An AWS database service master user password was changed
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Stealth Tactics, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004)
Severity
Informational
Description
An AWS database service master user password was changed.
Attacker's Goals
Gain access and control of the database.
Investigative actions
Confirm the identity intended to perform this action.
Follow further actions done by the identity.
Check what other changes were made to the AWS Database instance or cluster.
Variations
PreviousAn app was removed from a blocked list in Google Workspace
NextAn AWS EC2 instance containing sensitive data was exported
Was this helpful?
