> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/prowler-scanner-reference.md).

# Prowler step configuration

You can scan your configurations and ingest results from [Prowler](https://github.com/prowler-cloud/prowler). The default workflow is to add a Prowler step to a Build or Security stage and configure it as described below.

### Important notes for running Prowler scans in STO <a href="#important-notes-for-running-prowler-scans-in-sto" id="important-notes-for-running-prowler-scans-in-sto"></a>

#### Root access requirements <a href="#root-access-requirements" id="root-access-requirements"></a>

#### For more information <a href="#for-more-information" id="for-more-information"></a>

### Prowler step settings for STO <a href="#prowler-step-settings-for-sto" id="prowler-step-settings-for-sto"></a>

#### Scan <a href="#scan" id="scan"></a>

**Scan Mode**

**Scan Configuration**

Select the [compliance framework](https://github.com/prowler-cloud/prowler/blob/master/docs/tutorials/compliance.md) to apply when running the scan:

* **Default**
* **Hipaa**
* **GDPR**
* **Exclude Extras**

#### Target <a href="#target" id="target"></a>

**Type**

**Name**

**Variant**

**Workspace**

#### Authentication <a href="#authentication" id="authentication"></a>

Settings for the AWS account to use when running an orchestration scan.

**Access ID**

**Access Token**

**Access Region**

The AWS region of the configuration to scan.

#### Ingestion file <a href="#ingestion-file" id="ingestion-file"></a>

#### Log Level <a href="#log-level" id="log-level"></a>

#### Additional CLI flags <a href="#additional-cli-flags" id="additional-cli-flags"></a>

You can use this field to run the [prowler scanner](https://github.com/prowler-cloud/prowler) with specific command-line arguments. For example, this argument excludes specific checks from a scan:

`-excluded-checks s3_bucket_public_access`

#### Fail on Severity <a href="#fail-on-severity" id="fail-on-severity"></a>

#### Settings <a href="#settings" id="settings"></a>

#### Additional Configuration <a href="#additional-configuration" id="additional-configuration"></a>

#### Advanced settings <a href="#advanced-settings" id="advanced-settings"></a>
