-
Notifications
You must be signed in to change notification settings - Fork 2k
Description
Feature search
- I have searched the existing issues and this feature has not been requested yet or is already in our Public Roadmap
Which component would this feature affect?
Prowler Dashboard
Related to specific cloud provider?
Not provider-specific
New feature motivation
Motivation
- Prowler provides a dashboard for diving into individual findings across multi-account AWS environments.
- However, when dealing with high volumes of findings, it becomes difficult to get an executive summary.
- The Prowler dashboard started using the CLI command
prowler dashboardis slow to load in the browser and takes sometime to refresh. Also findings are repeated across regions in the same tabular display.
Feature Ask
This feature should be integrated with the native Prowler CLI.
Solution Proposed
To overcome this issue, a reference implementation has been built prowler-scan-insights. This tool addresses that need by providing high-level analytics and actionable insights. Currently it has been tested with Prowler output generated against an AWS environment. However it can easily be extended to other CSPs as well.
The proposed solution can be implemented as a HTML or PDF report as well.
Note - that the security scores implemented on this tool can definitely be updated to utilize other scoring mechanisms. This is just an initial attempt.
Use case and benefits
Executive-Level Clarity: While Prowler's native dashboard excels at drilling into individual findings, it struggles with high-volume environments. This tool fills that gap by transforming overwhelming detailed findings into actionable executive summaries with security scores, risk analytics, and prioritized recommendations—making it possible for leadership to understand security posture at a glance.
Operational Efficiency: The solution automates the analysis of multi-account AWS security scans and generates self-contained, HTML report that can be shared without external dependencies. This streamlines security reporting workflows, eliminates manual data aggregation, and provides real-time filtering capabilities that help security teams quickly identify patterns across accounts, services, and severity levels.
Describe alternatives you've considered
N/A
Additional context
[Prowler-Insights-Report](https://raw.githubusercontent.com/agasthik/prowler-scan-insights/refs/heads/main/sample-scan-insights/prowler_dashboard_screenshot.png
)
Adding @toniblyx for visibility