logo

Database

Aws Instance Encryption Disabled

Description

Detects AWS Neptune database instances that are not configured with encryption at rest enabled. Unencrypted Neptune database instances can expose sensitive graph data to unauthorized access if the underlying storage is compromised.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Checks Neptune database instances in the specified AWS region

    Reports a vulnerability if a Neptune instance has StorageEncrypted set to false

    Only evaluates instances where the StorageEncrypted parameter is explicitly defined