Misconfigurations with evidence, guidance and score history
Cloud accounts change faster than any documentation. A storage bucket is opened for a test, a role widened for a migration, an exception set for a weekend. It is rarely rolled back. CSPM therefore checks accounts continuously against a catalog: Entra ID and M365 via Microsoft Graph, Azure via the ARM API, AWS via the SDK, Google Cloud and OTC via their respective REST interfaces, everything else via the Prowler import. Every violation becomes a finding with a severity, the excerpt of the API response as evidence and guidance for portal, CLI and Terraform. All access is read-only. The module changes nothing in your cloud.
Reader role, SecurityAudit policy, Graph read scopes. The module deliberately performs no automatic remediation and provides the instructions instead. A tool that assesses your cloud should not also be allowed to change it.
2
Context decides the severity
Four factors per resource: internet-exposed, privileged, sensitive data, unencrypted. Only their combination raises a finding, and by exactly one level. The catalog severity remains visible alongside, together with the rule that raised it.
3
Works without outbound access
Instances without internet access run the module entirely through the Prowler import: Prowler runs on your side, the OCSF result arrives by upload or API. Unknown checks register themselves in the catalog along the way.
4
Exception instead of "accepted"
An accepted finding stays visibly open. Only an exception with justification, scope and optional expiry removes the check from the score denominator. It remains visible as its own metric and in the auditor PDF, and once it expires a daily job closes it again.
Capabilities
All capabilities at a glance
Native collectors for Entra ID/M365, Azure, AWS, Google Cloud and OTC/OpenStack
Prowler import (OCSF) for any further provider, by upload or API
"Test connection" checks each permission step separately and names missing rights
Findings with evidence from the API response and guidance for portal, CLI and Terraform
Context factors per resource, raised only on combination and only by one level
Rule editor: context rules are data and can be changed per instance
Deduplicated per account, check and resource, with first and last sighting
Automatic closing only after a complete run, never on partial API failures
Exceptions with justification, scope, expiry and optional four-eyes approval
Compliance view per framework, BSI C5 first, plus ISO 27001, NIS2 and DORA
Immutable score snapshots per run, overall and per framework
Cockpit with score history, severity distribution and sync health of all accounts
The tenant Microsoft Secure Score is imported and tracked with every run
Create a measure, task or exception directly from any finding
Auditor PDF, ASM correlation, drift timeline and Checkov import
Result
A score that discloses how it is calculated, and a list whose order can be justified.
Experience CSPM – Cloud Configuration live
Schedule a no-obligation demo – we will show you the module with your own use cases.