Solutions Engineer at a media company with 1,001-5,000 employees
MSP
Top 20
Jul 6, 2026
Prowler is open source and easy for me to access. I know there are many other tools such as Trend Micro or Trivy. Trivy is open source as well, but because I always use it for my POC environment, I definitely want a route that does not require spending money and at the same time can perform well as a compliance tool compared to the rest of the tools that have to be purchased. I understand that Prowler updates their checks quite frequently. Sometimes it might be a user issue because we always pull from the latest version. However, because we are using the latest version, it involves issue fixes for existing checks and also new introduced checks. All these new introduced checks sometimes come as a surprise for us because all these configurations might be new and we have to take time to review whether they are applicable to us or not. If a check is not applicable to us, we spend more time to review all these configurations that are not for us. For example, if Prowler released 10 to 20 checks, we have to spend more time to analyze if each one is applicable to us or not.
For the reports, Prowler does not provide PDF reports for all compliances; it only gives reports for the Prowler configuration. Prowler could include PDFs for all the compliances, which would be super useful for users.One feature Prowler can improve is providing PDFs for all the compliances, which would be very useful for users. Also, after identifying misconfigurations, Prowler should have a remediate button so that when using Prowler, we can apply those fixes automatically without going to the cloud and fixing them manually.
Some of the findings in Prowler are not that critical but come in the critical category, so that could be improved. The categorization of vulnerabilities could be improved.
Prowler offers comprehensive capabilities for automated compliance checking and security assessments, making it an indispensable tool in maintaining robust cloud environments.With a focus on security, Prowler provides detailed audits of cloud infrastructure to help organizations identify vulnerabilities and ensure compliance. Its ability to generate thorough reports streamlines the process of maintaining secure and compliant systems, catering to the needs of security-conscious...
Prowler is open source and easy for me to access. I know there are many other tools such as Trend Micro or Trivy. Trivy is open source as well, but because I always use it for my POC environment, I definitely want a route that does not require spending money and at the same time can perform well as a compliance tool compared to the rest of the tools that have to be purchased. I understand that Prowler updates their checks quite frequently. Sometimes it might be a user issue because we always pull from the latest version. However, because we are using the latest version, it involves issue fixes for existing checks and also new introduced checks. All these new introduced checks sometimes come as a surprise for us because all these configurations might be new and we have to take time to review whether they are applicable to us or not. If a check is not applicable to us, we spend more time to review all these configurations that are not for us. For example, if Prowler released 10 to 20 checks, we have to spend more time to analyze if each one is applicable to us or not.
For the reports, Prowler does not provide PDF reports for all compliances; it only gives reports for the Prowler configuration. Prowler could include PDFs for all the compliances, which would be super useful for users.One feature Prowler can improve is providing PDFs for all the compliances, which would be very useful for users. Also, after identifying misconfigurations, Prowler should have a remediate button so that when using Prowler, we can apply those fixes automatically without going to the cloud and fixing them manually.
Some of the findings in Prowler are not that critical but come in the critical category, so that could be improved. The categorization of vulnerabilities could be improved.