An RDS snapshot containing sensitive data was exported
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Data Detection & Response, Cloud Data Asset Exfiltration
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
An RDS snapshot containing sensitive data was exported to an S3 bucket.
Attacker's Goals
Exfiltrate data to an unknown bucket.
Investigative actions
Check the legitimacy of the destination bucket.
Review further logs for the source RDS instance.
Review further actions performed by the identity.
PreviousAn operation was performed by an identity from a domain that was not seen in the organization
NextAn RDS snapshot was exported from a production account
Was this helpful?
