Skip to content
Threat Feed

Product

Amazon RDS

7 briefs RSS
medium advisory

Detection of Unauthorized Amazon RDS Instance and Cluster Deletion

Adversaries with compromised credentials may delete Amazon RDS DB instances or Aurora clusters to cause permanent data loss, disrupt operations, or destroy forensic evidence.

Amazon RDS +1 impact aws cloud-security
1r 1t
low advisory

AWS CLI Discovery from Single Resource

An Elastic detection rule identifies when a single AWS identity, using the AWS CLI, performs more than five distinct read-only discovery API calls (such as Describe*, List*, Get*, and Generate*) across various AWS services within a 10-second window, indicating reconnaissance by an adversary using compromised credentials or an exploited EC2 instance to map the AWS infrastructure for potential targets and further exploitation.

AWS +13 cloud discovery reconnaissance cli
2t
high advisory

AWS RDS Snapshot Export for Data Exfiltration

An adversary can leverage the AWS `rds:StartExportTask` API to export sensitive RDS database snapshots or DB cluster data to an attacker-controlled Amazon S3 bucket, facilitating data exfiltration and potential data theft from organizations.

Amazon RDS +1 cloud aws exfiltration data-theft rds s3
1r 1t
high threat

AWS Discovery API Calls from VPN ASN for the First Time by Identity

This threat detection rule identifies initial reconnaissance activities within AWS by flagging an IAM principal's first-time invocation of sensitive discovery APIs, such as GetCallerIdentity, ListUsers, ListBuckets, and DescribeInstances, when the originating IP address is associated with consumer VPNs, high-usage hosting providers, or networks linked to threat groups like TeamPCP, indicating an attacker performing enumeration of cloud resources from a suspicious network origin.

AWS CloudTrail +12 TeamPCP aws-cloudtrail iam discovery cloud identity threat-detection
1r 2t 22i updated
medium advisory

AWS RDS Snapshot Deletion Detected

The deletion of AWS RDS DB snapshots or disabling backups via configuration changes can inhibit recovery, destroy forensic evidence, and prepare for destructive actions by adversaries.

Amazon RDS aws rds snapshot backup datadestruction
3r 2t
medium advisory

AWS RDS DB Instance or Cluster Deleted

An adversary with sufficient permissions may delete RDS resources such as DB instances or clusters to impede recovery, destroy evidence, or inflict operational impact on the environment.

Amazon RDS +1 cloud aws rds datadestruction
2r 1t
high advisory

AWS RDS Master User Password Reset Detection

Detection of unauthorized master user password resets for Amazon RDS DB instances via AWS CloudTrail logs, potentially leading to sensitive data access and data breaches.

Amazon RDS cloud aws credential-access rds
2r 2t