Prowler already does the scan
Prowler is the open-source AWS (and multi-cloud) misconfiguration scanner. Hundreds of checks, CIS and friends, HTML/CSV/JSON out. If you only need a point-in-time audit, run it locally and stop there:
pip install prowler
prowler aws -M html csv
The HTML file is the report. That is enough for a one-off. The pain starts when you want it every week without opening a laptop.
Schedule it yourself
A common pattern: CodeBuild (or a small Fargate/Lambda job) runs Prowler on a schedule, writes HTML/CSV to S3, and emails a presigned link or the HTML via SES. EventBridge Scheduler is the cron. AWS even has a multi-account Prowler pattern.
You will also need:
- A cross-account (or same-account) role Prowler can assume, scoped to SecurityAudit-ish read-only.
- SES out of the sandbox, with a verified
From. - Somewhere to put HTML that is too big for an email body (S3 + link is saner than stuffing MIME).
- A pin or image rebuild so last month’s Prowler is not what runs next month.
- Time, when a check breaks on a new AWS API or you add a second account.
None of that is hard. All of it is easy to stop maintaining. The “I will cron Prowler this weekend” thread is how a lot of accounts go a year between scans.
Prowler Cloud vs running it
Prowler also sells a hosted product (dashboard, alerts, SSO, Jira). That is the right upgrade if you want Prowler’s UI and you will live in it. It is a different product from “email me failed checks.” Read their pricing yourself before you assume OSS is free once you count the pipeline.
Where PostureRadar fits
PostureRadar is for the person who wanted the Prowler email, not the Prowler platform. You deploy one read-only CloudFormation role. We scan every enabled region and email the report, weekly, for $39 per AWS account per month, with specific remediation guidance (console + CLI) on most findings. No dashboard, no archive, cancel anytime.
Use Prowler OSS if you like owning the CLI. Use Hub/Config if you already operate that queue — know the noise and the Config bill first. Use us if the report in your inbox was the whole point.
Related: Public S3 buckets · Stale IAM access keys
