An AWS RDS instance was created from a snapshot
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Stealth Tactics, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
A new AWS RDS instance was created from a publicly available RDS snapshot.
Attacker's Goals
Gain access to the RDS instance.* Access confidential data stored in the RDS instance.
Investigative actions
Check the RDS instance status in the AWS console.
Verify if the instance is publicly accessible.
PreviousAn AWS RDS Global Cluster Deletion
NextAn AWS Route 53 domain was transferred to another AWS account
Was this helpful?
