What’s New in Prowler: July 2026

Summer is moving fast, and so are we. Over the last few weeks, we shipped a smarter Lighthouse AI experience, brought Prowler to Claude Code with a remote MCP Server and plugin, made AWS onboarding a one-click affair, unified compliance across providers, and expanded coverage to your identity layer with Okta.
We’re also heading to Las Vegas for Black Hat. If you’ll be there, come find us at booth 5913.
Here’s what’s new in Prowler.
💡 Lighthouse AI: Your Agentic Cloud Defender
More reasoning, more context, and a much smoother conversation.
Lighthouse AI in Prowler Cloud now runs on GPT-5.6 Terra by default, bringing stronger reasoning and tool calling to every investigation. You can watch the agent work in real time, with tool calls and reasoning steps rendered as they happen, and pick between the classic dashboard view or a chat-first agentic interface.
Lighthouse can now do a lot more than answer questions. It can search and summarize findings, inspect resource configurations and CloudTrail timelines, review compliance status, run attack path queries, trigger and schedule scans, manage provider connections, and create mute rules with full audit trails. Persistent chat sessions let you resume any investigation, and a side panel keeps Lighthouse one click away from every page. Access to your cloud environments stays strictly read-only.
Add shared business context, like priorities, compliance requirements, and ownership details, and Lighthouse feels less like a blank chat box and more like a teammate who already knows the environment.
👉 Explore the new Lighthouse AI capabilities →
🤖 Bring Prowler Into Claude Code
A remote MCP Server and a Prowler Plugin, available in Prowler Cloud only.

The new remote MCP Server connects your AI tools directly to Prowler Cloud, and the Prowler Plugin for Claude Code turns those connections into an automated security triage workflow. Describe a goal in plain language, like “make my AWS production account compliant with CIS 4.0,” and the plugin pulls your failing checks, prioritizes them by severity, compliance impact, and attack path blast radius, then drives the fix.
It can remediate through infrastructure-as-code or cloud CLIs, open pull requests that fit your existing review workflow, and trigger fresh scans to confirm findings actually cleared, with progress tracked in auditable markdown reports.
👉 Read about the Prowler Plugin for Claude Code →
⚡ One-Click AWS Onboarding
Onboarding an entire AWS Organization used to mean setting up an IAM role in every single account. Now, available in Prowler Cloud only, you can launch a single CloudFormation stack in your management account and let a StackSet automatically roll the Prowler scan role out to every member account, organizational units included.
One click, your whole organization connected, and every account ready to scan.
🎯 Finding Triage & Scan Configurations
A structured triage lifecycle and reusable scan configs, available in Prowler Cloud.
Findings now move through a proper triage lifecycle: Open, Under Review, Remediating, Risk Accepted, False Positive, and Resolved. Update statuses and add triage notes right from finding tables and side drawers, and let Prowler do the bookkeeping. When a finding flips from failing to passing, it automatically moves to Resolved, and if it regresses, it shows up as Reopened.
We also gave you more control over how scans run:
- Scan Configurations: create named, reusable configurations that override just the settings you need, validated against a provider-specific schema before saving, and attach them to one or more providers
- Schedule scans per provider or set them up in bulk across an organization
- Filter by provider group across Overview, Findings, Resources, Scans, and Providers
Less tab hopping, fewer repetitive setup steps, and a cleaner path from finding to action.
🔑 Stronger Secret Detection, With Fewer False Alarms
Prowler’s secret scanning now uses Kingfisher, a fast, offline engine that filters obvious placeholder values before they become noise. If you opt in to live validation, Prowler can check discovered credentials against provider APIs and mark confirmed live secrets as critical.
We also added coverage for hardcoded secrets in API Gateway stage variables, plus optional spot checks for publicly accessible S3 objects. And for teams building on Amazon Bedrock AgentCore, Prowler now detects additional IAM privilege escalation paths across Runtime, Harness, Code Interpreter, and Custom Browser.
This is the kind of signal security teams need: fewer placeholders, clearer severity, and more confidence about what needs attention first.
🌐 Cross-Provider Compliance: One Posture, All Your Clouds
Available in Prowler Cloud.
The new Cross-provider compliance tab aggregates the most recent scans from all your compatible providers into a single compliance posture per framework, with per-provider breakdowns and a combined executive PDF. Requirement status follows strict precedence, so if one provider fails a requirement, it is flagged across your entire infrastructure. No more assembling spreadsheets to answer “are we compliant?”
Three universal frameworks support it today: CIS Controls 8.1 (across 14 providers including AWS, Azure, Google Cloud, Kubernetes, GitHub, and Okta), CSA CCM 4.0, and DORA. Filter by provider type, account, or provider group, and export a consolidated report in one click.
👉 See what shipped in Prowler 5.34.0 →
📋 A Big Compliance Coverage Refresh
The biggest addition is CIS Controls v8.1, mapped across 18 Prowler providers. That gives teams a consistent way to measure safeguards across cloud, identity, SaaS, Kubernetes, and more.
We also added the latest CIS Foundations benchmarks for:
- AWS v7.0.0
- Microsoft Azure v6.0.0
- Google Cloud v5.0.0
- Microsoft 365 v7.0.0
- Kubernetes v2.0.1
- GitHub v1.2.0
DORA coverage now spans AWS, Azure, Google Cloud, Alibaba Cloud, and Cloudflare, and Okta teams can use the DISA Okta IDaaS STIG V1R2 framework out of the box.
👉 Read the compliance updates →
☁️ More Clouds, More Checks

Your identity layer is the new perimeter. Prowler now scans Okta with 29 checks mapped to the DISA Okta IDaaS STIG, covering session policies, MFA enforcement for admin consoles, password and lockout rules, API token network restrictions, and log streaming. It connects via OAuth 2.0 machine-to-machine authentication with strictly read-only, scoped permissions, so there is no human login and no password to store.
👉 Read why identity is the new perimeter →
We also added support for VMware Cloud Foundation (VCF), available in Prowler Private Cloud, and Linode is now a supported provider, with coverage across compute, networking, and administration services.
We also expanded the checks that help teams catch high-impact gaps:
- Azure: stronger coverage for AKS, Cosmos DB, Databricks, Entra ID, backups, databases, network exposure, and DDoS protection
- Google Cloud: public Cloud Functions and Secret Manager access, secret rotation, VPC connectivity, and Cloud SQL high availability
- Kubernetes: CPU and memory requests and limits, fixed image tags, liveness probes, and readiness probes
- AWS: post-quantum readiness checks for CloudFront, API Gateway, Transfer Family, Private CA, and IAM Roles Anywhere
👉 See the full coverage in Prowler 5.31.0 →
📍 Meet Prowler at Black Hat USA

We’re bringing the Prowler team to Las Vegas, August 4–6 at the Mandalay Bay Convention Center. Stop by booth 5913 for a live demo, talk through your cloud security challenges, see what’s coming next, or just say hi. Catch our CEO on the Global Startup Spotlight main stage, and join us for a cocktail evening hosted with Chainloop.
⚡ That’s a Wrap
Thanks for being part of the Prowler community. Ready to see these updates in action? Try Prowler Cloud free →




.avif)

.avif)
















