Data encryption was disabled
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Weaken Encryption (T1600), Disable or Modify Tools (T1685)
Severity
Informational
Description
A cloud identity has disabled data encryption.
Attacker's Goals
An attacker is trying to access sensitive data in plaintext.
An attacker might try to exfiltrate plaintext data to an endpoint controlled by the attacker and avoid detection.
An attacker can re-encrypt the data with a key that is available only to the attacker.
Investigative actions
Check if the identity intended to disable data encryption.
Check which cloud assets were affected by manipulating the above-mentioned configuration file.
Check if the identity performed additional suspicious actions to affected assets.
Was this helpful?
