Analytics BIOC Low

Disable encryption operations

Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Manipulation (T1565)
Detector tags: Cloud Data Asset Protection Tampering Data Detection & Response
Attacker's goals:

Decrypt sensitive data host on EC2 instance, this may be a step in a flow for data exfiltration.

Investigative actions:

Check if Identity intended to disable the encryption.

Test period:
N/A (single event)
Deduplication:
1 Day