Aws Automatic Rotation Disabled

Description

Detects AWS Secrets Manager secrets that do not have automatic rotation enabled. When secrets are not automatically rotated, they can become stale and pose a security risk if compromised, as the same credentials remain valid for extended periods.

Weakness:

396 - Insecure service configuration - KMS

Category: Functionality Abuse

Detection Strategy

    Lists all secrets in the AWS Secrets Manager service for the given region

    Checks each secret's configuration to determine if rotation is enabled

    Reports a vulnerability when a secret has RotationEnabled set to false or undefined