logo

Database

Aws Delivery Failing

Description

Detects AWS CloudTrail trails that are failing to deliver logs to their destination. CloudTrail delivery failures can create gaps in audit logging and security monitoring, potentially masking unauthorized activities or security incidents. This impacts the organization's ability to maintain security audit trails and meet compliance requirements.

Weakness:

400 - Traceability Loss - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all CloudTrail trails in the AWS account and region

    Checks each trail's delivery status for error messages

    Reports a vulnerability if a trail has a non-empty LatestDeliveryError value

    Includes the specific delivery error message in the vulnerability details

Severity v4.0

0.6

Low

Method ID

CSPM-C0LGW

Technique

CSPM

Target

AWS

Technology

CLOUDTRAIL

CWE ID(s)

CWE-778