If you've never heard of Prowler, you're not alone. I built my own AWS security scanner before I stumbled across it. Read the landing page, had a quiet moment of what is this, and realised it was basically the scan engine I had spent weeks building from scratch. It's open source, free, covers every major AWS finding category, and maps everything to compliance frameworks out of the box. It is one of the most underrated tools in cloud security.
So run it. Seriously, if you haven't, stop reading and go run it now.
Come back when you have your 400 findings.
The problem isn't Prowler. It's what happens after.
You run the scan. You get the report. You open it.
Four hundred findings stare back at you. Some are CRITICAL. Some are HIGH. Some are things you've never heard of. Some are probably fine. Some are definitely not fine. You don't know which is which.
So you do what everyone does. You close the tab and tell yourself you'll come back to it.
Three months later, you have
Discussion
Say something first
It all starts with you—share your thoughts now.