Relational Database Service

eventNameDescriptionSampleRule
anyCatch-all entry for Relational Database Service rules that match the service but not a specific eventName.NN
AuthorizeDBSecurityGroupIngressEnables ingress to a DB security group by authorizing an EC2 security group or an IP address range to access the DB security group.YY
CreateDBClusterCreates a new Amazon Aurora DB cluster or Multi-AZ DB cluster.YY
CreateDBClusterSnapshotCreates a snapshot of a DB cluster.YY
CreateDBInstanceCreates a new DB instance.YY
CreateDBSecurityGroupCreates a new DB security group (EC2-Classic only) and associates it with an Amazon RDS resource.YY
CreateDBSnapshotCreates a snapshot of a DB instance.YY
DeleteDBClusterDeletes a previously provisioned DB cluster, including all automated backups if automated backups are enabled.YY
DeleteDBClusterSnapshotDeletes a DB cluster snapshot; the snapshot must be in the available state to be deleted.YY
DeleteDBInstanceDeletes a previously provisioned DB instance, with the option to create a final snapshot.YY
DeleteDBSecurityGroupDeletes a DB security group after dissociating it from all DB instances.YY
DeleteDBSnapshotDeletes a DB snapshot; the snapshot must be in the available state to be deleted.YY
DeleteGlobalClusterDeletes a global database cluster and removes the primary and all secondary DB clusters that are part of it.YY
DescribeDBInstancesReturns information about provisioned RDS DB instances, including their configuration, status, and endpoint details.YY
DescribeDBSnapshotsReturns information about DB snapshots for a specified DB instance or all snapshots accessible to the account.YY
ModifyDBClusterModifies settings for a DB cluster, including engine version, storage, and backup retention period.YY
ModifyDBClusterSnapshotAttributeAdds or removes attributes on a DB cluster snapshot, including cross-account copy and restore permissions.YY
ModifyDBInstanceModifies settings for a DB instance, including instance class, allocated storage, and multi-AZ configuration.YY
ModifyDBSnapshotAttributeAdds or removes attributes on a manual DB snapshot, including cross-account copy and restore permissions.YY
RestoreDBInstanceFromDBSnapshotCreates a new DB instance from a DB snapshot.YY
RestoreDBInstanceFromS3Creates a new DB instance from a MySQL database backup stored in Amazon S3.NY
RevokeDBSecurityGroupIngressRevokes ingress from a DB security group for previously authorized IP ranges or EC2 security groups.YY
StartExportTaskStarts an export of DB snapshot or DB cluster data to Amazon S3 in Parquet format.YY
AddRoleToDBClusterAssociates an Identity and Access Management (IAM) role with an Neptune DB cluster.YY
AddRoleToDBInstanceAssociates an Amazon Web Services Identity and Access Management (IAM) role with a DB instance.YY
AddSourceIdentifierToSubscriptionAdds a source identifier to an existing event notification subscription.NN
AddTagsToResourceAdds metadata tags to an Amazon DocumentDB resource.YN
ApplyPendingMaintenanceActionApplies a pending maintenance action to a resource (for example, to an Amazon DocumentDB instance).YN
BacktrackDBClusterBacktracks a DB cluster to a specific time, without creating a new DB cluster.YN
CancelExportTaskCancels an export task in progress that is exporting a snapshot or cluster to Amazon S3.YN
CopyDBClusterParameterGroupCopies the specified cluster parameter group.YN
CopyDBClusterSnapshotCopies a snapshot of a cluster.YY
CopyDBParameterGroupCopies the specified DB parameter group.YN
CopyDBSnapshotCopies the specified DBSnapshot.YY
CopyOptionGroupCopies the specified option group.NN
CreateBlueGreenDeploymentCreates a blue/green deployment.NN
CreateCustomDBEngineVersionCreates a custom DB engine version (CEV).NN
CreateDBClusterEndpointCreates a new custom endpoint and associates it with an Amazon Neptune DB cluster.YN
CreateDBClusterParameterGroupCreates a new cluster parameter group.YN
CreateDBInstanceReadReplicaCreates a DB instance that acts as a Read Replica of a source DB instance.NN
CreateDBParameterGroupCreates a new DB parameter group.YN
CreateDBProxyCreates a new DB proxy.YN
CreateDBProxyEndpointCreates a DBProxyEndpoint.YN
CreateDBShardGroupCreates a new DB shard group for Aurora Limitless Database.NN
CreateDBSubnetGroupCreates a new subnet group.YN
CreateEventSubscriptionCreates an Amazon DocumentDB event notification subscription.YN
CreateGlobalClusterCreates an Amazon DocumentDB global cluster that can span multiple multiple Amazon Web Services Regions.NN
CreateIntegrationCreates a zero-ETL integration with Amazon Redshift.NN
CreateOptionGroupCreates a new option group.YN
CreateTenantDatabaseCreates a tenant database in a DB instance that uses the multi-tenant configuration.NN
DeleteBlueGreenDeploymentDeletes a blue/green deployment.YN
DeleteCustomDBEngineVersionDeletes a custom engine version.YN
DeleteDBClusterAutomatedBackupDeletes automated backups using the DbClusterResourceId value of the source DB cluster or the Amazon Resource Name (ARN) of the automated backups.YY
DeleteDBClusterEndpointDeletes a custom endpoint and removes it from an Amazon Neptune DB cluster.YN
DeleteDBClusterParameterGroupDeletes a specified cluster parameter group.YN
DeleteDBInstanceAutomatedBackupDeletes automated backups using the DbiResourceId value of the source DB instance or the Amazon Resource Name (ARN) of the automated backups.YY
DeleteDBParameterGroupDeletes a specified DBParameterGroup.YN
DeleteDBProxyDeletes an existing DB proxy.YN
DeleteDBProxyEndpointDeletes a DBProxyEndpoint.YN
DeleteDBShardGroupDeletes an Aurora Limitless Database DB shard group.YN
DeleteDBSubnetGroupDeletes a subnet group.YN
DeleteEventSubscriptionDeletes an Amazon DocumentDB event notification subscription.YN
DeleteIntegrationDeletes a zero-ETL integration with Amazon Redshift.NN
DeleteOptionGroupDeletes an existing option group.YN
DeleteTenantDatabaseDeletes a tenant database from your DB instance.YN
DeregisterDBProxyTargetsRemove the association between one or more DBProxyTarget data structures and a DBProxyTargetGroup.YN
DescribeAccountAttributesLists all of the attributes for a customer account.YN
DescribeBlueGreenDeploymentsDescribes one or more blue/green deployments.YN
DescribeCertificatesReturns a list of certificate authority (CA) certificates provided by Amazon DocumentDB for this Amazon Web Services account.YN
DescribeDBClusterAutomatedBackupsDisplays backups for both current and deleted DB clusters.YN
DescribeDBClusterBacktracksReturns information about backtracks for a DB cluster.YN
DescribeDBClusterEndpointsReturns information about endpoints for an Amazon Neptune DB cluster.YN
DescribeDBClusterParameterGroupsReturns a list of DBClusterParameterGroup descriptions.YN
DescribeDBClusterParametersReturns the detailed parameter list for a particular cluster parameter group.YN
DescribeDBClustersReturns information about provisioned Amazon DocumentDB clusters.YN
DescribeDBClusterSnapshotAttributesReturns a list of cluster snapshot attribute names and values for a manual DB cluster snapshot.YN
DescribeDBClusterSnapshotsReturns information about cluster snapshots.YY
DescribeDBEngineVersionsReturns a list of the available engines.YN
DescribeDBInstanceAutomatedBackupsDisplays backups for both current and deleted instances.YN
DescribeDBLogFilesReturns a list of DB log files for the DB instance.YN
DescribeDBMajorEngineVersionsDescribes the properties of specific major versions of DB engines.YN
DescribeDBParameterGroupsReturns a list of DBParameterGroup descriptions.YN
DescribeDBParametersReturns the detailed parameter list for a particular DB parameter group.YN
DescribeDBProxiesReturns information about DB proxies.YN
DescribeDBProxyEndpointsReturns information about DB proxy endpoints.YN
DescribeDBProxyTargetGroupsReturns information about DB proxy target groups, represented by DBProxyTargetGroup data structures.YN
DescribeDBProxyTargetsReturns information about DBProxyTarget objects.YN
DescribeDBRecommendationsDescribes the recommendations to resolve the issues for your DB instances, DB clusters, and DB parameter groups.YN
DescribeDBSecurityGroupsReturns a list of DBSecurityGroup descriptions.YN
DescribeDBShardGroupsDescribes existing Aurora Limitless Database DB shard groups.YN
DescribeDBSnapshotAttributesReturns a list of DB snapshot attribute names and values for a manual DB snapshot.YN
DescribeDBSnapshotTenantDatabasesDescribes the tenant databases that exist in a DB snapshot.YN
DescribeDBSubnetGroupsReturns a list of DBSubnetGroup descriptions.YN
DescribeEngineDefaultClusterParametersReturns the default engine and system parameter information for the cluster database engine.YN
DescribeEngineDefaultParametersReturns the default engine and system parameter information for the specified database engine.YN
DescribeEventCategoriesDisplays a list of categories for all event source types, or, if specified, for a specified source type.YN
DescribeEventsReturns events related to instances, security groups, snapshots, and DB parameter groups for the past 14 days.YN
DescribeEventSubscriptionsLists all the subscription descriptions for a customer account.YN
DescribeExportTasksReturns information about a snapshot or cluster export to Amazon S3.YN
DescribeGlobalClustersReturns information about Amazon DocumentDB global clusters.YN
DescribeIntegrationsDescribe one or more zero-ETL integrations with Amazon Redshift.YN
DescribeOptionGroupOptionsDescribes all available options.YN
DescribeOptionGroupsDescribes the available option groups.YN
DescribeOrderableDBInstanceOptionsReturns a list of orderable instance options for the specified engine.YN
DescribePendingMaintenanceActionsReturns a list of resources (for example, instances) that have at least one pending maintenance action.YN
DescribeReservedDBInstancesReturns information about reserved DB instances for this account, or about a specified reserved DB instance.YN
DescribeReservedDBInstancesOfferingsLists available reserved DB instance offerings.YN
DescribeServerlessV2PlatformVersionsDescribes the properties of specific platform versions for Aurora Serverless v2.YN
DescribeSourceRegionsReturns a list of the source Amazon Web Services Regions where the current Amazon Web Services Region can create a read replica, copy a DB snapshot from, or replicate automated backups from.YN
DescribeTenantDatabasesDescribes the tenant databases in a DB instance that uses the multi-tenant configuration.YN
DescribeValidDBInstanceModificationsYou can call DescribeValidDBInstanceModifications to learn what modifications you can make to your DB instance.YN
DisableHttpEndpointDisables the HTTP endpoint for the specified DB cluster.YN
DownloadDBLogFilePortionDownloads all or a portion of the specified log file.NY
EnableHttpEndpointEnables the HTTP endpoint for the DB cluster.YN
FailoverDBClusterForces a failover for a cluster.YY
FailoverGlobalClusterPromotes the specified secondary DB cluster to be the primary DB cluster in the global cluster when failing over a global cluster occurs.NY
ListTagsForResourceLists all tags on an Amazon DocumentDB resource.YN
ModifyActivityStreamChanges the audit policy state of a database activity stream to either locked (default) or unlocked.YN
ModifyCertificatesOverride the system-default Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate for Amazon RDS for new DB instances, or remove the override.YN
ModifyCurrentDBClusterCapacitySet the capacity of an Aurora Serverless v1 DB cluster to a specific value.YN
ModifyCustomDBEngineVersionModifies the status of a custom engine version (CEV).YN
ModifyDBClusterEndpointModifies the properties of an endpoint in an Amazon Neptune DB cluster.YN
ModifyDBClusterParameterGroupModifies the parameters of a cluster parameter group.YN
ModifyDBParameterGroupModifies the parameters of a DB parameter group.YN
ModifyDBProxyChanges the settings for an existing DB proxy.YN
ModifyDBProxyEndpointChanges the settings for an existing DB proxy endpoint.YN
ModifyDBProxyTargetGroupModifies the properties of a DBProxyTargetGroup.YN
ModifyDBRecommendationUpdates the recommendation status and recommended action status for the specified recommendation.YN
ModifyDBShardGroupModifies the settings of an Aurora Limitless Database DB shard group.YN
ModifyDBSnapshotUpdates a manual DB snapshot with a new engine version.YN
ModifyDBSubnetGroupModifies an existing subnet group.YN
ModifyEventSubscriptionModifies an existing Amazon DocumentDB event notification subscription.YN
ModifyGlobalClusterModify a setting for an Amazon DocumentDB global cluster.YN
ModifyIntegrationModifies a zero-ETL integration with Amazon Redshift.NN
ModifyOptionGroupModifies an existing option group.YN
ModifyTenantDatabaseModifies an existing tenant database in a DB instance.YN
PromoteReadReplicaPromotes a Read Replica DB instance to a standalone DB instance.NN
PromoteReadReplicaDBClusterNot supported.NN
PurchaseReservedDBInstancesOfferingPurchases a reserved DB instance offering.NN
RebootDBClusterYou might need to reboot your DB cluster, usually for maintenance reasons.YY
RebootDBInstanceYou might need to reboot your instance, usually for maintenance reasons.YY
RebootDBShardGroupYou might need to reboot your DB shard group, usually for maintenance reasons.NY
RegisterDBProxyTargetsAssociate one or more DBProxyTarget data structures with a DBProxyTargetGroup.YN
RemoveFromGlobalClusterDetaches an Amazon DocumentDB secondary cluster from a global cluster.YN
RemoveRoleFromDBClusterDisassociates an Identity and Access Management (IAM) role from a DB cluster.YN
RemoveRoleFromDBInstanceDisassociates an Amazon Web Services Identity and Access Management (IAM) role from a DB instance.YN
RemoveSourceIdentifierFromSubscriptionRemoves a source identifier from an existing Amazon DocumentDB event notification subscription.YN
RemoveTagsFromResourceRemoves metadata tags from an Amazon DocumentDB resource.YN
ResetDBClusterParameterGroupModifies the parameters of a cluster parameter group to the default value.YN
ResetDBParameterGroupModifies the parameters of a DB parameter group to the engine/system default value.YN
RestoreDBClusterFromS3Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket.NN
RestoreDBClusterFromSnapshotCreates a new cluster from a snapshot or cluster snapshot.NN
RestoreDBClusterToPointInTimeRestores a cluster to an arbitrary point in time.NN
RestoreDBInstanceToPointInTimeRestores a DB instance to an arbitrary point-in-time.NN
StartActivityStreamStarts a database activity stream to monitor activity on the database.NN
StartDBClusterRestarts the stopped cluster that is specified by DBClusterIdentifier.YN
StartDBInstanceStarts an Amazon RDS DB instance that was stopped using the Amazon Web Services console, the stop-db-instance CLI command, or the StopDBInstance operation.YN
StartDBInstanceAutomatedBackupsReplicationEnables replication of automated backups to a different Amazon Web Services Region.NN
StopActivityStreamStops a database activity stream that was started using the Amazon Web Services console, the start-activity-stream CLI command, or the StartActivityStream operation.NY
StopDBClusterStops the running cluster that is specified by DBClusterIdentifier.YN
StopDBInstanceStops an Amazon RDS DB instance temporarily.YN
StopDBInstanceAutomatedBackupsReplicationStops automated backup replication for a DB instance.YN
SwitchoverBlueGreenDeploymentSwitches over a blue/green deployment.NN
SwitchoverGlobalClusterSwitches over the specified secondary Amazon DocumentDB cluster to be the new primary Amazon DocumentDB cluster in the global database cluster.NN
SwitchoverReadReplicaSwitches over an Oracle standby database in an Oracle Data Guard environment, making it the new primary database.NN

any: Relational Database Service (catch-all)

#
Service
rds

Description

Catch-all entry for Relational Database Service rules that match the service but not a specific eventName.

AuthorizeDBSecurityGroupIngress

#
Service
rds

Description

Enables ingress to a DB security group by authorizing an EC2 security group or an IP address range to access the DB security group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "VPC DB Security Groups cannot be modified with this API version.  Please use an API version between 2012-01-15 and 2012-10-31 to modify this group.",
  "eventCategory": "Management",
  "eventID": "3348e56c-d35d-4c9b-ab9d-e951b30c33ff",
  "eventName": "AuthorizeDBSecurityGroupIngress",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "91206c2b-14d8-483c-89e7-a740b4c1665a",
  "requestParameters": {
    "cIDRIP": "10.0.0.0/8",
    "dBSecurityGroupName": "dwfix-ec2classic-sg"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

Panther #

CreateDBCluster

#
Service
rds

Description

Creates a new Amazon Aurora DB cluster or Multi-AZ DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The parameter MasterUserPassword is not a valid password. Only printable ASCII characters besides '/', '@', '\"', ' ' may be used.",
  "eventCategory": "Management",
  "eventID": "337a0070-0c64-47e1-8892-0af86058690f",
  "eventName": "CreateDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3f413968-a007-41db-a0c1-839ae5b5ce06",
  "requestParameters": {
    "backupRetentionPeriod": 1,
    "dBClusterIdentifier": "dwfix-aurora-cl",
    "dBClusterParameterGroupName": "dwfix-aurora-pg",
    "dBSubnetGroupName": "dwfix-rds-subnet-grp",
    "deletionProtection": false,
    "engine": "aurora-mysql",
    "engineVersion": "8.0.mysql_aurora.3.04.0",
    "masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "masterUsername": "dwfixadmin",
    "serverlessV2ScalingConfiguration": {
      "maxCapacity": 1.0,
      "minCapacity": 0.5
    },
    "storageEncrypted": false,
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Instance Made Public source medium: Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls.T1133, T1556, T1556.009↳ also matches CreateDBInstance, ModifyDBInstance

CreateDBClusterSnapshot

#
Service
rds

Description

Creates a snapshot of a DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "DBCluster not found: dwfix-aurora-cl",
  "eventCategory": "Management",
  "eventID": "428cb678-c6f1-4f0e-8c98-f0297a64601f",
  "eventName": "CreateDBClusterSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9fe54895-0453-4d4a-91fa-de529dfcb1ee",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl",
    "dBClusterSnapshotIdentifier": "dwfix-aurora-snap",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Snapshot Created source low: Identifies when an AWS RDS DB Snapshot is created. This can be used to evade defenses by allowing an attacker to bypass access controls or cover their tracks by reverting an instance to a previous state. This is a building block rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. To generate alerts, create a rule that uses this signal as a building block.T1578, T1578.001↳ also matches CreateDBSnapshot

CreateDBInstance

#
Service
rds

Description

Creates a new DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "fdc74c82-c299-4211-a08e-b5f125ee3b58",
  "eventName": "CreateDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:15:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "5677161c-d80f-4202-8e1f-53c4dcd261af",
  "requestParameters": {
    "allocatedStorage": 10,
    "autoMinorVersionUpgrade": true,
    "backupRetentionPeriod": 0,
    "copyTagsToSnapshot": false,
    "dBInstanceClass": "db.t3.micro",
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBName": "stratusredteamsharesnapdb",
    "dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
    "deletionProtection": false,
    "engine": "mysql",
    "engineVersion": "8.0",
    "masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "masterUsername": "admin",
    "publiclyAccessible": false,
    "storageEncrypted": false,
    "tags": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "allocatedStorage": 10,
    "associatedRoles": [],
    "autoMinorVersionUpgrade": true,
    "backupRetentionPeriod": 0,
    "backupTarget": "region",
    "cACertificateIdentifier": "rds-ca-2019",
    "certificateDetails": {
      "cAIdentifier": "rds-ca-2019"
    },
    "copyTagsToSnapshot": false,
    "customerOwnedIpEnabled": false,
    "dBInstanceArn": "arn:aws:rds:us-east-1:123837392027:db:terraform-20230710121504061500000001",
    "dBInstanceClass": "db.t3.micro",
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBInstanceStatus": "creating",
    "dBName": "stratusredteamsharesnapdb",
    "dBParameterGroups": [
      {
        "dBParameterGroupName": "default.mysql8.0",
        "parameterApplyStatus": "in-sync"
      }
    ],
    "dBSecurityGroups": [],
    "dBSubnetGroup": {
      "dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
      "dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
      "subnetGroupStatus": "Complete",
      "subnets": [
        {
          "subnetAvailabilityZone": {
            "name": "us-east-1a"
          },
          "subnetIdentifier": "subnet-0cac13291c6f317ec",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        },
        {
          "subnetAvailabilityZone": {
            "name": "us-east-1b"
          },
          "subnetIdentifier": "subnet-0c8a70cf4fd24084f",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        }
      ],
      "vpcId": "vpc-07b33857c7ad1c027"
    },
    "dbInstancePort": 0,
    "dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
    "dedicatedLogVolume": false,
    "deletionProtection": false,
    "domainMemberships": [],
    "engine": "mysql",
    "engineVersion": "8.0.32",
    "httpEndpointEnabled": false,
    "iAMDatabaseAuthenticationEnabled": false,
    "licenseModel": "general-public-license",
    "masterUsername": "admin",
    "monitoringInterval": 0,
    "multiAZ": false,
    "networkType": "IPV4",
    "optionGroupMemberships": [
      {
        "optionGroupName": "default:mysql-8-0",
        "status": "in-sync"
      }
    ],
    "pendingModifiedValues": {
      "masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS"
    },
    "performanceInsightsEnabled": false,
    "preferredBackupWindow": "04:41-05:11",
    "preferredMaintenanceWindow": "tue:03:39-tue:04:09",
    "publiclyAccessible": false,
    "readReplicaDBInstanceIdentifiers": [],
    "storageEncrypted": false,
    "storageThroughput": 0,
    "storageType": "gp2",
    "tagList": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ],
    "vpcSecurityGroups": [
      {
        "status": "active",
        "vpcSecurityGroupId": "sg-0a1ae80d31d1e9c86"
      }
    ]
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Instance Made Public source medium: Identifies the creation or modification of an Amazon RDS DB instance or cluster where the "publiclyAccessible" attribute is set to "true". Publicly accessible RDS instances expose a network endpoint on the public internet, which may allow unauthorized access if combined with overly permissive security groups, weak authentication, or misconfigured IAM policies. Adversaries may enable public access on an existing instance, or create a new publicly accessible instance, to establish persistence, move data outside of controlled network boundaries, or bypass internal access controls.T1133, T1556, T1556.009↳ also matches CreateDBCluster, ModifyDBInstance

References #

CreateDBSecurityGroup

#
Service
rds

Description

Creates a new DB security group (EC2-Classic only) and associates it with an Amazon RDS resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1e1bbcf3-cb4a-4d9f-b6b7-8dc3461c7792",
  "eventName": "CreateDBSecurityGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "13b53091-8438-4075-b3cc-67f79fabcdcb",
  "requestParameters": {
    "dBSecurityGroupDescription": "dwfix EC2-Classic test SG",
    "dBSecurityGroupName": "dwfix-ec2classic-sg"
  },
  "responseElements": {
    "dBSecurityGroupArn": "arn:aws:rds:us-west-1:123456789012:secgrp:dwfix-ec2classic-sg",
    "dBSecurityGroupDescription": "dwfix EC2-Classic test SG",
    "dBSecurityGroupName": "dwfix-ec2classic-sg",
    "eC2SecurityGroups": [],
    "iPRanges": [],
    "ownerId": "123456789012",
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

CreateDBSnapshot

#
Service
rds

Description

Creates a snapshot of a DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "0516b66a-77ec-4479-a82d-0cda54d3fc5d",
  "eventName": "CreateDBSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:19:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "63f3081b-eb64-472c-96ec-c9a24028320c",
  "requestParameters": {
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBSnapshotIdentifier": "exfiltration",
    "tags": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "allocatedStorage": 10,
    "availabilityZone": "us-east-1b",
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBSnapshotArn": "arn:aws:rds:us-east-1:123837392027:snapshot:exfiltration",
    "dBSnapshotIdentifier": "exfiltration",
    "dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
    "dedicatedLogVolume": false,
    "encrypted": false,
    "engine": "mysql",
    "engineVersion": "8.0.32",
    "iAMDatabaseAuthenticationEnabled": false,
    "instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
    "licenseModel": "general-public-license",
    "masterUsername": "admin",
    "optionGroupName": "default:mysql-8-0",
    "percentProgress": 0,
    "port": 3306,
    "processorFeatures": [],
    "snapshotTarget": "region",
    "snapshotType": "manual",
    "status": "creating",
    "storageThroughput": 0,
    "storageType": "gp2",
    "tagList": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ],
    "vpcId": "vpc-07b33857c7ad1c027"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Snapshot Created source low: Identifies when an AWS RDS DB Snapshot is created. This can be used to evade defenses by allowing an attacker to bypass access controls or cover their tracks by reverting an instance to a previous state. This is a building block rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. To generate alerts, create a rule that uses this signal as a building block.T1578, T1578.001↳ also matches CreateDBClusterSnapshot

Panther #

References #

DeleteDBCluster

#
Service
rds

Description

Deletes a previously provisioned DB cluster, including all automated backups if automated backups are enabled.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "The source cluster could not be found or cannot be accessed: dw-probe",
  "eventCategory": "Management",
  "eventID": "b63bc185-46c0-4abb-9f3a-a318e3c876ec",
  "eventName": "DeleteDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cbc9480a-d5db-43da-92e7-8fbde59e2136",
  "requestParameters": {
    "dBClusterIdentifier": "dw-probe",
    "skipFinalSnapshot": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS RDS DB Instance or Cluster Deleted source medium: Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment.T1485↳ also matches DeleteDBInstance, DeleteGlobalCluster

Panther #

DeleteDBClusterSnapshot

#
Service
rds

Description

Deletes a DB cluster snapshot; the snapshot must be in the available state to be deleted.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterSnapshotNotFoundFault",
  "errorMessage": "DBClusterSnapshot not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "7ff19601-41e8-4878-8d2e-da1d384f947d",
  "eventName": "DeleteDBClusterSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4823ced9-6962-439a-baca-40c1cfc90c3c",
  "requestParameters": {
    "dBClusterSnapshotIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS Snapshot Deleted source medium: Identifies the deletion of an AWS RDS DB snapshot or configuration changes that effectively remove backup coverage for a DB instance. RDS snapshots contain full backups of database instances, and disabling automated backups by setting "backupRetentionPeriod=0" has a similar impact by preventing future restore points. Adversaries with the appropriate permissions may delete snapshots or disable backups to inhibit recovery, destroy forensic evidence, or prepare for follow-on destructive actions such as instance or cluster deletion.T1485, T1490↳ also matches DeleteDBSnapshot, ModifyDBInstance

Panther #

  • AWS RDS Snapshot Deleted source high: Detects deletion of RDS snapshots. Attackers delete backups to prevent recovery or hide evidence of data exfiltration. Multiple snapshot deletions may indicate ransomware preparing to encrypt databases without recovery options.T1070, T1485↳ also matches DeleteDBSnapshot

DeleteDBInstance

#
Service
rds

Description

Deletes a previously provisioned DB instance, with the option to create a final snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b5232796-c668-4d71-a006-d9cabb3d607d",
  "eventName": "DeleteDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "23ffb7fd-6479-46bd-9db4-62348a02d8a4",
  "requestParameters": {
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "deleteAutomatedBackups": true,
    "finalDBSnapshotIdentifier": "terraform-20230710121504061500000001-snapshot",
    "skipFinalSnapshot": false
  },
  "responseElements": {
    "allocatedStorage": 10,
    "associatedRoles": [],
    "autoMinorVersionUpgrade": true,
    "availabilityZone": "us-east-1b",
    "backupRetentionPeriod": 0,
    "backupTarget": "region",
    "cACertificateIdentifier": "",
    "copyTagsToSnapshot": false,
    "customerOwnedIpEnabled": false,
    "dBInstanceArn": "arn:aws:rds:us-east-1:123837392027:db:terraform-20230710121504061500000001",
    "dBInstanceClass": "db.t3.micro",
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBInstanceStatus": "deleting",
    "dBName": "stratusredteamsharesnapdb",
    "dBParameterGroups": [
      {
        "dBParameterGroupName": "default.mysql8.0",
        "parameterApplyStatus": "in-sync"
      }
    ],
    "dBSecurityGroups": [],
    "dBSubnetGroup": {
      "dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
      "dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
      "subnetGroupStatus": "Complete",
      "subnets": [
        {
          "subnetAvailabilityZone": {
            "name": "us-east-1a"
          },
          "subnetIdentifier": "subnet-0cac13291c6f317ec",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        },
        {
          "subnetAvailabilityZone": {
            "name": "us-east-1b"
          },
          "subnetIdentifier": "subnet-0c8a70cf4fd24084f",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        }
      ],
      "vpcId": "vpc-07b33857c7ad1c027"
    },
    "dbInstancePort": 0,
    "dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
    "dedicatedLogVolume": false,
    "deletionProtection": false,
    "domainMemberships": [],
    "endpoint": {
      "address": "terraform-20230710121504061500000001.c2m8opohni2g.us-east-1.rds.amazonaws.com",
      "hostedZoneId": "Z2R2ITUGPM61AM",
      "port": 3306
    },
    "engine": "mysql",
    "engineVersion": "8.0.32",
    "httpEndpointEnabled": false,
    "iAMDatabaseAuthenticationEnabled": false,
    "instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
    "licenseModel": "general-public-license",
    "masterUsername": "admin",
    "monitoringInterval": 0,
    "multiAZ": false,
    "networkType": "IPV4",
    "optionGroupMemberships": [
      {
        "optionGroupName": "default:mysql-8-0",
        "status": "in-sync"
      }
    ],
    "pendingModifiedValues": {},
    "performanceInsightsEnabled": false,
    "preferredBackupWindow": "04:41-05:11",
    "preferredMaintenanceWindow": "tue:03:39-tue:04:09",
    "publiclyAccessible": false,
    "readReplicaDBInstanceIdentifiers": [],
    "storageEncrypted": false,
    "storageThroughput": 0,
    "storageType": "gp2",
    "tagList": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ],
    "vpcSecurityGroups": [
      {
        "status": "active",
        "vpcSecurityGroupId": "sg-0a1ae80d31d1e9c86"
      }
    ]
  },
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Instance or Cluster Deleted source medium: Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment.T1485↳ also matches DeleteDBCluster, DeleteGlobalCluster

Panther #

References #

DeleteDBSecurityGroup

#
Service
rds

Description

Deletes a DB security group after dissociating it from all DB instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSecurityGroupNotFoundFault",
  "errorMessage": "DBSecurityGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "0b42e1f0-48b1-4cbf-a46b-d4abc220888d",
  "eventName": "DeleteDBSecurityGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "112c7bbe-1f03-421a-bb47-aa5b85244d1f",
  "requestParameters": {
    "dBSecurityGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

DeleteDBSnapshot

#
Service
rds

Description

Deletes a DB snapshot; the snapshot must be in the available state to be deleted.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1b51dbcc-50a4-4e5c-a558-69096203818a",
  "eventName": "DeleteDBSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "4414a0af-48a6-4807-901f-7f9a8b23d0ce",
  "requestParameters": {
    "dBSnapshotIdentifier": "exfiltration"
  },
  "responseElements": {
    "allocatedStorage": 10,
    "availabilityZone": "us-east-1b",
    "dBInstanceIdentifier": "terraform-20230710121504061500000001",
    "dBSnapshotArn": "arn:aws:rds:us-east-1:123837392027:snapshot:exfiltration",
    "dBSnapshotIdentifier": "exfiltration",
    "dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
    "dedicatedLogVolume": false,
    "encrypted": false,
    "engine": "mysql",
    "engineVersion": "8.0.32",
    "iAMDatabaseAuthenticationEnabled": false,
    "instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
    "licenseModel": "general-public-license",
    "masterUsername": "admin",
    "optionGroupName": "default:mysql-8-0",
    "originalSnapshotCreateTime": "Jul 10, 2023 12:20:17 PM",
    "percentProgress": 100,
    "port": 3306,
    "processorFeatures": [],
    "snapshotCreateTime": "Jul 10, 2023 12:20:17 PM",
    "snapshotTarget": "region",
    "snapshotType": "manual",
    "status": "deleted",
    "storageThroughput": 0,
    "storageType": "gp2",
    "tagList": [],
    "vpcId": "vpc-07b33857c7ad1c027"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS Snapshot Deleted source medium: Identifies the deletion of an AWS RDS DB snapshot or configuration changes that effectively remove backup coverage for a DB instance. RDS snapshots contain full backups of database instances, and disabling automated backups by setting "backupRetentionPeriod=0" has a similar impact by preventing future restore points. Adversaries with the appropriate permissions may delete snapshots or disable backups to inhibit recovery, destroy forensic evidence, or prepare for follow-on destructive actions such as instance or cluster deletion.T1485, T1490↳ also matches DeleteDBClusterSnapshot, ModifyDBInstance

Panther #

  • AWS RDS Snapshot Deleted source high: Detects deletion of RDS snapshots. Attackers delete backups to prevent recovery or hide evidence of data exfiltration. Multiple snapshot deletions may indicate ransomware preparing to encrypt databases without recovery options.T1070, T1485↳ also matches DeleteDBClusterSnapshot

References #

DeleteGlobalCluster

#
Service
rds

Description

Deletes a global database cluster and removes the primary and all secondary DB clusters that are part of it.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "GlobalClusterNotFoundFault",
  "errorMessage": "Global cluster 'ddddd' not found",
  "eventCategory": "Management",
  "eventID": "76135edb-a9c1-4ecf-bbdf-187f8f459497",
  "eventName": "DeleteGlobalCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f18c1630-1780-4d7a-9930-9e5a893c140e",
  "requestParameters": {
    "globalClusterIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Instance or Cluster Deleted source medium: Identifies the deletion of an Amazon RDS DB instance, Aurora cluster, or global database cluster. Deleting these resources permanently destroys stored data and can cause major service disruption. Adversaries with sufficient permissions may delete RDS resources to impede recovery, destroy evidence, or inflict operational impact on the environment.T1485↳ also matches DeleteDBCluster, DeleteDBInstance

DescribeDBInstances

#
Service
rds

Description

Returns information about provisioned RDS DB instances, including their configuration, status, and endpoint details.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "193dd028-8c45-4b6a-9339-ed4358ca0105",
  "eventName": "DescribeDBInstances",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:16:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "802f63f1-f396-4ee4-bf02-25f136f28b87",
  "requestParameters": {
    "dBInstanceIdentifier": "terraform-20230710121504061500000001"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeDBSnapshots

References #

DescribeDBSnapshots

#
Service
rds

Description

Returns information about DB snapshots for a specified DB instance or all snapshots accessible to the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "5eeb7559-5684-48c2-9583-a4309fed632b",
  "eventName": "DescribeDBSnapshots",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:21:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "8f1799a7-b750-436e-8d46-078bdff4a328",
  "requestParameters": {
    "dBSnapshotIdentifier": "exfiltration",
    "includePublic": false,
    "includeShared": false
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeDBInstances

Panther #

References #

ModifyDBCluster

#
Service
rds

Description

Modifies settings for a DB cluster, including engine version, storage, and backup retention period.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "DBCluster not found",
  "eventCategory": "Management",
  "eventID": "4bc29181-b8e2-4bb5-8bb3-741ab9ea815c",
  "eventName": "ModifyDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8edbbb6f-1580-424c-95d4-74666c9b7e54",
  "requestParameters": {
    "allowEngineModeChange": false,
    "allowMajorVersionUpgrade": false,
    "applyImmediately": false,
    "dBClusterIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS RDS DB Instance or Cluster Deletion Protection Disabled source medium: Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster.T1485, T1578, T1578.005↳ also matches ModifyDBInstance
  • AWS RDS DB Instance or Cluster Password Modified source medium: Identifies the modification of the master password for an AWS RDS DB instance or cluster. Changing the master password is a legitimate recovery action when access is lost, but adversaries with sufficient permissions may modify it to regain access, establish persistence, bypass existing controls, or escalate privileges within a compromised environment. Because RDS does not expose the password in API responses, this operation can meaningfully alter access pathways to sensitive data stores.T1098, T1098.001↳ also matches ModifyDBInstance

Splunk #

Panther #

ModifyDBClusterSnapshotAttribute

#
Service
rds

Description

Adds or removes attributes on a DB cluster snapshot, including cross-account copy and restore permissions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterSnapshotNotFoundFault",
  "errorMessage": "DBClusterSnapshot not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "01036be9-f9fa-4095-bdee-317c9501ec4f",
  "eventName": "ModifyDBClusterSnapshotAttribute",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0c702e56-47b4-4948-8120-dfdbef357bff",
  "requestParameters": {
    "attributeName": "dw-probe",
    "dBClusterSnapshotIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Snapshot Shared with Another Account source medium: Identifies when an AWS RDS DB snapshot is shared with another AWS account or made public. DB snapshots contain complete backups of database instances, including schemas, table data, and sensitive application content. When shared externally, snapshots can be restored in another AWS environment, enabling unauthorized access, offline analysis, or data exfiltration. Adversaries who obtain valid credentials or exploit misconfigurations may modify snapshot attributes to grant access to accounts they control, bypassing network, IAM, and monitoring controls.T1537↳ also matches ModifyDBSnapshotAttribute

YARA-L #

Panther #

ModifyDBInstance

#
Service
rds

Description

Modifies settings for a DB instance, including instance class, allocated storage, and multi-AZ configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "46351ca1-760e-4eef-b3ff-19723e13fbf8",
  "eventName": "ModifyDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2022-08-05T09:19:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "59e6b621-2f12-415b-bde4-21fa2dc7c113",
  "requestParameters": {
    "allowMajorVersionUpgrade": false,
    "applyImmediately": true,
    "dBInstanceIdentifier": "database-1",
    "deletionProtection": true,
    "masterUserPassword": "****"
  },
  "responseElements": {
    "allocatedStorage": 5,
    "associatedRoles": [],
    "autoMinorVersionUpgrade": true,
    "availabilityZone": "us-west-2a",
    "backupRetentionPeriod": 7,
    "backupTarget": "region",
    "cACertificateIdentifier": "rds-ca-2019",
    "copyTagsToSnapshot": true,
    "customerOwnedIpEnabled": false,
    "dBInstanceArn": "arn:aws:rds:us-west-2:111111111111:db:database-1",
    "dBInstanceClass": "db.m6g.large",
    "dBInstanceIdentifier": "database-1",
    "dBInstanceStatus": "available",
    "dBParameterGroups": [
      {
        "dBParameterGroupName": "default.postgres14",
        "parameterApplyStatus": "in-sync"
      }
    ],
    "dBSecurityGroups": [],
    "dBSubnetGroup": {
      "dBSubnetGroupDescription": "default",
      "dBSubnetGroupName": "default",
      "subnetGroupStatus": "Complete",
      "subnets": [
        {
          "subnetAvailabilityZone": {
            "name": "us-west-2b"
          },
          "subnetIdentifier": "subnet-43225f35",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        },
        {
          "subnetAvailabilityZone": {
            "name": "us-west-2a"
          },
          "subnetIdentifier": "subnet-e55d7881",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        },
        {
          "subnetAvailabilityZone": {
            "name": "us-west-2c"
          },
          "subnetIdentifier": "subnet-0beddb972f034bdaa",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        },
        {
          "subnetAvailabilityZone": {
            "name": "us-west-2c"
          },
          "subnetIdentifier": "subnet-2d70cd75",
          "subnetOutpost": {},
          "subnetStatus": "Active"
        }
      ],
      "vpcId": "vpc-5f02343b"
    },
    "dbInstancePort": 0,
    "dbiResourceId": "db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
    "deletionProtection": true,
    "domainMemberships": [],
    "endpoint": {
      "address": "database-1.ce6wk5bvtc0t.us-west-2.rds.amazonaws.com",
      "hostedZoneId": "Z1PVIF0B656C1W",
      "port": 5432
    },
    "engine": "postgres",
    "engineVersion": "14.2",
    "enhancedMonitoringResourceArn": "arn:aws:logs:us-west-2:111111111111:log-group:RDSOSMetrics:log-stream:db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
    "httpEndpointEnabled": false,
    "iAMDatabaseAuthenticationEnabled": false,
    "instanceCreateTime": "Aug 5, 2022 9:02:51 AM",
    "kmsKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
    "latestRestorableTime": "Aug 5, 2022 9:12:31 AM",
    "licenseModel": "postgresql-license",
    "masterUsername": "postgres",
    "monitoringInterval": 60,
    "monitoringRoleArn": "arn:aws:iam::111111111111:role/rds-monitoring-role",
    "multiAZ": false,
    "networkType": "IPV4",
    "optionGroupMemberships": [
      {
        "optionGroupName": "default:postgres-14",
        "status": "in-sync"
      }
    ],
    "pendingModifiedValues": {
      "masterUserPassword": "****"
    },
    "performanceInsightsEnabled": true,
    "performanceInsightsKMSKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
    "performanceInsightsRetentionPeriod": 7,
    "preferredBackupWindow": "06:35-07:05",
    "preferredMaintenanceWindow": "sat:11:44-sat:12:14",
    "publiclyAccessible": false,
    "readReplicaDBInstanceIdentifiers": [],
    "storageEncrypted": true,
    "storageThroughput": 0,
    "storageType": "standard",
    "tagList": [],
    "vpcSecurityGroups": [
      {
        "status": "active",
        "vpcSecurityGroupId": "sg-46cfd020"
      }
    ]
  },
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "AWS Internal",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLAKJDBQGB",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
    "principalId": "AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com",
    "sessionContext": {
      "attributes": {
        "creationDate": "2022-08-05T08:47:55Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
        "principalId": "AROAYTOGP2RLDF6WP4HD6",
        "type": "Role",
        "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCodeis_null3 ruleskusto, panther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS RDS DB Instance or Cluster Deletion Protection Disabled source medium: Identifies the modification of an AWS RDS DB instance or cluster to disable the deletionProtection feature. Deletion protection prevents accidental or unauthorized deletion of RDS resources. Adversaries with sufficient permissions may disable this protection as a precursor to destructive actions, including the deletion of databases containing sensitive or business-critical data. This rule alerts when deletionProtection is explicitly set to false on an RDS DB instance or cluster.T1485, T1578, T1578.005↳ also matches ModifyDBCluster
  • AWS RDS Snapshot Deleted source medium: Identifies the deletion of an AWS RDS DB snapshot or configuration changes that effectively remove backup coverage for a DB instance. RDS snapshots contain full backups of database instances, and disabling automated backups by setting "backupRetentionPeriod=0" has a similar impact by preventing future restore points. Adversaries with the appropriate permissions may delete snapshots or disable backups to inhibit recovery, destroy forensic evidence, or prepare for follow-on destructive actions such as instance or cluster deletion.T1485, T1490↳ also matches DeleteDBClusterSnapshot, DeleteDBSnapshot
  • AWS RDS DB Instance or Cluster Password Modified source medium: Identifies the modification of the master password for an AWS RDS DB instance or cluster. Changing the master password is a legitimate recovery action when access is lost, but adversaries with sufficient permissions may modify it to regain access, establish persistence, bypass existing controls, or escalate privileges within a compromised environment. Because RDS does not expose the password in API responses, this operation can meaningfully alter access pathways to sensitive data stores.T1098, T1098.001↳ also matches ModifyDBCluster

Splunk #

Kusto #

Panther #

References #

ModifyDBSnapshotAttribute

#
Service
rds

Description

Adds or removes attributes on a manual DB snapshot, including cross-account copy and restore permissions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2d19ab1e-82e9-4302-ad10-a405b50c8d49",
  "eventName": "ModifyDBSnapshotAttribute",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:22:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "d6d4e27c-49b8-4eaa-971d-601d4368846d",
  "requestParameters": {
    "attributeName": "restore",
    "dBSnapshotIdentifier": "exfiltration",
    "valuesToAdd": [
      "193672423079"
    ]
  },
  "responseElements": {
    "dBSnapshotAttributes": [
      {
        "attributeName": "restore",
        "attributeValues": [
          "193672423079"
        ]
      }
    ],
    "dBSnapshotIdentifier": "exfiltration"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Snapshot Shared with Another Account source medium: Identifies when an AWS RDS DB snapshot is shared with another AWS account or made public. DB snapshots contain complete backups of database instances, including schemas, table data, and sensitive application content. When shared externally, snapshots can be restored in another AWS environment, enabling unauthorized access, offline analysis, or data exfiltration. Adversaries who obtain valid credentials or exploit misconfigurations may modify snapshot attributes to grant access to accounts they control, bypassing network, IAM, and monitoring controls.T1537↳ also matches ModifyDBClusterSnapshotAttribute

YARA-L #

Panther #

References #

RestoreDBInstanceFromDBSnapshot

#
Service
rds

Description

Creates a new DB instance from a DB snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:RestoreDBInstanceFromDBSnapshot on resource: arn:aws:rds:us-west-2:811596193553:db:vol-8e100f305b7a6fef3",
  "eventID": "39b68aa6-4805-4fc8-af84-0381cd75282b",
  "eventName": "RestoreDBInstanceFromDBSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2020-05-16T20:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0d2cceb2-8bfe-48b5-8011-c8026be025d5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.63.7.255",
  "userAgent": "aws-cli/1.14.44 Python/3.6.9 Linux/5.3.0-51-generic botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS RDS DB Instance Restored source medium: Identifies the restoration of an AWS RDS database instance from a snapshot or S3 backup. Adversaries with access to valid credentials may restore copies of existing databases to bypass logging and monitoring controls or to exfiltrate sensitive data from a duplicated environment. This rule detects successful restoration operations using "RestoreDBInstanceFromDBSnapshot" or "RestoreDBInstanceFromS3", which may indicate unauthorized data access or post-compromise defense evasion.T1074, T1074.002, T1578, T1578.002, T1578.004↳ also matches RestoreDBInstanceFromS3

Panther #

References #

RestoreDBInstanceFromS3

#
Service
rds

Description

Creates a new DB instance from a MySQL database backup stored in Amazon S3.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS DB Instance Restored source medium: Identifies the restoration of an AWS RDS database instance from a snapshot or S3 backup. Adversaries with access to valid credentials may restore copies of existing databases to bypass logging and monitoring controls or to exfiltrate sensitive data from a duplicated environment. This rule detects successful restoration operations using "RestoreDBInstanceFromDBSnapshot" or "RestoreDBInstanceFromS3", which may indicate unauthorized data access or post-compromise defense evasion.T1074, T1074.002, T1578, T1578.002, T1578.004↳ also matches RestoreDBInstanceFromDBSnapshot

RevokeDBSecurityGroupIngress

#
Service
rds

Description

Revokes ingress from a DB security group for previously authorized IP ranges or EC2 security groups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSecurityGroupNotFoundFault",
  "errorMessage": "DBSecurityGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "c0f54107-344b-4abb-9efc-7b7ac399256f",
  "eventName": "RevokeDBSecurityGroupIngress",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "34c4da8c-f977-41be-9987-990919906342",
  "requestParameters": {
    "dBSecurityGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

StartExportTask

#
Service
rds

Description

Starts an export of DB snapshot or DB cluster data to Amazon S3 in Parquet format.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Cross-account pass role is not allowed.",
  "eventCategory": "Management",
  "eventID": "f4bca42d-d427-424d-894a-cf968af4c8c8",
  "eventName": "StartExportTask",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2024-08-18T15:44:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1087c7dc-a750-4b8c-86f7-f0f4316fba2e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_507e6b2d-9561-4119-be31-e29bfee30f4d cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#rds.start-export-task",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS RDS Snapshot Export source high: Identifies the export of a DB snapshot or DB cluster data to Amazon S3. Snapshot exports can be used for analytics or migration workflows, but adversaries may abuse them to exfiltrate sensitive data outside of RDS-managed storage. Exporting a snapshot creates a portable copy of the database contents, which, if performed without authorization, can indicate data theft, staging for exfiltration, or operator misconfiguration that exposes regulated information.T1213, T1213.006, T1567, T1567.002

Panther #

  • AWS RDS Snapshot Exported to S3 source high: Detects when an RDS snapshot is exported to S3 using StartExportTask. Attackers use this to exfiltrate database contents by exporting snapshots to buckets they control. While snapshot exports are legitimate for analytics, they provide complete database access.T1537

References #

AddRoleToDBCluster

#
Service
rds

Description

Associates an Identity and Access Management (IAM) role with an Neptune DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "DBCluster not found: dwfix-aurora-cl",
  "eventCategory": "Management",
  "eventID": "5d0a5e7d-55be-42a3-b995-0109d0b46b29",
  "eventName": "AddRoleToDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "104fe301-bf71-414e-850f-5aa845d2cfa8",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl",
    "featureName": "s3Export",
    "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

AddRoleToDBInstance

#
Service
rds

Description

Associates an Amazon Web Services Identity and Access Management (IAM) role with a DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance not found: dwfix-aurora-inst",
  "eventCategory": "Management",
  "eventID": "6c2e7b92-3813-4ed9-a979-c199e9ab290b",
  "eventName": "AddRoleToDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0581a30c-289f-48cd-bc1b-9e7d6c8d142b",
  "requestParameters": {
    "dBInstanceIdentifier": "dwfix-aurora-inst",
    "featureName": "s3Export",
    "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

AddSourceIdentifierToSubscription

#
Service
rds

Description

Adds a source identifier to an existing event notification subscription.

AddTagsToResource

#
Service
rds

Description

Adds metadata tags to an Amazon DocumentDB resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2c7e5443-6380-436a-9915-1a9bf290b52a",
  "eventName": "AddTagsToResource",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5da9cca1-a5b8-452d-8c7e-82524dda102b",
  "requestParameters": {
    "resourceName": "arn:aws:rds:us-west-1:123456789012:pg:dwfix-pg",
    "tags": [
      {
        "key": "dw",
        "value": "f"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ApplyPendingMaintenanceAction

#
Service
rds

Description

Applies a pending maintenance action to a resource (for example, to an Amazon DocumentDB instance).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterCombinationException",
  "errorMessage": "There is no pending system-update action for arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl",
  "eventCategory": "Management",
  "eventID": "0cfe758f-88ae-4bee-890d-d05852a41e31",
  "eventName": "ApplyPendingMaintenanceAction",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:50:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5af2abdd-eb85-4e48-a6d1-1539ea50e56d",
  "requestParameters": {
    "applyAction": "system-update",
    "optInType": "undo-opt-in",
    "resourceIdentifier": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

BacktrackDBCluster

#
Service
rds

Description

Backtracks a DB cluster to a specific time, without creating a new DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "Could not find specified DB Cluster",
  "eventCategory": "Management",
  "eventID": "41f15628-d5f0-492f-832f-b305ee77d64b",
  "eventName": "BacktrackDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a9383d3-4dcc-4d83-a25f-8113916373e4",
  "requestParameters": {
    "backtrackTo": "Jun 29, 2026, 10:35:01 PM",
    "dBClusterIdentifier": "dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelExportTask

#
Service
rds

Description

Cancels an export task in progress that is exporting a snapshot or cluster to Amazon S3.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ExportTaskNotFoundFault",
  "errorMessage": "The export task dw-probe doesn't exist.",
  "eventCategory": "Management",
  "eventID": "f172af85-24b2-41d9-93c3-943501a5ef2f",
  "eventName": "CancelExportTask",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "68f69ced-cb6c-43b9-b6ea-24d81832663e",
  "requestParameters": {
    "exportTaskIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CopyDBClusterParameterGroup

#
Service
rds

Description

Copies the specified cluster parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3b28ba6c-dbd0-45f0-bdb5-8bed4c154e40",
  "eventName": "CopyDBClusterParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "171c0663-dec8-436b-9dd8-d900971900c3",
  "requestParameters": {
    "sourceDBClusterParameterGroupIdentifier": "dwfix-aurora-pg",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "targetDBClusterParameterGroupDescription": "dwfix copy of aurora cluster PG",
    "targetDBClusterParameterGroupIdentifier": "dwfix-aurora-pg-copy"
  },
  "responseElements": {
    "dBClusterParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:cluster-pg:dwfix-aurora-pg-copy",
    "dBClusterParameterGroupName": "dwfix-aurora-pg-copy",
    "dBParameterGroupFamily": "aurora-mysql8.0",
    "description": "dwfix copy of aurora cluster PG"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CopyDBClusterSnapshot

#
Service
rds

Description

Copies a snapshot of a cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterSnapshotNotFoundFault",
  "errorMessage": "DBClusterSnapshot not found: dwfix-aurora-snap",
  "eventCategory": "Management",
  "eventID": "e3955c6b-984e-4ef5-bb0d-706d9e81660c",
  "eventName": "CopyDBClusterSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d5403a0a-a4f4-4ad6-8112-852e443c3a16",
  "requestParameters": {
    "sourceDBClusterSnapshotIdentifier": "dwfix-aurora-snap",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "targetDBClusterSnapshotIdentifier": "dwfix-aurora-snap-copy"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • AWS RDS Snapshot Copied Cross-Region source medium: Detects when RDS snapshots are copied to different AWS regions. While legitimate for disaster recovery, cross-region snapshot copies can be used for data exfiltration or to prepare snapshots for sharing with external accounts.T1537↳ also matches CopyDBSnapshot

CopyDBParameterGroup

#
Service
rds

Description

Copies the specified DB parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The parameter DBParameterGroupName is not a valid identifier. Identifiers must begin with a letter; must contain only ASCII letters, digits, and hyphens; and must not end with a hyphen or contain two consecutive hyphens.",
  "eventCategory": "Management",
  "eventID": "f3e0076a-adb8-4098-bcbb-f290de80cc3d",
  "eventName": "CopyDBParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "65890272-139e-41ef-b5b7-3dd2fee4a295",
  "requestParameters": {
    "sourceDBParameterGroupIdentifier": "default.aurora-mysql8.0",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "targetDBParameterGroupDescription": "dwfix copy of aurora-mysql8.0 instance PG",
    "targetDBParameterGroupIdentifier": "dwfix-inst-pg-copy"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CopyDBSnapshot

#
Service
rds

Description

Copies the specified DBSnapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "19a4e40d-ea26-4842-9892-49c40ca2ce92",
  "eventName": "CopyDBSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:16:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6791bea2-70ec-4c2c-8845-9a6c6b9f91e0",
  "requestParameters": {
    "sourceDBSnapshotIdentifier": "dwfix-snap",
    "targetDBSnapshotIdentifier": "dwfix-snap2"
  },
  "responseElements": {
    "allocatedStorage": 20,
    "backupRetentionPeriod": 0,
    "dBInstanceIdentifier": "dwfix-db",
    "dBSnapshotArn": "arn:aws:rds:us-west-1:123456789012:snapshot:dwfix-snap2",
    "dBSnapshotIdentifier": "dwfix-snap2",
    "dbiResourceId": "db-4R7RSIWQWQ3B6KT64HCC5BEO5Y",
    "dedicatedLogVolume": false,
    "encrypted": false,
    "engine": "mysql",
    "engineVersion": "8.4.8",
    "iAMDatabaseAuthenticationEnabled": false,
    "instanceCreateTime": "Jun 29, 2026, 8:10:46 PM",
    "licenseModel": "general-public-license",
    "masterUsername": "admin",
    "multiTenant": false,
    "optionGroupName": "default:mysql-8-4",
    "originalSnapshotCreateTime": "Jun 29, 2026, 8:14:16 PM",
    "percentProgress": 0,
    "port": 3306,
    "preferredBackupWindow": "08:45-09:15",
    "processorFeatures": [],
    "snapshotCreateTime": "Jun 29, 2026, 8:12:16 PM",
    "snapshotTarget": "region",
    "snapshotType": "manual",
    "sourceDBSnapshotIdentifier": "arn:aws:rds:us-west-1:123456789012:snapshot:dwfix-snap",
    "sourceRegion": "us-west-1",
    "status": "creating",
    "storageEncryptionType": "none",
    "storageThroughput": 0,
    "storageType": "gp2",
    "tagList": [],
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CopyOptionGroup

#
Service
rds

Description

Copies the specified option group.

CreateBlueGreenDeployment

#
Service
rds

Description

Creates a blue/green deployment.

CreateCustomDBEngineVersion

#
Service
rds

Description

Creates a custom DB engine version (CEV).

CreateDBClusterEndpoint

#
Service
rds

Description

Creates a new custom endpoint and associates it with an Amazon Neptune DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "The source cluster could not be found or cannot be accessed: dwfix-aurora-cl",
  "eventCategory": "Management",
  "eventID": "2ad59d1d-44fc-483a-b605-9baad9978ae8",
  "eventName": "CreateDBClusterEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "82f93d46-d79c-4451-acdc-883ae401c2ae",
  "requestParameters": {
    "dBClusterEndpointIdentifier": "dwfix-aurora-ep",
    "dBClusterIdentifier": "dwfix-aurora-cl",
    "endpointType": "READER",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDBClusterParameterGroup

#
Service
rds

Description

Creates a new cluster parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3b4ac246-fc79-418f-ac56-89d9b10624fe",
  "eventName": "CreateDBClusterParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "607a6a16-7f03-4053-ba98-62637ef407eb",
  "requestParameters": {
    "dBClusterParameterGroupName": "dwfix-cpg",
    "dBParameterGroupFamily": "aurora-mysql8.0",
    "description": "dw"
  },
  "responseElements": {
    "dBClusterParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:cluster-pg:dwfix-cpg",
    "dBClusterParameterGroupName": "dwfix-cpg",
    "dBParameterGroupFamily": "aurora-mysql8.0",
    "description": "dw"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDBInstanceReadReplica

#
Service
rds

Description

Creates a DB instance that acts as a Read Replica of a source DB instance.

CreateDBParameterGroup

#
Service
rds

Description

Creates a new DB parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "82a13ccc-8d2b-46dc-bddd-7b2319eaf5f6",
  "eventName": "CreateDBParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eb24ef0d-cf6d-410b-94e1-6c585f33b4c6",
  "requestParameters": {
    "dBParameterGroupFamily": "mysql8.0",
    "dBParameterGroupName": "dwfix-pg",
    "description": "dw"
  },
  "responseElements": {
    "dBParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:pg:dwfix-pg",
    "dBParameterGroupFamily": "mysql8.0",
    "dBParameterGroupName": "dwfix-pg",
    "description": "dw"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDBProxy

#
Service
rds

Description

Creates a new DB proxy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c5152636-58fc-4b58-ae3d-cecc7f6c0793",
  "eventName": "CreateDBProxy",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:05:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "74e4098a-c901-4a65-81fa-41a4496e302b",
  "requestParameters": {
    "auth": [
      {
        "authScheme": "SECRETS",
        "iAMAuth": "DISABLED",
        "secretArn": "arn:aws:secretsmanager:us-west-1:123456789012:secret:dwfix-rds-secret-iRLiD0"
      }
    ],
    "dBProxyName": "dwfix-rds-proxy",
    "debugLogging": false,
    "engineFamily": "MYSQL",
    "requireTLS": false,
    "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "vpcSubnetIds": [
      "subnet-0c9f719882f5c95ae",
      "subnet-04caa2ba1250f8fb6"
    ]
  },
  "responseElements": {
    "dBProxy": {
      "auth": [
        {
          "authScheme": "SECRETS",
          "clientPasswordAuthType": "MYSQL_CACHING_SHA2_PASSWORD",
          "iAMAuth": "DISABLED",
          "secretArn": "arn:aws:secretsmanager:us-west-1:123456789012:secret:dwfix-rds-secret-iRLiD0"
        }
      ],
      "createdDate": "2026-06-29T23:05:09Z",
      "dBProxyArn": "arn:aws:rds:us-west-1:123456789012:db-proxy:prx-039d3b611bb0b1c65",
      "dBProxyName": "dwfix-rds-proxy",
      "debugLogging": false,
      "defaultAuthScheme": "NONE",
      "endpoint": "dwfix-rds-proxy.proxy-cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
      "endpointNetworkType": "IPV4",
      "engineFamily": "MYSQL",
      "idleClientTimeout": 1800,
      "requireTLS": false,
      "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role",
      "status": "creating",
      "targetConnectionNetworkType": "IPV4",
      "vpcId": "vpc-0cf63cfb072f7d61f",
      "vpcSecurityGroupIds": [
        "sg-063fc1a8302bc48a4"
      ],
      "vpcSubnetIds": [
        "subnet-0c9f719882f5c95ae",
        "subnet-04caa2ba1250f8fb6"
      ]
    }
  },
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T23:05:08Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDBProxyEndpoint

#
Service
rds

Description

Creates a DBProxyEndpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "73a1808e-5d88-4c8b-88cc-cee3f9e8d5f5",
  "eventName": "CreateDBProxyEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "49d09d9a-2b48-433f-8231-9c36cea7db97",
  "requestParameters": {
    "dBProxyEndpointName": "dwfix-rds-proxy-ep",
    "dBProxyName": "dwfix-rds-proxy",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "targetRole": "READ_WRITE",
    "vpcSubnetIds": [
      "subnet-0c9f719882f5c95ae",
      "subnet-04caa2ba1250f8fb6"
    ]
  },
  "responseElements": {
    "dBProxyEndpoint": {
      "createdDate": "2026-06-29T23:10:41Z",
      "dBProxyEndpointArn": "arn:aws:rds:us-west-1:123456789012:db-proxy-endpoint:prx-endpoint-0bcdbb60003e9e7f0",
      "dBProxyEndpointName": "dwfix-rds-proxy-ep",
      "dBProxyName": "dwfix-rds-proxy",
      "endpoint": "dwfix-rds-proxy-ep.endpoint.proxy-cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
      "endpointNetworkType": "IPV4",
      "endpointType": "CUSTOM",
      "isDefault": false,
      "status": "creating",
      "targetRole": "READ_WRITE",
      "vpcId": "vpc-0cf63cfb072f7d61f",
      "vpcSecurityGroupIds": [
        "sg-063fc1a8302bc48a4"
      ],
      "vpcSubnetIds": [
        "subnet-0c9f719882f5c95ae",
        "subnet-04caa2ba1250f8fb6"
      ]
    }
  },
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T23:09:39Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDBShardGroup

#
Service
rds

Description

Creates a new DB shard group for Aurora Limitless Database.

CreateDBSubnetGroup

#
Service
rds

Description

Creates a new subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "726b9d86-35ea-49a3-b87a-2c44f9b5ddad",
  "eventName": "CreateDBSubnetGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:15:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "1c4b0074-47c4-4ed7-84e7-9e77445e4caf",
  "requestParameters": {
    "dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
    "dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
    "subnetIds": [
      "subnet-0cac13291c6f317ec",
      "subnet-0c8a70cf4fd24084f"
    ],
    "tags": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      },
      {
        "key": "Name",
        "value": "stratus-red-team-share-snap-vpc"
      }
    ]
  },
  "responseElements": {
    "dBSubnetGroupArn": "arn:aws:rds:us-east-1:123837392027:subgrp:stratus-red-team-share-snap-vpc",
    "dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
    "dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
    "subnetGroupStatus": "Complete",
    "subnets": [
      {
        "subnetAvailabilityZone": {
          "name": "us-east-1a"
        },
        "subnetIdentifier": "subnet-0cac13291c6f317ec",
        "subnetOutpost": {},
        "subnetStatus": "Active"
      },
      {
        "subnetAvailabilityZone": {
          "name": "us-east-1b"
        },
        "subnetIdentifier": "subnet-0c8a70cf4fd24084f",
        "subnetOutpost": {},
        "subnetStatus": "Active"
      }
    ],
    "supportedNetworkTypes": [
      "IPV4"
    ],
    "vpcId": "vpc-07b33857c7ad1c027"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateEventSubscription

#
Service
rds

Description

Creates an Amazon DocumentDB event notification subscription.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "SNSTopicArnNotFoundFault",
  "errorMessage": "Failed to create Subscription because of Topic arn:aws:sns:us-west-1:123456789012:nonexistent Not Found.",
  "eventCategory": "Management",
  "eventID": "fed51df5-43cb-483e-8e1e-6df7222c7e2e",
  "eventName": "CreateEventSubscription",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "69223f30-76d7-4057-b398-ccf4aac94f83",
  "requestParameters": {
    "snsTopicArn": "arn:aws:sns:us-west-1:123456789012:nonexistent",
    "subscriptionName": "dwfix-es"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateGlobalCluster

#
Service
rds

Description

Creates an Amazon DocumentDB global cluster that can span multiple multiple Amazon Web Services Regions.

CreateIntegration

#
Service
rds

Description

Creates a zero-ETL integration with Amazon Redshift.

CreateOptionGroup

#
Service
rds

Description

Creates a new option group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "842a2d40-93bf-4b89-b786-ce88933827d3",
  "eventName": "CreateOptionGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "53bb303a-3b0d-47b4-9abb-e6fd69364f41",
  "requestParameters": {
    "engineName": "mysql",
    "majorEngineVersion": "8.0",
    "optionGroupDescription": "dw",
    "optionGroupName": "dwfix-og"
  },
  "responseElements": {
    "allowsVpcAndNonVpcInstanceMemberships": true,
    "engineName": "mysql",
    "majorEngineVersion": "8.0",
    "optionGroupArn": "arn:aws:rds:us-west-1:123456789012:og:dwfix-og",
    "optionGroupDescription": "dw",
    "optionGroupName": "dwfix-og",
    "options": []
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTenantDatabase

#
Service
rds

Description

Creates a tenant database in a DB instance that uses the multi-tenant configuration.

DeleteBlueGreenDeployment

#
Service
rds

Description

Deletes a blue/green deployment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BlueGreenDeploymentNotFoundFault",
  "errorMessage": "Blue Green Deployment 'ddddd' doesn't exist.",
  "eventCategory": "Management",
  "eventID": "7f4ae431-9c37-44bb-93a5-7ee94f4696a9",
  "eventName": "DeleteBlueGreenDeployment",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6cbcf1fe-0314-49db-9617-4f70717aa2de",
  "requestParameters": {
    "blueGreenDeploymentIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCustomDBEngineVersion

#
Service
rds

Description

Deletes a custom engine version.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "The custom engine version you requested may not exist or you don't have the required permission.",
  "eventCategory": "Management",
  "eventID": "59e1d6dd-9993-4700-8e79-693d40c09bee",
  "eventName": "DeleteCustomDBEngineVersion",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "46eadd9f-817f-4fe4-a23b-faa148a8e828",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBClusterAutomatedBackup

#
Service
rds

Description

Deletes automated backups using the DbClusterResourceId value of the source DB cluster or the Amazon Resource Name (ARN) of the automated backups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The parameter db-cluster-resource-id isn't a valid DbClusterResourceId. The DbClusterResourceId must begin with the prefix cluster- and contain only ASCII letters and digits.",
  "eventCategory": "Management",
  "eventID": "3774e05b-3263-4c96-a97a-c45fbe4d0044",
  "eventName": "DeleteDBClusterAutomatedBackup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0ab8ae93-98d5-4653-9ca2-52b69dba4a7a",
  "requestParameters": {
    "dbClusterResourceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteDBClusterEndpoint

#
Service
rds

Description

Deletes a custom endpoint and removes it from an Amazon Neptune DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterEndpointNotFoundFault",
  "errorMessage": "DBClusterEndpoint dw-probe not found",
  "eventCategory": "Management",
  "eventID": "004d6b43-9d13-49e8-ac2d-b012d396eeeb",
  "eventName": "DeleteDBClusterEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6be982cb-15f5-4286-bbf3-08ec0d15f32d",
  "requestParameters": {
    "dBClusterEndpointIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBClusterParameterGroup

#
Service
rds

Description

Deletes a specified cluster parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBClusterParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "29f34925-ae1f-4d5a-8a9f-2813ba0c3f36",
  "eventName": "DeleteDBClusterParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "02e8d173-34fc-4a47-a09f-9751de64831c",
  "requestParameters": {
    "dBClusterParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBInstanceAutomatedBackup

#
Service
rds

Description

Deletes automated backups using the DbiResourceId value of the source DB instance or the Amazon Resource Name (ARN) of the automated backups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "You must enter either DbInstanceAutomatedBackupsArn or DbiResourceId.",
  "eventCategory": "Management",
  "eventID": "15d20f64-4ae7-4f27-941c-f38b777c66b0",
  "eventName": "DeleteDBInstanceAutomatedBackup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:45:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6bcff2d5-2b5c-4376-a323-14c48cc1811c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteDBParameterGroup

#
Service
rds

Description

Deletes a specified DBParameterGroup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "9ad975e7-b4cb-43b6-82ca-e25a694d133f",
  "eventName": "DeleteDBParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d8627746-22ae-4d05-bbfc-e7a1b1a433fa",
  "requestParameters": {
    "dBParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBProxy

#
Service
rds

Description

Deletes an existing DB proxy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "35df340f-5744-40e6-88a6-61a55961df3d",
  "eventName": "DeleteDBProxy",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f6eda1a7-2b60-4aff-bd1b-393f2d894f4e",
  "requestParameters": {
    "dBProxyName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:58Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBProxyEndpoint

#
Service
rds

Description

Deletes a DBProxyEndpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyEndpointNotFoundFault",
  "errorMessage": "DBProxyEndpoint 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "aed23f99-b301-48df-abb3-04fe3627258d",
  "eventName": "DeleteDBProxyEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8ce32283-8f14-4f68-9fbb-723bec98f1bb",
  "requestParameters": {
    "dBProxyEndpointName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:58Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBShardGroup

#
Service
rds

Description

Deletes an Aurora Limitless Database DB shard group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBShardGroupNotFoundFault",
  "errorMessage": "DB shard group not found or can not be accessed",
  "eventCategory": "Management",
  "eventID": "a51fe6f1-be94-40ec-84d9-f35d55d65be5",
  "eventName": "DeleteDBShardGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7ba32d1b-320c-429b-aed4-e10daa8c242b",
  "requestParameters": {
    "dBShardGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDBSubnetGroup

#
Service
rds

Description

Deletes a subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSubnetGroupNotFoundFault",
  "errorMessage": "DB subnet group 'dw-probe' does not exist.",
  "eventCategory": "Management",
  "eventID": "e43ec713-9120-4004-8e70-d98842eb5227",
  "eventName": "DeleteDBSubnetGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "822bfc13-f6fe-4038-b7f9-fb1c72aef36b",
  "requestParameters": {
    "dBSubnetGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteEventSubscription

#
Service
rds

Description

Deletes an Amazon DocumentDB event notification subscription.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "SubscriptionNotFoundFault",
  "errorMessage": "Event Subscription dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "0cb7b7fd-3228-426a-82a4-cd530a4003a9",
  "eventName": "DeleteEventSubscription",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "243e0e80-0f54-4977-b0af-95da825de5ef",
  "requestParameters": {
    "subscriptionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIntegration

#
Service
rds

Description

Deletes a zero-ETL integration with Amazon Redshift.

DeleteOptionGroup

#
Service
rds

Description

Deletes an existing option group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "OptionGroupNotFoundFault",
  "errorMessage": "Specified OptionGroupName: dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "9d084e30-6bd4-483c-8e91-45acb6014b68",
  "eventName": "DeleteOptionGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fef2925a-e7c3-4270-acec-8c2bba2dd7ba",
  "requestParameters": {
    "optionGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTenantDatabase

#
Service
rds

Description

Deletes a tenant database from your DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "611088e5-06fa-40c4-9c2c-fc6dc0440aaf",
  "eventName": "DeleteTenantDatabase",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "43e04f5c-1c30-4402-82ae-80fa9f3bc964",
  "requestParameters": {
    "dBInstanceIdentifier": "dw-probe",
    "skipFinalSnapshot": false,
    "tenantDBName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterDBProxyTargets

#
Service
rds

Description

Remove the association between one or more DBProxyTarget data structures and a DBProxyTargetGroup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "e98492a8-7351-4d5c-a471-2606d7c104a4",
  "eventName": "DeregisterDBProxyTargets",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7d817d8b-7fe3-4319-b08d-f34dd452fcdd",
  "requestParameters": {
    "dBProxyName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:59Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountAttributes

#
Service
rds

Description

Lists all of the attributes for a customer account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b73a8e9d-7b64-43a0-b6ec-f9fa72ec5d18",
  "eventName": "DescribeAccountAttributes",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "cd303e63-76df-4bd2-a2f5-38cea268f1df",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeBlueGreenDeployments

#
Service
rds

Description

Describes one or more blue/green deployments.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f87c126e-ff77-4c8b-9277-267c81b11c68",
  "eventName": "DescribeBlueGreenDeployments",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "4098a577-4037-4fb0-b1ef-3f02e31ca1b4",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeCertificates

#
Service
rds

Description

Returns a list of certificate authority (CA) certificates provided by Amazon DocumentDB for this Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8981c57b-d61a-49f3-b134-a1c6d1674157",
  "eventName": "DescribeCertificates",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "3c442b66-1f11-4c80-b4e0-7a30aeef725e",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDBClusterAutomatedBackups

#
Service
rds

Description

Displays backups for both current and deleted DB clusters.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7a1f1365-66aa-42b6-8d72-afcaa94ebb43",
  "eventName": "DescribeDBClusterAutomatedBackups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d8cbe827-6fd8-460f-9197-d141c2d8b034",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBClusterBacktracks

#
Service
rds

Description

Returns information about backtracks for a DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "Could not find specified DB Cluster",
  "eventCategory": "Management",
  "eventID": "629f6650-efc4-48d0-98b6-d9d31ad77170",
  "eventName": "DescribeDBClusterBacktracks",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cf2ed184-8981-4b78-a55e-215366c52a33",
  "requestParameters": {
    "dBClusterIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBClusterEndpoints

#
Service
rds

Description

Returns information about endpoints for an Amazon Neptune DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "fab10466-28ed-4ce8-9300-45298faceb4",
  "eventName": "DescribeDBClusterEndpoints",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2019-07-02T20:36:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "b2effafc-6810-43ad-9fba-68dc01e3f07a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.52.31.206",
  "userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeDBClusterParameterGroups

#
Service
rds

Description

Returns a list of DBClusterParameterGroup descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6e669813-bca3-4a5d-a1f1-dd26e88345c0",
  "eventName": "DescribeDBClusterParameterGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "ace5e4a6-6ee0-4797-a8af-078b3e20d202",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDBClusterParameters

#
Service
rds

Description

Returns the detailed parameter list for a particular cluster parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBClusterParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "9fe3cc58-579c-413d-91ce-15e43c88005f",
  "eventName": "DescribeDBClusterParameters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "609fa507-8fa1-4bb6-84d1-ae71ad938f53",
  "requestParameters": {
    "dBClusterParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBClusters

#
Service
rds

Description

Returns information about provisioned Amazon DocumentDB clusters.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7781c787-f07f-47d8-900e-6456f15ff82f",
  "eventName": "DescribeDBClusters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "64e4d8e9-c216-4572-94d7-2edb3d392665",
  "requestParameters": {
    "includeShared": true
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDBClusterSnapshotAttributes

#
Service
rds

Description

Returns a list of cluster snapshot attribute names and values for a manual DB cluster snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterSnapshotNotFoundFault",
  "errorMessage": "DBClusterSnapshot not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "495ddcd9-f860-4bac-976a-ac601f82bb98",
  "eventName": "DescribeDBClusterSnapshotAttributes",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7c852f64-8e7f-4a94-b893-bce6b777b9ca",
  "requestParameters": {
    "dBClusterSnapshotIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBClusterSnapshots

#
Service
rds

Description

Returns information about cluster snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "61a0f81e-f7ae-41ef-9675-09ba66de605c",
  "eventName": "DescribeDBClusterSnapshots",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "781f3f1b-d22f-4bef-ab01-538e8e94cac9",
  "requestParameters": {
    "includePublic": false,
    "includeShared": false
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DescribeDBEngineVersions

#
Service
rds

Description

Returns a list of the available engines.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6fd95e78-7e26-4de6-87fc-8a4fa7394544",
  "eventName": "DescribeDBEngineVersions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "0a7c8907-73ce-46d7-bf30-7c1d338fe818",
  "requestParameters": {
    "defaultOnly": false,
    "listSupportedCharacterSets": true,
    "marker": "bWFyaWFkYgoxMC42LjE0"
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDBInstanceAutomatedBackups

#
Service
rds

Description

Displays backups for both current and deleted instances.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "ef4d7934-bb3d-430a-80de-7128c84333bd",
  "eventName": "DescribeDBInstanceAutomatedBackups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2019-07-02T20:36:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a8bedc23-f7e0-4548-ba20-7a5fb6f60bd5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.52.31.206",
  "userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeDBLogFiles

#
Service
rds

Description

Returns a list of DB log files for the DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "6dff181f-0cc2-400e-8908-78a3fe2ee875",
  "eventName": "DescribeDBLogFiles",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c019a902-c34b-4ac7-a1b4-f9c87704261e",
  "requestParameters": {
    "dBInstanceIdentifier": "dw-probe",
    "fileLastWritten": 0,
    "fileSize": 0
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBMajorEngineVersions

#
Service
rds

Description

Describes the properties of specific major versions of DB engines.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "73624923-4a5e-4c5a-b32e-f3aa9732e66b",
  "eventName": "DescribeDBMajorEngineVersions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "36a6d43a-1dbc-48b6-b36e-18f11bd21824",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBParameterGroups

#
Service
rds

Description

Returns a list of DBParameterGroup descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "491d711a-5d8c-4a74-9d06-ba68fd00056d",
  "eventName": "DescribeDBParameterGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5011b253-0a6c-4923-a841-f5b2638eb5a3",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDBParameters

#
Service
rds

Description

Returns the detailed parameter list for a particular DB parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "015e865b-b822-451a-bc77-3fe7fc04c5b6",
  "eventName": "DescribeDBParameters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4cfc76d5-d15b-4054-ba73-27e8b036ad2e",
  "requestParameters": {
    "dBParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBProxies

#
Service
rds

Description

Returns information about DB proxies.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:DescribeDBProxies on resource: *",
  "eventID": "cb8923b6-3bf1-4a97-a820-412d125fa71e",
  "eventName": "DescribeDBProxies",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2020-06-10T05:32:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "ac29d92c-edf5-409f-a1ec-d0d59b3da622",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA1SGW6G0UATGTBPYU",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "sessionContext": {
      "attributes": {
        "creationDate": "2020-06-10T05:32:42Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeDBProxyEndpoints

#
Service
rds

Description

Returns information about DB proxy endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b3da2f3a-6452-4dc5-9733-4b15603351c5",
  "eventName": "DescribeDBProxyEndpoints",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "849ed635-4090-47cb-a40e-001de317f0a9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T18:32:27Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBProxyTargetGroups

#
Service
rds

Description

Returns information about DB proxy target groups, represented by DBProxyTargetGroup data structures.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "99bc6cc1-b6f9-4353-a700-fcbb8d6247c5",
  "eventName": "DescribeDBProxyTargetGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7f6d5012-6064-4b66-8ead-9036dd6bf8a2",
  "requestParameters": {
    "dBProxyName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T18:45:19Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBProxyTargets

#
Service
rds

Description

Returns information about DBProxyTarget objects.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "fd9f5e15-c1f9-433f-ac5d-f636916b1c68",
  "eventName": "DescribeDBProxyTargets",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3b1c2be9-c138-4846-954d-67d184a491e8",
  "requestParameters": {
    "dBProxyName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T18:45:19Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBRecommendations

#
Service
rds

Description

Describes the recommendations to resolve the issues for your DB instances, DB clusters, and DB parameter groups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0e6e3258-e422-4b02-85ae-ad62cfebbf37",
  "eventName": "DescribeDBRecommendations",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "48c07b07-1b33-42a3-a084-edba0943f292",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBSecurityGroups

#
Service
rds

Description

Returns a list of DBSecurityGroup descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "2e61e3c7-bb96-43c7-ab5e-0304d78fab71",
  "eventName": "DescribeDBSecurityGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2017-03-04T22:12:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "9cfe6765-0127-11e7-b9e9-e1a60774bf",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "3.254.5.251",
  "userAgent": "Boto/2.10.0 (win32)",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeDBShardGroups

#
Service
rds

Description

Describes existing Aurora Limitless Database DB shard groups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0417cad9-17ac-434f-9e19-45660568e134",
  "eventName": "DescribeDBShardGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "537b3231-ecf6-4826-99e8-59b064174584",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBSnapshotAttributes

#
Service
rds

Description

Returns a list of DB snapshot attribute names and values for a manual DB snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSnapshotNotFoundFault",
  "errorMessage": "DBSnapshot not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "adf251bf-b53d-4eb5-afa7-4b5a1f33a4b6",
  "eventName": "DescribeDBSnapshotAttributes",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9798b9e4-caa1-4706-b7c4-7617b69b4af3",
  "requestParameters": {
    "dBSnapshotIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBSnapshotTenantDatabases

#
Service
rds

Description

Describes the tenant databases that exist in a DB snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8a29e9e7-2606-42d3-8d0c-d9736a2354ff",
  "eventName": "DescribeDBSnapshotTenantDatabases",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "09864b42-dffd-4d22-9c71-591d60986f65",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDBSubnetGroups

#
Service
rds

Description

Returns a list of DBSubnetGroup descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "026541c4-3ca9-4fd7-952d-7f9fd5515077",
  "eventName": "DescribeDBSubnetGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:15:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "830a9734-b8df-4b53-bb47-817997a213dc",
  "requestParameters": {
    "dBSubnetGroupName": "stratus-red-team-share-snap-vpc"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeEngineDefaultClusterParameters

#
Service
rds

Description

Returns the default engine and system parameter information for the cluster database engine.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "ParameterGroupFamily dw-probe is not a valid parameter group family",
  "eventCategory": "Management",
  "eventID": "902ea466-ca93-403c-a744-ab44aa6f0604",
  "eventName": "DescribeEngineDefaultClusterParameters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6e5e54e9-237b-4022-b87f-de5cddf977c1",
  "requestParameters": {
    "dBParameterGroupFamily": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEngineDefaultParameters

#
Service
rds

Description

Returns the default engine and system parameter information for the specified database engine.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "ParameterGroupFamily dw-probe is not a valid parameter group family",
  "eventCategory": "Management",
  "eventID": "f5ea8d95-0c21-4f01-9288-6467169086bc",
  "eventName": "DescribeEngineDefaultParameters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4a7e1c7f-390e-4958-851e-3057bf94c9c7",
  "requestParameters": {
    "dBParameterGroupFamily": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEventCategories

#
Service
rds

Description

Displays a list of categories for all event source types, or, if specified, for a specified source type.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "d41e2a20-ec6c-4bd6-8a50-421447bafa9f6",
  "eventName": "DescribeEventCategories",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2018-10-17T20:17:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "fff43f9a-864e-4324-be30-0ddc460b8534",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeEvents

#
Service
rds

Description

Returns events related to instances, security groups, snapshots, and DB parameter groups for the past 14 days.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "ecea916b-8348-4166-ab7d-18be871f30bb",
  "eventName": "DescribeEvents",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "70d98fa6-103e-4a91-b075-d14217e851cf",
  "requestParameters": {
    "duration": 1440
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeEventSubscriptions

#
Service
rds

Description

Lists all the subscription descriptions for a customer account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "5c052932-3417-4553-a355-17bcfec19b4f",
  "eventName": "DescribeEventSubscriptions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "abfb158d-1dcf-4ada-949c-c2d103e0870a",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeExportTasks

#
Service
rds

Description

Returns information about a snapshot or cluster export to Amazon S3.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:DescribeExportTasks",
  "eventID": "da34bd05-b6bc-4139-8dcc-ada5f15447cf",
  "eventName": "DescribeExportTasks",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2020-06-10T05:32:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "b1b89c2a-da4d-4adc-a1d0-a0947b54d88c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeGlobalClusters

#
Service
rds

Description

Returns information about Amazon DocumentDB global clusters.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a292c6c3-0652-4f90-b921-21a76356f7f8",
  "eventName": "DescribeGlobalClusters",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "fbe93792-975f-4dd5-9465-0d5bd106196f",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeIntegrations

#
Service
rds

Description

Describe one or more zero-ETL integrations with Amazon Redshift.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "47ab6f8c-0e74-44dc-942a-bf0234573f8e",
  "eventName": "DescribeIntegrations",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "37af21d9-09ba-4b47-84b3-b71ed304e201",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeOptionGroupOptions

#
Service
rds

Description

Describes all available options.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid DB engine",
  "eventCategory": "Management",
  "eventID": "fa13c179-48a7-4ecd-ab90-196e06f32bc0",
  "eventName": "DescribeOptionGroupOptions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1eb7d0e5-8369-4050-bcfd-1d68dd730c74",
  "requestParameters": {
    "engineName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeOptionGroups

#
Service
rds

Description

Describes the available option groups.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6a29520a-c41e-4282-a27c-6f230ffeab3b",
  "eventName": "DescribeOptionGroups",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "11bf4dba-e1ef-447a-9a63-c802bbc2c1dc",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeOrderableDBInstanceOptions

#
Service
rds

Description

Returns a list of orderable instance options for the specified engine.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "5bb4f93c-6f73-4f40-80e9-d97c55b033af",
  "eventName": "DescribeOrderableDBInstanceOptions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "37bee226-7c1a-44f5-942f-da7f1df1533d",
  "requestParameters": {
    "engine": "sqlserver-ee",
    "engineVersion": "15.00.4312.2.v1",
    "marker": "ZGIucjUuMnhsYXJnZQpsaWNlbnNlLWluY2x1ZGVkCjE1LjAwLjQzMTIuMi52MQpZCmdwMg==",
    "vpc": true
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribePendingMaintenanceActions

#
Service
rds

Description

Returns a list of resources (for example, instances) that have at least one pending maintenance action.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "cddff16f-6b27-42a6-9c64-f4fcfc932ef4",
  "eventName": "DescribePendingMaintenanceActions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:28:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "08e95c0c-c20d-4d9d-924d-bf16d98dc6a6",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeReservedDBInstances

#
Service
rds

Description

Returns information about reserved DB instances for this account, or about a specified reserved DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "7bb78a69-0fac-46af-9d57-d6c2d1eafef0",
  "eventName": "DescribeReservedDBInstances",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2018-10-17T20:17:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "bff42367-e8d2-4097-b500-eb53b693834",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeReservedDBInstancesOfferings

#
Service
rds

Description

Lists available reserved DB instance offerings.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "719594a8f-6e92-45a0-b2e3-87bfd8f4828e",
  "eventName": "DescribeReservedDBInstancesOfferings",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2019-07-02T20:36:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "87efc12f-b31b-4abc-ae19-78f237622d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.52.31.206",
  "userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeServerlessV2PlatformVersions

#
Service
rds

Description

Describes the properties of specific platform versions for Aurora Serverless v2.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dd7b0bc1-bfa9-4b45-8aed-1647e41d5e2d",
  "eventName": "DescribeServerlessV2PlatformVersions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "279d454e-32af-4c52-8508-e362effaa062",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSourceRegions

#
Service
rds

Description

Returns a list of the source Amazon Web Services Regions where the current Amazon Web Services Region can create a read replica, copy a DB snapshot from, or replicate automated backups from.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "f6ed9a29-ab82-45fd-9af8-6cf876c99b27",
  "eventName": "DescribeSourceRegions",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2018-10-17T20:17:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "b1a561c1-0a1b-4b06-9958-0abb230fefd9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTenantDatabases

#
Service
rds

Description

Describes the tenant databases in a DB instance that uses the multi-tenant configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "132d7e61-a820-4d58-ad01-ea6ac014a111",
  "eventName": "DescribeTenantDatabases",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:32:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b4108539-f477-40c7-92b4-7b6021545968",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeValidDBInstanceModifications

#
Service
rds

Description

You can call DescribeValidDBInstanceModifications to learn what modifications you can make to your DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "6754f7f0-c075-4592-9a15-0291ab3bf50c",
  "eventName": "DescribeValidDBInstanceModifications",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T18:45:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5ea93d0c-7295-4743-b7fe-b1f55189a216",
  "requestParameters": {
    "dBInstanceIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableHttpEndpoint

#
Service
rds

Description

Disables the HTTP endpoint for the specified DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterCombinationException",
  "errorMessage": "An unknown error occurred",
  "eventCategory": "Management",
  "eventID": "ed57452a-a4db-4e47-867c-ced2fbcce918",
  "eventName": "DisableHttpEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:50:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9b5da9d6-c5e1-44c9-a18a-f0e6de26a665",
  "requestParameters": {
    "resourceArn": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DownloadDBLogFilePortion

#
Service
rds

Description

Downloads all or a portion of the specified log file.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • AWS RDS Log File Downloaded source low: Detects when RDS database log files are downloaded. Log files may contain credentials, sensitive queries, or application secrets. Bulk downloads from unusual locations may indicate credential harvesting or data reconnaissance.T1552.001

EnableHttpEndpoint

#
Service
rds

Description

Enables the HTTP endpoint for the DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterCombinationException",
  "errorMessage": "An unknown error occurred",
  "eventCategory": "Management",
  "eventID": "58a51782-2fe5-4b95-8790-087053fa8974",
  "eventName": "EnableHttpEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:50:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "84068bff-a1b2-47dc-bf1b-f5ffa4a2d91b",
  "requestParameters": {
    "resourceArn": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

FailoverDBCluster

#
Service
rds

Description

Forces a failover for a cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDBClusterStateFault",
  "errorMessage": "Database cluster:dwfix-aurora-cl should have at least two database instances for failover.",
  "eventCategory": "Management",
  "eventID": "ed3d0423-d58c-4edb-b9bc-c3002786f230",
  "eventName": "FailoverDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d27ef57a-db44-49c3-88a1-0778206bb443",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

FailoverGlobalCluster

#
Service
rds

Description

Promotes the specified secondary DB cluster to be the primary DB cluster in the global cluster when failing over a global cluster occurs.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • AWS RDS Cluster Failover Initiated source medium: Detects when RDS cluster or global cluster failovers are manually initiated. Forced failovers cause brief service interruptions and may indicate disaster recovery testing, operational troubleshooting, or disruption attempts.T1499↳ also matches FailoverDBCluster

ListTagsForResource

#
Service
rds

Description

Lists all tags on an Amazon DocumentDB resource.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "589a2fff-0244-4491-b90a-02474591cb6c",
  "eventName": "ListTagsForResource",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2023-07-10T12:15:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "4b1ebdc0-778b-415f-9970-53e2f9fb0e88",
  "requestParameters": {
    "resourceName": "arn:aws:rds:us-east-1:123837392027:subgrp:stratus-red-team-share-snap-vpc"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

ModifyActivityStream

#
Service
rds

Description

Changes the audit policy state of a database activity stream to either locked (default) or unlocked.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: rds:ModifyActivityStream because no identity-based policy allows the rds:ModifyActivityStream action",
  "eventCategory": "Management",
  "eventID": "e5dfb544-8e8f-42a0-a8a1-182f1adffcd0",
  "eventName": "ModifyActivityStream",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2024-08-18T15:49:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d72b80c4-4492-4fc2-a749-c12e6abd871f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_76ba4fbc-8896-492d-bd45-8de66c9423fd cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#rds.modify-activity-stream",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

References #

ModifyCertificates

#
Service
rds

Description

Override the system-default Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate for Amazon RDS for new DB instances, or remove the override.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "94170d4c-e4a6-43ae-87f7-e51a3feb16c7",
  "eventName": "ModifyCertificates",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "802194c5-3202-4524-9dd1-2a81cb3cd161",
  "requestParameters": {
    "removeCustomerOverride": true
  },
  "responseElements": {
    "certificateArn": "arn:aws:rds:us-west-1::cert:rds-ca-rsa2048-g1",
    "certificateIdentifier": "rds-ca-rsa2048-g1",
    "certificateType": "CA",
    "customerOverride": false,
    "thumbprint": "0f7fb44cf65fc3b2b9133305fd11bc80973a36d5",
    "validFrom": "May 19, 2021, 7:04:06 PM",
    "validTill": "May 19, 2061, 8:04:06 PM"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCurrentDBClusterCapacity

#
Service
rds

Description

Set the capacity of an Aurora Serverless v1 DB cluster to a specific value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "DBCluster dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "d4c9423a-ef41-48c9-ab61-d1ba90b0adf8",
  "eventName": "ModifyCurrentDBClusterCapacity",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eb70486e-4cf7-44d9-9222-683a8d832abb",
  "requestParameters": {
    "dBClusterIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCustomDBEngineVersion

#
Service
rds

Description

Modifies the status of a custom engine version (CEV).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "The custom engine version you requested may not exist or you don't have the required permission.",
  "eventCategory": "Management",
  "eventID": "cdca7bbe-6ed9-4e4b-affa-9e9f268ecd40",
  "eventName": "ModifyCustomDBEngineVersion",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "24e60c91-e95f-47ad-85cd-98b931eddcab",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBClusterEndpoint

#
Service
rds

Description

Modifies the properties of an endpoint in an Amazon Neptune DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterEndpointNotFoundFault",
  "errorMessage": "DBClusterEndpoint dw-probe not found",
  "eventCategory": "Management",
  "eventID": "355669ee-d5b6-4a82-82ae-3462c0b78490",
  "eventName": "ModifyDBClusterEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cc179c45-82aa-45c8-9a99-a3b16cc7f53a",
  "requestParameters": {
    "dBClusterEndpointIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBClusterParameterGroup

#
Service
rds

Description

Modifies the parameters of a cluster parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "Parameter group does not exist",
  "eventCategory": "Management",
  "eventID": "2f510134-1e3d-4de0-b897-52089135cba7",
  "eventName": "ModifyDBClusterParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3dc81995-55be-4f35-b815-d62e28887609",
  "requestParameters": {
    "dBClusterParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBParameterGroup

#
Service
rds

Description

Modifies the parameters of a DB parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "fe0bd158-09e6-4b4a-af84-65e37eab32bc",
  "eventName": "ModifyDBParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0c9e66bb-84c3-43b0-85d8-f8d9df5524af",
  "requestParameters": {
    "dBParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBProxy

#
Service
rds

Description

Changes the settings for an existing DB proxy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "6f26a692-7270-4319-9bbd-8368fd8da80d",
  "eventName": "ModifyDBProxy",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:24:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f71ea064-dda3-48f3-8881-60d4241ad26f",
  "requestParameters": {
    "dBProxyName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:59Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBProxyEndpoint

#
Service
rds

Description

Changes the settings for an existing DB proxy endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyEndpointNotFoundFault",
  "errorMessage": "DBProxyEndpoint 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "430c7773-a667-4c4d-bc7e-96c4a7e9e698",
  "eventName": "ModifyDBProxyEndpoint",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b02a12f1-9db8-4923-bc8f-0ff4ad13c8bb",
  "requestParameters": {
    "dBProxyEndpointName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:59Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBProxyTargetGroup

#
Service
rds

Description

Modifies the properties of a DBProxyTargetGroup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBProxyNotFoundFault",
  "errorMessage": "DBProxy 'ddddd' not found.",
  "eventCategory": "Management",
  "eventID": "51e207a8-d85f-43b3-a60c-1d7296a94cb4",
  "eventName": "ModifyDBProxyTargetGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e9ba07de-938b-4ff0-97a0-aff130a3c1e5",
  "requestParameters": {
    "dBProxyName": "ddddd",
    "targetGroupName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T19:24:59Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBRecommendation

#
Service
rds

Description

Updates the recommendation status and recommended action status for the specified recommendation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBRecommendationNotFoundFault",
  "errorMessage": " The recommendation with ID dw-probe can’t be found.",
  "eventCategory": "Management",
  "eventID": "005eb219-8baa-4613-9c72-4347d811dd29",
  "eventName": "ModifyDBRecommendation",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3003ca7f-a7f5-4ba5-8ca3-84d7cac1778d",
  "requestParameters": {
    "recommendationId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBShardGroup

#
Service
rds

Description

Modifies the settings of an Aurora Limitless Database DB shard group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBShardGroupNotFoundFault",
  "errorMessage": "The DB shard group with requested identifier in requested account doesn't exist.",
  "eventCategory": "Management",
  "eventID": "4b86cc5b-f519-4973-a7e5-ddb77798db2e",
  "eventName": "ModifyDBShardGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cf2d216f-5291-47df-b2b7-fe3ad675892b",
  "requestParameters": {
    "dBShardGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBSnapshot

#
Service
rds

Description

Updates a manual DB snapshot with a new engine version.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSnapshotNotFoundFault",
  "errorMessage": "Could not find snapshot with name dw-probe",
  "eventCategory": "Management",
  "eventID": "33208c54-5fcd-411a-8595-52387b60c6c4",
  "eventName": "ModifyDBSnapshot",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "19a7fa0a-f2f0-478d-9c81-032c257e4446",
  "requestParameters": {
    "dBSnapshotIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDBSubnetGroup

#
Service
rds

Description

Modifies an existing subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBSubnetGroupNotFoundFault",
  "errorMessage": "DB subnet group 'dw-probe' does not exist.",
  "eventCategory": "Management",
  "eventID": "7b344e9f-3ad7-489f-8a69-ec5440e8cfe4",
  "eventName": "ModifyDBSubnetGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dd8cb2ff-2add-437e-9be1-25676043af0f",
  "requestParameters": {
    "dBSubnetGroupName": "dw-probe",
    "subnetIds": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyEventSubscription

#
Service
rds

Description

Modifies an existing Amazon DocumentDB event notification subscription.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "SubscriptionNotFoundFault",
  "errorMessage": "Event Subscription dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "c54fef95-cafe-4d2e-93fa-9413371e552c",
  "eventName": "ModifyEventSubscription",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3f8dc110-2a3b-4dda-bbf2-fe9172a25789",
  "requestParameters": {
    "subscriptionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyGlobalCluster

#
Service
rds

Description

Modify a setting for an Amazon DocumentDB global cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "GlobalClusterNotFoundFault",
  "errorMessage": "Global cluster 'ddddd' not found",
  "eventCategory": "Management",
  "eventID": "1d71db55-49b6-4ad0-9d5c-6f89101180e3",
  "eventName": "ModifyGlobalCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9b6aad86-170d-4259-b02d-53765083b8fb",
  "requestParameters": {
    "globalClusterIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIntegration

#
Service
rds

Description

Modifies a zero-ETL integration with Amazon Redshift.

ModifyOptionGroup

#
Service
rds

Description

Modifies an existing option group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "OptionGroupNotFoundFault",
  "errorMessage": "Specified OptionGroupName: dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "6d7332bb-50dc-4e61-a9a6-49c81f7d7d0d",
  "eventName": "ModifyOptionGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "59228979-c0bd-4e16-a8c4-3311e2454480",
  "requestParameters": {
    "applyImmediately": false,
    "optionGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTenantDatabase

#
Service
rds

Description

Modifies an existing tenant database in a DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "df49e12a-8dea-4501-91a4-7a32e95976f5",
  "eventName": "ModifyTenantDatabase",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e4ea53dd-885d-4fe8-a5c2-4baf9e300d80",
  "requestParameters": {
    "dBInstanceIdentifier": "dw-probe",
    "tenantDBName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PromoteReadReplica

#
Service
rds

Description

Promotes a Read Replica DB instance to a standalone DB instance.

PromoteReadReplicaDBCluster

#
Service
rds

Description

Not supported.

PurchaseReservedDBInstancesOffering

#
Service
rds

Description

Purchases a reserved DB instance offering.

RebootDBCluster

#
Service
rds

Description

You might need to reboot your DB cluster, usually for maintenance reasons.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "The source cluster could not be found or cannot be accessed: dwfix-aurora-cl",
  "eventCategory": "Management",
  "eventID": "13754226-cbca-46ce-ba11-96ad0a163f7c",
  "eventName": "RebootDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T22:40:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "14986bba-3f25-45e0-8398-7936d3fb5ef9",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

RebootDBInstance

#
Service
rds

Description

You might need to reboot your instance, usually for maintenance reasons.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDBInstanceStateFault",
  "errorMessage": "Can only reboot db instances with state in: available, storage-optimization, storage-initialization, incompatible-credentials, incompatible-parameters.  Instance dwfix-db has state: backing-up.",
  "eventCategory": "Management",
  "eventID": "ba7e3a7e-e055-45aa-8d4e-0b20e168b15f",
  "eventName": "RebootDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:16:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "88f04d9e-5243-4eb4-8a72-628c6f61d92e",
  "requestParameters": {
    "dBInstanceIdentifier": "dwfix-db"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

RebootDBShardGroup

#
Service
rds

Description

You might need to reboot your DB shard group, usually for maintenance reasons.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

RegisterDBProxyTargets

#
Service
rds

Description

Associate one or more DBProxyTarget data structures with a DBProxyTargetGroup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5f2bf599-ca6b-4c32-9199-08b3c3d9a030",
  "eventName": "RegisterDBProxyTargets",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5ba5eb3d-dd8e-45b1-85bb-f7506a244e00",
  "requestParameters": {
    "dBClusterIdentifiers": [
      "dwfix-aurora-cl"
    ],
    "dBProxyName": "dwfix-rds-proxy"
  },
  "responseElements": {
    "dBProxyTargets": [
      {
        "port": 3306,
        "rdsResourceId": "dwfix-aurora-cl",
        "targetHealth": {
          "state": "REGISTERING"
        },
        "type": "TRACKED_CLUSTER"
      },
      {
        "endpoint": "dwfix-aurora-inst.cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
        "port": 3306,
        "rdsResourceId": "dwfix-aurora-inst",
        "targetHealth": {
          "state": "REGISTERING"
        },
        "type": "RDS_INSTANCE"
      }
    ]
  },
  "sourceIPAddress": "rds.amazonaws.com",
  "userAgent": "rds.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "invokedBy": "rds.amazonaws.com",
    "principalId": "AIDAEXAMPLE00000000",
    "sessionContext": {
      "attributes": {
        "creationDate": "2026-06-29T23:09:39Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveFromGlobalCluster

#
Service
rds

Description

Detaches an Amazon DocumentDB secondary cluster from a global cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Malformed db cluster arn dw-probe",
  "eventCategory": "Management",
  "eventID": "a1dbca2d-7403-4590-9188-6e1b71099c25",
  "eventName": "RemoveFromGlobalCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "97a1bf3e-1a4c-45d8-867b-2f3039a4dfa7",
  "requestParameters": {
    "dbClusterIdentifier": "dw-probe",
    "globalClusterIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveRoleFromDBCluster

#
Service
rds

Description

Disassociates an Identity and Access Management (IAM) role from a DB cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterRoleNotFoundFault",
  "errorMessage": "Role ARN arn:aws:iam::123456789012:role/dwfix-rds-proxy-role with Feature Name s3Export cannot be found for DB Cluster: dwfix-aurora-cl. Verify your role ARN and try again.",
  "eventCategory": "Management",
  "eventID": "83814f07-3ff5-4bc5-9ed3-6f3c113060d0",
  "eventName": "RemoveRoleFromDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0b3e924e-a22f-4396-a062-5d65e7774573",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl",
    "featureName": "s3Export",
    "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveRoleFromDBInstance

#
Service
rds

Description

Disassociates an Amazon Web Services Identity and Access Management (IAM) role from a DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDBInstanceStateFault",
  "errorMessage": "The dwfix-aurora-inst DB instance is associated with a database cluster. Manage the arn:aws:iam::123456789012:role/dwfix-rds-proxy-role IAM role from the cluster instead of from the DB instance.",
  "eventCategory": "Management",
  "eventID": "1620472e-a375-4b72-990e-78f8cf7f3692",
  "eventName": "RemoveRoleFromDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f783dc77-58be-46e9-aaf2-f3ba90bc91eb",
  "requestParameters": {
    "dBInstanceIdentifier": "dwfix-aurora-inst",
    "featureName": "s3Export",
    "roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveSourceIdentifierFromSubscription

#
Service
rds

Description

Removes a source identifier from an existing Amazon DocumentDB event notification subscription.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "SubscriptionNotFoundFault",
  "errorMessage": "Event Subscription dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "5f8b57df-f60d-4b5e-9917-ed40fa65a2ef",
  "eventName": "RemoveSourceIdentifierFromSubscription",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8571bc5b-b90f-4351-8456-c87569f267bf",
  "requestParameters": {
    "sourceIdentifier": "dw-probe",
    "subscriptionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveTagsFromResource

#
Service
rds

Description

Removes metadata tags from an Amazon DocumentDB resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3d540999-0f6d-4a0e-99d9-91d45ef89181",
  "eventName": "RemoveTagsFromResource",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T20:04:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4a7d65ef-ba45-4e7b-9ebd-ef89fbcb9767",
  "requestParameters": {
    "resourceName": "arn:aws:rds:us-west-1:123456789012:pg:dwfix-pg",
    "tagKeys": [
      "dw"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetDBClusterParameterGroup

#
Service
rds

Description

Modifies the parameters of a cluster parameter group to the default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBClusterParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "9202709f-540b-482f-a548-89dbc0110c6d",
  "eventName": "ResetDBClusterParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a9ec99e4-a983-4b41-801a-d87a674758d6",
  "requestParameters": {
    "dBClusterParameterGroupName": "dw-probe",
    "resetAllParameters": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetDBParameterGroup

#
Service
rds

Description

Modifies the parameters of a DB parameter group to the engine/system default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBParameterGroupNotFoundFault",
  "errorMessage": "DBParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "3ef87552-e4db-439d-a7da-5e409db4ab8a",
  "eventName": "ResetDBParameterGroup",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a278ad03-f616-44a1-80f2-343eb42619a4",
  "requestParameters": {
    "dBParameterGroupName": "dw-probe",
    "resetAllParameters": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RestoreDBClusterFromS3

#
Service
rds

Description

Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket.

RestoreDBClusterFromSnapshot

#
Service
rds

Description

Creates a new cluster from a snapshot or cluster snapshot.

RestoreDBClusterToPointInTime

#
Service
rds

Description

Restores a cluster to an arbitrary point in time.

RestoreDBInstanceToPointInTime

#
Service
rds

Description

Restores a DB instance to an arbitrary point-in-time.

StartActivityStream

#
Service
rds

Description

Starts a database activity stream to monitor activity on the database.

StartDBCluster

#
Service
rds

Description

Restarts the stopped cluster that is specified by DBClusterIdentifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDBClusterStateFault",
  "errorMessage": "DbCluster dwfix-aurora-cl is in available state but expected it to be one of stopped,inaccessible-encryption-credentials-recoverable.",
  "eventCategory": "Management",
  "eventID": "c17e4973-6632-429e-863b-1d42c271da73",
  "eventName": "StartDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:05:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e8621a03-bdff-47bc-afe1-20f4c83cb006",
  "requestParameters": {
    "dBClusterIdentifier": "dwfix-aurora-cl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartDBInstance

#
Service
rds

Description

Starts an Amazon RDS DB instance that was stopped using the Amazon Web Services console, the stop-db-instance CLI command, or the StopDBInstance operation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterCombinationException",
  "errorMessage": "aurora-mysql DB instances are not eligible for stopping and starting.",
  "eventCategory": "Management",
  "eventID": "7ba348b1-d51b-427d-a371-e6fb518ab9c1",
  "eventName": "StartDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T23:10:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c7f11522-9f30-4744-99b1-fc3f8582a059",
  "requestParameters": {
    "dBInstanceIdentifier": "dwfix-aurora-inst"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartDBInstanceAutomatedBackupsReplication

#
Service
rds

Description

Enables replication of automated backups to a different Amazon Web Services Region.

StopActivityStream

#
Service
rds

Description

Stops a database activity stream that was started using the Amazon Web Services console, the start-activity-stream CLI command, or the StartActivityStream operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • AWS RDS Activity Stream Stopped source high: Detects when RDS Database Activity Streams are stopped. Activity Streams provide real-time monitoring of database activity. Disabling them is a clear evasion technique used by attackers to avoid detection before performing malicious operations.T1562.008

StopDBCluster

#
Service
rds

Description

Stops the running cluster that is specified by DBClusterIdentifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBClusterNotFoundFault",
  "errorMessage": "DBCluster dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "eed534b1-113a-4f74-923a-e303c510f256",
  "eventName": "StopDBCluster",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3e80fd66-dcc0-4b74-96ab-794e8cd5dd3f",
  "requestParameters": {
    "dBClusterIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StopDBInstance

#
Service
rds

Description

Stops an Amazon RDS DB instance temporarily.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DBInstanceNotFoundFault",
  "errorMessage": "DBInstance dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "bfc408a6-0f40-4a68-b6f2-832b81345b7d",
  "eventName": "StopDBInstance",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1fb378ce-67e4-4692-b03d-a1af2ce8a294",
  "requestParameters": {
    "dBInstanceIdentifier": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StopDBInstanceAutomatedBackupsReplication

#
Service
rds

Description

Stops automated backup replication for a DB instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The SourceDBInstanceArn you provided isn't a valid Amazon Resource Name (ARN).",
  "eventCategory": "Management",
  "eventID": "45ccc06e-5d4c-4d9c-8890-a582235b0466",
  "eventName": "StopDBInstanceAutomatedBackupsReplication",
  "eventSource": "rds.amazonaws.com",
  "eventTime": "2026-06-29T19:25:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "26930ecc-11fb-4359-bdb5-76659fcc10ca",
  "requestParameters": {
    "sourceDBInstanceArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SwitchoverBlueGreenDeployment

#
Service
rds

Description

Switches over a blue/green deployment.

SwitchoverGlobalCluster

#
Service
rds

Description

Switches over the specified secondary Amazon DocumentDB cluster to be the new primary Amazon DocumentDB cluster in the global database cluster.

SwitchoverReadReplica

#
Service
rds

Description

Switches over an Oracle standby database in an Oracle Data Guard environment, making it the new primary database.