logo

Database

Aws Redshift Encryption Disabled

Description

Detects AWS Redshift clusters that are not configured with encryption at rest enabled. Unencrypted Redshift clusters pose a security risk as sensitive data stored in these clusters could be exposed if the underlying storage is compromised.

Detection Strategy

    Scans all Redshift clusters in the specified AWS region

    Reports a vulnerability when a Redshift cluster has the 'Encrypted' property set to false

    For each unencrypted cluster found, includes the cluster identifier, AWS account ID, and region in the vulnerability report