Skip to content
Threat Feed

Product

RDS

5 briefs RSS
medium advisory

Detection of Unauthorized Public Exposure of AWS RDS Instances

Adversaries with compromised AWS credentials may set the publiclyAccessible attribute to true during RDS instance creation or modification to facilitate data exfiltration, establish persistence, or bypass internal network boundaries.

RDS aws cloud persistence defense-evasion
1r 2t
medium advisory

AWS RDS Deletion Protection Disabled

Adversaries with elevated IAM permissions may disable deletion protection on AWS RDS instances or clusters as a prerequisite for unauthorized data destruction.

RDS +1 cloud aws impact defense-evasion
1r 2t updated
medium advisory

AWS RDS DB Instance or Cluster Password Modification

The modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.

RDS cloud aws persistence
2r 3t
medium advisory

AWS RDS DB Instance Restored for Defense Evasion or Data Collection

Detection of AWS RDS database instance restoration from a snapshot or S3 backup, potentially indicating unauthorized data access, defense evasion, or data collection by adversaries recreating database environments to bypass controls or exfiltrate sensitive data.

RDS cloud aws defense-evasion data-collection
3r 3t
medium advisory

AWS RDS Snapshot Export to S3 for Potential Data Exfiltration

An adversary may export RDS snapshots to Amazon S3 to exfiltrate sensitive data outside of RDS-managed storage, potentially bypassing database access controls and leading to unauthorized data theft.

RDS +1 aws s3 exfiltration cloudtrail
2r 1t