AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance

Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
faloker (SigmaHQ), DRL 1.1
Published
2020-02-12
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule identifies CloudTrail events where an AWS RDS database instance is restored from a DB snapshot and marked as publicly accessible. Attackers can use public restoration to quickly expose a database for staging access during data theft or exfiltration workflows. The detection relies on CloudTrail fields indicating the RDS restore action and the resulting public accessibility setting.

Related detections9 linkedT1020 — drag to rearrange
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
O365 Mail Forwarding and Redirecting Rule Changes
PowerShell Script Reading Files and Resolving DNS Host Entries
PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
Microsoft 365 Cloud App Security Alerts on Suspicious Inbox Forwarding Rules
AWS CloudTrail RDS ModifyDBInstance Master User Password Change
AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Pivot detection · T1020 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.