Connectors
Prowler
Vulnerability management: cloud accounts scanned against CIS/security benchmarks, with open critical/high findings surfaced.
What it covers
Vulnerability management: cloud accounts scanned against CIS/security benchmarks, with open critical/high findings surfaced.
Credential to create
Prowler App API key
Permissions to grant
- Reads findings (status + severity) - the key grants the creator's access level
Setup steps
- In Prowler Cloud, run a scan on the cloud account(s) you want covered.
- Create an API key: Profile > Account > Create API Key (copy it immediately - it is shown only once).
- On the Integrations page, paste the key. Leave the base URL blank for Prowler Cloud, or set it to your instance for a self-hosted Prowler App.
Notes and gotchas
- The control passes when Prowler reports zero open critical/high findings across the connected accounts.
- The key authenticates as 'Authorization: Api-Key <key>'; it defaults to a 1-year expiry and has the creator's access level, so scope the creating user to read-only if possible.