For the complete documentation index, see llms.txt. This page is also available as Markdown.

An AWS database service master user password was changed

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Stealth Tactics, Cloud Data Asset Configuration, Data Detection & Response

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004)

Severity

Informational

Description

An AWS database service master user password was changed.

Attacker's Goals

  • Gain access and control of the database.

Investigative actions

  • Confirm the identity intended to perform this action.

  • Follow further actions done by the identity.

  • Check what other changes were made to the AWS Database instance or cluster.

Variations

An AWS Database Service master user password was changed from an unusual country

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004)

Severity

Low

Description

An AWS database service master user password was changed.

Attacker's Goals

  • Gain access and control of the database.

Investigative actions

  • Confirm the identity intended to perform this action.

  • Follow further actions done by the identity.

  • Check what other changes were made to the AWS Database instance or cluster.

An AWS Database Service master user password was changed by a non-DevOps identity

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004)

Severity

Low

Description

An AWS database service master user password was changed.

Attacker's Goals

  • Gain access and control of the database.

Investigative actions

  • Confirm the identity intended to perform this action.

  • Follow further actions done by the identity.

  • Check what other changes were made to the AWS Database instance or cluster.

Was this helpful?