logo

Database

Aws Unencrypted Storage

Description

Detects AWS RDS database instances that are configured without storage encryption enabled. Unencrypted RDS storage puts sensitive database contents at risk of exposure if the underlying storage is compromised or improperly accessed.

Weakness:

246 - Non-encrypted confidential information - DB

Category: Information Collection

Detection Strategy

    Scans all RDS database instances in the specified AWS region

    Reports a vulnerability if an RDS instance has StorageEncrypted set to false or missing

    Each vulnerable instance is reported with its unique DB Instance ARN and encryption status