logo

Database

Aws Cloudfront Logging Disabled

Description

Detects AWS CloudFront distributions that have logging disabled. When CloudFront logging is disabled, there is no audit trail of content access patterns, which impacts security monitoring and incident investigation capabilities.

Weakness:

400 - Traceability Loss - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all CloudFront distributions in the AWS account

    Checks if the logging configuration is disabled (Logging.Enabled = false) for each distribution

    Reports a vulnerability for each CloudFront distribution that has logging disabled