logo

Database

Aws Encryption At Rest Disabled

Description

Detects AWS OpenSearch domains that do not have encryption at rest enabled. When encryption at rest is disabled, data stored in OpenSearch is not encrypted on disk, potentially exposing sensitive information if the underlying storage is compromised.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all OpenSearch domains in the specified AWS region

    Checks the 'Enabled' status of EncryptionAtRestOptions for each domain

    Reports a vulnerability if encryption at rest is set to false or not configured

    Includes the domain's ARN and encryption configuration in the vulnerability report

Severity v4.0

1.3

Low

Method ID

CSPM-DLEEN

Technique

CSPM

Target

AWS

Technology

OPENSEARCH

CWE ID(s)

CWE-306