LoFP LoFP / system administrator activities

Techniques

Sample rules

AWS EC2 Disable EBS Encryption

Description

Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.

Detection logic

condition: selection
selection:
  eventName: DisableEbsEncryptionByDefault
  eventSource: ec2.amazonaws.com