For the complete documentation index, see llms.txt. This page is also available as Markdown.

Data encryption was disabled

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Weaken Encryption (T1600), Disable or Modify Tools (T1685)

Severity

Informational

Description

A cloud identity has disabled data encryption.

Attacker's Goals

  • An attacker is trying to access sensitive data in plaintext.

  • An attacker might try to exfiltrate plaintext data to an endpoint controlled by the attacker and avoid detection.

  • An attacker can re-encrypt the data with a key that is available only to the attacker.

Investigative actions

  • Check if the identity intended to disable data encryption.

  • Check which cloud assets were affected by manipulating the above-mentioned configuration file.

  • Check if the identity performed additional suspicious actions to affected assets.

Was this helpful?