Topics

Prowler and CSPM on AWS

Continuous posture assessment with the open-source scanner — setup, scoring, and turning findings into a plan.

These four lessons cover Prowler from install to what to do with the output. Start with the 2026 setup for CLI and Prowler Cloud, which skips the dead ends in older tutorials written before Prowler 5's unified multi-cloud platform. ThreatScore, introduced in Prowler 5.6, is the risk-weighted score that replaces "count the red checks" with something closer to actual exposure.

The real work starts after the scan. Triaging 500 findings into an executable plan is the step most tutorials skip — a scan is a result, not a plan. And because Prowler isn't the only posture tool in an AWS account, Prowler vs Security Hub vs Config conformance packs settles which one to use for which job, specifically when the goal is CPS 234 audit evidence rather than just a dashboard.

Read in the order above — setup, scoring, triage, then positioning against the other AWS-native tools — and you go from a first scan to a defensible plan without the dead ends the older tutorials leave in.

Lessons

Common questions

Is Prowler free?
The CLI is open source and free. Prowler Cloud is a hosted product with a free tier.