logo

Database

Aws Files Not Validated

Description

Detects AWS CloudTrail trails that are not configured to validate log file integrity. When log file validation is disabled, there is no way to verify if CloudTrail log files have been modified or tampered with, which could allow malicious activities to go undetected.

Detection Strategy

    Scans all CloudTrail trails in the AWS account within the specified region

    Checks if the LogFileValidationEnabled setting is set to false for each trail

    Reports a vulnerability for each CloudTrail trail that has log file validation disabled

Severity v4.0

0.6

Low

Method ID

CSPM-EENI9

Technique

CSPM

Target

AWS

Technology

CLOUDTRAIL

CWE ID(s)

CWE-117