding
- __tests__
- provider-credentials
- tours
- __tests__
- store
- public
- scripts
- sentry
- store
- __tests__
- scans
- styles
- tests
- auth
- home
- invitation-accept
- invitations
- providers
- runtime-config
- scans
- setups
- sign-in-base
- sign-up
- types
- util/prowler-bulk-provisioning
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | 8 | | |
10 | 9 | | |
11 | | - | |
| 10 | + | |
12 | 11 | | |
13 | | - | |
| 12 | + | |
14 | 13 | | |
15 | | - | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
16 | 22 | | |
17 | 23 | | |
18 | | - | |
| 24 | + | |
19 | 25 | | |
20 | 26 | | |
21 | 27 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
| 11 | + | |
| 12 | + | |
10 | 13 | | |
| 14 | + | |
11 | 15 | | |
12 | 16 | | |
13 | 17 | | |
14 | 18 | | |
15 | | - | |
| 19 | + | |
| 20 | + | |
16 | 21 | | |
| 22 | + | |
17 | 23 | | |
18 | 24 | | |
19 | 25 | | |
| |||
139 | 145 | | |
140 | 146 | | |
141 | 147 | | |
142 | | - | |
143 | | - | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
144 | 153 | | |
145 | | - | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
146 | 158 | | |
147 | 159 | | |
148 | | - | |
| 160 | + | |
149 | 161 | | |
150 | 162 | | |
151 | 163 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
5 | 4 | | |
6 | 5 | | |
7 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
This file was deleted.
0 commit comments