Analytics BIOC Informational

An AWS RDS instance was created from a snapshot

A new AWS RDS instance was created from a publicly available RDS snapshot.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Stealth Tactics Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Gain access to the RDS instance.* Access confidential data stored in the RDS instance.

Investigative actions:

Check the RDS instance status in the AWS console. Verify if the instance is publicly accessible.

Test period:
N/A (single event)
Deduplication:
5 Days