Sign up for Prowler Updates
Scanner updated to Prowler 3.11.0 with new features
New features to highlight in this version:
π·οΈ STS V2 Tokens (this will be in the SaaS immediately, so more regions may appear with findings)
- Now Prowler will call Regional AWS STS endpoints to get session tokens valid in all AWS Regions.
See more in https://docs.prowler.cloud/en/latest/tutorials/aws/role-assumption/#sts-endpoint-region
β New 9 checks for AWS! (this will be in the SaaS immediately, so more findings may appear)
- New Account check
account_maintain_different_contact_details_to_security_billing_and_operations
- New CloudTrail check
cloudtrail_multi_region_enabled_logging_management_events
- New EC2 DataLifecycle Manager service and check
dlm_ebs_snapshot_lifecycle_policy_exists
- New EC2 EBS check
ec2_ebs_volume_snapshots_exists
- New DocumentDB service and check
documentdb_instance_storage_encrypted
- New Support check
trustedadvisor_premium_support_plan_subscribed
- New Neptune service and check
neptune_uses_a_public_subnet
- New Elasticache service and check
elasticache_using_public_subnets
- New IAM check
iam_use_temporary_credentials
π Ignore Findings from services not in actual use (this will be a roll out in the SaaS over the next weeks)
- Prowler now allows you to ignore unused services findings, so you can reduce the number of findings in Prowler’s reports.
prowler <provider> --ignore-unused-services
See more in https://docs.prowler.cloud/en/latest/tutorials/ignore-unused-services/
βοΈ New AWS Allowlist including AWS Control Tower resources (this will be nn the SaaS as a UI feature in a month)
- New allowlist file that ensures that applies to all resources created by AWS Control Tower when setting up a landing zone:
prowler aws --allowlist prowler/config/aws_allowlist.yaml
See more in https://docs.prowler.cloud/en/latest/tutorials/allowlist/#default-aws-allowlist
More details here https://github.com/prowler-cloud/prowler/releases/tag/3.11.0
Recent Articles
Securing Your Amazon Bedrock Environments With Prowler
The following guidance and new Prowler checks for Bedrock are designed to combat the risks of data leakage via logs from AWS Bedrock environments.
Mastering Multi-Cloud Security with Prowler 5
Managing security across multiple cloud platforms shouldnβt feel like a never-ending headache. Thatβs where Prowler 5 comes in. With its unified, open-source approach, Prowler 5 makes securing AWS, Azure, GCP,...
Seamless Security for Every Cloud with Prowler 5
TL;DR: Prowler 5 is now available. Sign up today to use Prowler to secure every cloud, in the SaaS or the CLI.