AWS Threat Hunting Ideas: RDS
Overview:
1. Unauthorized Database Creation (CreateDBInstance)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=CreateDBInstance
2. Suspicious Database Deletion (DeleteDBInstance)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=DeleteDBInstance
3. Modifying Database Security Groups (ModifyDBInstance)
4. Snapshot Creation and Copy (CreateDBSnapshot/CopyDBSnapshot)
5. Suspected Data Exfiltration (DownloadDBLogFilePortion)
6. Unauthorized Parameter Group Changes (ModifyDBParameterGroup)
7. Automated Backdoor Access (ModifyDBInstance to Enable Public Access)
8. Cross-Account Snapshot Sharing (ModifyDBSnapshotAttribute)
9. Privilege Escalation through Role Association (AddRoleToDBInstance)
10. Database Configuration Rollbacks (RebootDBInstance)
Last updated