Analytics BIOC
Low
✕
Disable encryption operations
Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Manipulation (T1565)
Detector tags: Cloud Data Asset Protection Tampering Data Detection & Response
Attacker's goals:
Decrypt sensitive data host on EC2 instance, this may be a step in a flow for data exfiltration.
Investigative actions:
Check if Identity intended to disable the encryption.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day