logo

Database

Aws Broker Logs Disabled

Description

Detects AWS MQ brokers that have either audit logs or general logs disabled. Message broker logging is critical for security auditing, debugging, and compliance monitoring. Disabled logs can hinder incident investigation and regulatory compliance.

Weakness:

400 - Traceability Loss - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all AWS MQ brokers in the specified region

    Checks the logging configuration for each broker

    Reports a vulnerability if either Audit logs or General logs are disabled (set to false)

    Each vulnerability includes the broker's ARN and its current logging configuration