ENNAENNA

Checkov vs Prowler

GitHub Stats

8.6k
Stars
13.6k
1.3k
Forks
2.1k
157
Issues
220
3d ago
Updated
3d ago
Apache-2.0
License
Apache-2.0
Python
Language
Python

About Checkov

Checkov is a static analysis tool developed by Bridgecrew (now Palo Alto Networks) that scans infrastructure-as-code files for security misconfigurations and compliance violations across Terraform, CloudFormation, Kubernetes manifests, Helm charts, ARM templates, and Serverless framework configurations. It ships with over 1,000 built-in policies covering AWS, Azure, GCP, and Kubernetes security best practices, and supports custom policies written in Python or YAML. Cloud security engineers, DevOps teams, and compliance officers use Checkov to prevent cloud misconfigurations before deployment by integrating it into CI/CD pipelines as a pre-commit or build-stage gate. The tool also scans container images and open-source package dependencies, providing a comprehensive shift-left security solution for organizations adopting infrastructure-as-code practices.

About Prowler

Prowler is a cloud security assessment tool that performs over 300 checks against AWS, Azure, GCP, and Kubernetes infrastructures. Aligning with CIS benchmarks, it evaluates cloud environments for compliance and security vulnerabilities. Prowler is a critical resource for cloud security practitioners and auditors aiming to enhance the security posture of their cloud deployments through comprehensive and automated assessments.

Platform Support

๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows
๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows

Tags

Checkov only

iacterraformcloudformationcompliance

Prowler only

cloud-securityawsazuregcpcis-benchmark