Analytics BIOC Informational

Data encryption was disabled

A cloud identity has disabled data encryption.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Weaken Encryption (T1600) Impair Defenses (T1562)
Detector tags: Cloud Data Asset Disaster Recovery Risks Cloud Data Asset Protection Tampering Data Detection & Response
Attacker's goals:

An attacker is trying to access sensitive data in plaintext. An attacker might try to exfiltrate plaintext data to an endpoint controlled by the attacker and avoid detection. An attacker can re-encrypt the data with a key that is available only to the attacker.

Investigative actions:

Check if the identity intended to disable data encryption. Check which cloud assets were affected by manipulating the above-mentioned configuration file. Check if the identity performed additional suspicious actions to affected assets.

Test period:
N/A (single event)
Deduplication:
1 Day