Relational Database Service
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Relational Database Service rules that match the service but not a specific eventName. | N | N |
| Authorize | Enables ingress to a DB security group by authorizing an EC2 security group or an IP address range to access the DB security group. | Y | Y |
| Create | Creates a new Amazon Aurora DB cluster or Multi-AZ DB cluster. | Y | Y |
| Create | Creates a snapshot of a DB cluster. | Y | Y |
| Create | Creates a new DB instance. | Y | Y |
| Create | Creates a new DB security group (EC2-Classic only) and associates it with an Amazon RDS resource. | Y | Y |
| Create | Creates a snapshot of a DB instance. | Y | Y |
| Delete | Deletes a previously provisioned DB cluster, including all automated backups if automated backups are enabled. | Y | Y |
| Delete | Deletes a DB cluster snapshot; the snapshot must be in the available state to be deleted. | Y | Y |
| Delete | Deletes a previously provisioned DB instance, with the option to create a final snapshot. | Y | Y |
| Delete | Deletes a DB security group after dissociating it from all DB instances. | Y | Y |
| Delete | Deletes a DB snapshot; the snapshot must be in the available state to be deleted. | Y | Y |
| Delete | Deletes a global database cluster and removes the primary and all secondary DB clusters that are part of it. | Y | Y |
| Describe | Returns information about provisioned RDS DB instances, including their configuration, status, and endpoint details. | Y | Y |
| Describe | Returns information about DB snapshots for a specified DB instance or all snapshots accessible to the account. | Y | Y |
| Modify | Modifies settings for a DB cluster, including engine version, storage, and backup retention period. | Y | Y |
| Modify | Adds or removes attributes on a DB cluster snapshot, including cross-account copy and restore permissions. | Y | Y |
| Modify | Modifies settings for a DB instance, including instance class, allocated storage, and multi-AZ configuration. | Y | Y |
| Modify | Adds or removes attributes on a manual DB snapshot, including cross-account copy and restore permissions. | Y | Y |
| Restore | Creates a new DB instance from a DB snapshot. | Y | Y |
| Restore | Creates a new DB instance from a MySQL database backup stored in Amazon S3. | N | Y |
| Revoke | Revokes ingress from a DB security group for previously authorized IP ranges or EC2 security groups. | Y | Y |
| Start | Starts an export of DB snapshot or DB cluster data to Amazon S3 in Parquet format. | Y | Y |
| Add | Associates an Identity and Access Management (IAM) role with an Neptune DB cluster. | Y | Y |
| Add | Associates an Amazon Web Services Identity and Access Management (IAM) role with a DB instance. | Y | Y |
| Add | Adds a source identifier to an existing event notification subscription. | N | N |
| Add | Adds metadata tags to an Amazon DocumentDB resource. | Y | N |
| Apply | Applies a pending maintenance action to a resource (for example, to an Amazon DocumentDB instance). | Y | N |
| Backtrack | Backtracks a DB cluster to a specific time, without creating a new DB cluster. | Y | N |
| Cancel | Cancels an export task in progress that is exporting a snapshot or cluster to Amazon S3. | Y | N |
| Copy | Copies the specified cluster parameter group. | Y | N |
| Copy | Copies a snapshot of a cluster. | Y | Y |
| Copy | Copies the specified DB parameter group. | Y | N |
| Copy | Copies the specified DBSnapshot. | Y | Y |
| Copy | Copies the specified option group. | N | N |
| Create | Creates a blue/green deployment. | N | N |
| Create | Creates a custom DB engine version (CEV). | N | N |
| Create | Creates a new custom endpoint and associates it with an Amazon Neptune DB cluster. | Y | N |
| Create | Creates a new cluster parameter group. | Y | N |
| Create | Creates a DB instance that acts as a Read Replica of a source DB instance. | N | N |
| Create | Creates a new DB parameter group. | Y | N |
| Create | Creates a new DB proxy. | Y | N |
| Create | Creates a DBProxyEndpoint. | Y | N |
| Create | Creates a new DB shard group for Aurora Limitless Database. | N | N |
| Create | Creates a new subnet group. | Y | N |
| Create | Creates an Amazon DocumentDB event notification subscription. | Y | N |
| Create | Creates an Amazon DocumentDB global cluster that can span multiple multiple Amazon Web Services Regions. | N | N |
| Create | Creates a zero-ETL integration with Amazon Redshift. | N | N |
| Create | Creates a new option group. | Y | N |
| Create | Creates a tenant database in a DB instance that uses the multi-tenant configuration. | N | N |
| Delete | Deletes a blue/green deployment. | Y | N |
| Delete | Deletes a custom engine version. | Y | N |
| Delete | Deletes automated backups using the DbClusterResourceId value of the source DB cluster or the Amazon Resource Name (ARN) of the automated backups. | Y | Y |
| Delete | Deletes a custom endpoint and removes it from an Amazon Neptune DB cluster. | Y | N |
| Delete | Deletes a specified cluster parameter group. | Y | N |
| Delete | Deletes automated backups using the DbiResourceId value of the source DB instance or the Amazon Resource Name (ARN) of the automated backups. | Y | Y |
| Delete | Deletes a specified DBParameterGroup. | Y | N |
| Delete | Deletes an existing DB proxy. | Y | N |
| Delete | Deletes a DBProxyEndpoint. | Y | N |
| Delete | Deletes an Aurora Limitless Database DB shard group. | Y | N |
| Delete | Deletes a subnet group. | Y | N |
| Delete | Deletes an Amazon DocumentDB event notification subscription. | Y | N |
| Delete | Deletes a zero-ETL integration with Amazon Redshift. | N | N |
| Delete | Deletes an existing option group. | Y | N |
| Delete | Deletes a tenant database from your DB instance. | Y | N |
| Deregister | Remove the association between one or more DBProxyTarget data structures and a DBProxyTargetGroup. | Y | N |
| Describe | Lists all of the attributes for a customer account. | Y | N |
| Describe | Describes one or more blue/green deployments. | Y | N |
| Describe | Returns a list of certificate authority (CA) certificates provided by Amazon DocumentDB for this Amazon Web Services account. | Y | N |
| Describe | Displays backups for both current and deleted DB clusters. | Y | N |
| Describe | Returns information about backtracks for a DB cluster. | Y | N |
| Describe | Returns information about endpoints for an Amazon Neptune DB cluster. | Y | N |
| Describe | Returns a list of DBClusterParameterGroup descriptions. | Y | N |
| Describe | Returns the detailed parameter list for a particular cluster parameter group. | Y | N |
| Describe | Returns information about provisioned Amazon DocumentDB clusters. | Y | N |
| Describe | Returns a list of cluster snapshot attribute names and values for a manual DB cluster snapshot. | Y | N |
| Describe | Returns information about cluster snapshots. | Y | Y |
| Describe | Returns a list of the available engines. | Y | N |
| Describe | Displays backups for both current and deleted instances. | Y | N |
| Describe | Returns a list of DB log files for the DB instance. | Y | N |
| Describe | Describes the properties of specific major versions of DB engines. | Y | N |
| Describe | Returns a list of DBParameterGroup descriptions. | Y | N |
| Describe | Returns the detailed parameter list for a particular DB parameter group. | Y | N |
| Describe | Returns information about DB proxies. | Y | N |
| Describe | Returns information about DB proxy endpoints. | Y | N |
| Describe | Returns information about DB proxy target groups, represented by DBProxyTargetGroup data structures. | Y | N |
| Describe | Returns information about DBProxyTarget objects. | Y | N |
| Describe | Describes the recommendations to resolve the issues for your DB instances, DB clusters, and DB parameter groups. | Y | N |
| Describe | Returns a list of DBSecurityGroup descriptions. | Y | N |
| Describe | Describes existing Aurora Limitless Database DB shard groups. | Y | N |
| Describe | Returns a list of DB snapshot attribute names and values for a manual DB snapshot. | Y | N |
| Describe | Describes the tenant databases that exist in a DB snapshot. | Y | N |
| Describe | Returns a list of DBSubnetGroup descriptions. | Y | N |
| Describe | Returns the default engine and system parameter information for the cluster database engine. | Y | N |
| Describe | Returns the default engine and system parameter information for the specified database engine. | Y | N |
| Describe | Displays a list of categories for all event source types, or, if specified, for a specified source type. | Y | N |
| Describe | Returns events related to instances, security groups, snapshots, and DB parameter groups for the past 14 days. | Y | N |
| Describe | Lists all the subscription descriptions for a customer account. | Y | N |
| Describe | Returns information about a snapshot or cluster export to Amazon S3. | Y | N |
| Describe | Returns information about Amazon DocumentDB global clusters. | Y | N |
| Describe | Describe one or more zero-ETL integrations with Amazon Redshift. | Y | N |
| Describe | Describes all available options. | Y | N |
| Describe | Describes the available option groups. | Y | N |
| Describe | Returns a list of orderable instance options for the specified engine. | Y | N |
| Describe | Returns a list of resources (for example, instances) that have at least one pending maintenance action. | Y | N |
| Describe | Returns information about reserved DB instances for this account, or about a specified reserved DB instance. | Y | N |
| Describe | Lists available reserved DB instance offerings. | Y | N |
| Describe | Describes the properties of specific platform versions for Aurora Serverless v2. | Y | N |
| Describe | Returns a list of the source Amazon Web Services Regions where the current Amazon Web Services Region can create a read replica, copy a DB snapshot from, or replicate automated backups from. | Y | N |
| Describe | Describes the tenant databases in a DB instance that uses the multi-tenant configuration. | Y | N |
| Describe | You can call DescribeValidDBInstanceModifications to learn what modifications you can make to your DB instance. | Y | N |
| Disable | Disables the HTTP endpoint for the specified DB cluster. | Y | N |
| Download | Downloads all or a portion of the specified log file. | N | Y |
| Enable | Enables the HTTP endpoint for the DB cluster. | Y | N |
| Failover | Forces a failover for a cluster. | Y | Y |
| Failover | Promotes the specified secondary DB cluster to be the primary DB cluster in the global cluster when failing over a global cluster occurs. | N | Y |
| List | Lists all tags on an Amazon DocumentDB resource. | Y | N |
| Modify | Changes the audit policy state of a database activity stream to either locked (default) or unlocked. | Y | N |
| Modify | Override the system-default Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate for Amazon RDS for new DB instances, or remove the override. | Y | N |
| Modify | Set the capacity of an Aurora Serverless v1 DB cluster to a specific value. | Y | N |
| Modify | Modifies the status of a custom engine version (CEV). | Y | N |
| Modify | Modifies the properties of an endpoint in an Amazon Neptune DB cluster. | Y | N |
| Modify | Modifies the parameters of a cluster parameter group. | Y | N |
| Modify | Modifies the parameters of a DB parameter group. | Y | N |
| Modify | Changes the settings for an existing DB proxy. | Y | N |
| Modify | Changes the settings for an existing DB proxy endpoint. | Y | N |
| Modify | Modifies the properties of a DBProxyTargetGroup. | Y | N |
| Modify | Updates the recommendation status and recommended action status for the specified recommendation. | Y | N |
| Modify | Modifies the settings of an Aurora Limitless Database DB shard group. | Y | N |
| Modify | Updates a manual DB snapshot with a new engine version. | Y | N |
| Modify | Modifies an existing subnet group. | Y | N |
| Modify | Modifies an existing Amazon DocumentDB event notification subscription. | Y | N |
| Modify | Modify a setting for an Amazon DocumentDB global cluster. | Y | N |
| Modify | Modifies a zero-ETL integration with Amazon Redshift. | N | N |
| Modify | Modifies an existing option group. | Y | N |
| Modify | Modifies an existing tenant database in a DB instance. | Y | N |
| Promote | Promotes a Read Replica DB instance to a standalone DB instance. | N | N |
| Promote | Not supported. | N | N |
| Purchase | Purchases a reserved DB instance offering. | N | N |
| Reboot | You might need to reboot your DB cluster, usually for maintenance reasons. | Y | Y |
| Reboot | You might need to reboot your instance, usually for maintenance reasons. | Y | Y |
| Reboot | You might need to reboot your DB shard group, usually for maintenance reasons. | N | Y |
| Register | Associate one or more DBProxyTarget data structures with a DBProxyTargetGroup. | Y | N |
| Remove | Detaches an Amazon DocumentDB secondary cluster from a global cluster. | Y | N |
| Remove | Disassociates an Identity and Access Management (IAM) role from a DB cluster. | Y | N |
| Remove | Disassociates an Amazon Web Services Identity and Access Management (IAM) role from a DB instance. | Y | N |
| Remove | Removes a source identifier from an existing Amazon DocumentDB event notification subscription. | Y | N |
| Remove | Removes metadata tags from an Amazon DocumentDB resource. | Y | N |
| Reset | Modifies the parameters of a cluster parameter group to the default value. | Y | N |
| Reset | Modifies the parameters of a DB parameter group to the engine/system default value. | Y | N |
| Restore | Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket. | N | N |
| Restore | Creates a new cluster from a snapshot or cluster snapshot. | N | N |
| Restore | Restores a cluster to an arbitrary point in time. | N | N |
| Restore | Restores a DB instance to an arbitrary point-in-time. | N | N |
| Start | Starts a database activity stream to monitor activity on the database. | N | N |
| Start | Restarts the stopped cluster that is specified by DBClusterIdentifier. | Y | N |
| Start | Starts an Amazon RDS DB instance that was stopped using the Amazon Web Services console, the stop-db-instance CLI command, or the StopDBInstance operation. | Y | N |
| Start | Enables replication of automated backups to a different Amazon Web Services Region. | N | N |
| Stop | Stops a database activity stream that was started using the Amazon Web Services console, the start-activity-stream CLI command, or the StartActivityStream operation. | N | Y |
| Stop | Stops the running cluster that is specified by DBClusterIdentifier. | Y | N |
| Stop | Stops an Amazon RDS DB instance temporarily. | Y | N |
| Stop | Stops automated backup replication for a DB instance. | Y | N |
| Switchover | Switches over a blue/green deployment. | N | N |
| Switchover | Switches over the specified secondary Amazon DocumentDB cluster to be the new primary Amazon DocumentDB cluster in the global database cluster. | N | N |
| Switchover | Switches over an Oracle standby database in an Oracle Data Guard environment, making it the new primary database. | N | N |
any: Relational Database Service (catch-all)
#Description
Catch-all entry for Relational Database Service rules that match the service but not a specific eventName.
CreateDBCluster
#Description
Creates a new Amazon Aurora DB cluster or Multi-AZ DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The parameter MasterUserPassword is not a valid password. Only printable ASCII characters besides '/', '@', '\"', ' ' may be used.",
"eventCategory": "Management",
"eventID": "337a0070-0c64-47e1-8892-0af86058690f",
"eventName": "CreateDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3f413968-a007-41db-a0c1-839ae5b5ce06",
"requestParameters": {
"backupRetentionPeriod": 1,
"dBClusterIdentifier": "dwfix-aurora-cl",
"dBClusterParameterGroupName": "dwfix-aurora-pg",
"dBSubnetGroupName": "dwfix-rds-subnet-grp",
"deletionProtection": false,
"engine": "aurora-mysql",
"engineVersion": "8.0.mysql_aurora.3.04.0",
"masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS",
"masterUsername": "dwfixadmin",
"serverlessV2ScalingConfiguration": {
"maxCapacity": 1.0,
"minCapacity": 0.5
},
"storageEncrypted": false,
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1133, T1556, T1556.009↳ also matches CreateDBInstance, ModifyDBInstance
CreateDBClusterSnapshot
#Description
Creates a snapshot of a DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "DBCluster not found: dwfix-aurora-cl",
"eventCategory": "Management",
"eventID": "428cb678-c6f1-4f0e-8c98-f0297a64601f",
"eventName": "CreateDBClusterSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9fe54895-0453-4d4a-91fa-de529dfcb1ee",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl",
"dBClusterSnapshotIdentifier": "dwfix-aurora-snap",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.001↳ also matches CreateDBSnapshot
CreateDBInstance
#Description
Creates a new DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fdc74c82-c299-4211-a08e-b5f125ee3b58",
"eventName": "CreateDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:15:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "5677161c-d80f-4202-8e1f-53c4dcd261af",
"requestParameters": {
"allocatedStorage": 10,
"autoMinorVersionUpgrade": true,
"backupRetentionPeriod": 0,
"copyTagsToSnapshot": false,
"dBInstanceClass": "db.t3.micro",
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBName": "stratusredteamsharesnapdb",
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
"deletionProtection": false,
"engine": "mysql",
"engineVersion": "8.0",
"masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS",
"masterUsername": "admin",
"publiclyAccessible": false,
"storageEncrypted": false,
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"responseElements": {
"allocatedStorage": 10,
"associatedRoles": [],
"autoMinorVersionUpgrade": true,
"backupRetentionPeriod": 0,
"backupTarget": "region",
"cACertificateIdentifier": "rds-ca-2019",
"certificateDetails": {
"cAIdentifier": "rds-ca-2019"
},
"copyTagsToSnapshot": false,
"customerOwnedIpEnabled": false,
"dBInstanceArn": "arn:aws:rds:us-east-1:123837392027:db:terraform-20230710121504061500000001",
"dBInstanceClass": "db.t3.micro",
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBInstanceStatus": "creating",
"dBName": "stratusredteamsharesnapdb",
"dBParameterGroups": [
{
"dBParameterGroupName": "default.mysql8.0",
"parameterApplyStatus": "in-sync"
}
],
"dBSecurityGroups": [],
"dBSubnetGroup": {
"dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
"subnetGroupStatus": "Complete",
"subnets": [
{
"subnetAvailabilityZone": {
"name": "us-east-1a"
},
"subnetIdentifier": "subnet-0cac13291c6f317ec",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-east-1b"
},
"subnetIdentifier": "subnet-0c8a70cf4fd24084f",
"subnetOutpost": {},
"subnetStatus": "Active"
}
],
"vpcId": "vpc-07b33857c7ad1c027"
},
"dbInstancePort": 0,
"dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
"dedicatedLogVolume": false,
"deletionProtection": false,
"domainMemberships": [],
"engine": "mysql",
"engineVersion": "8.0.32",
"httpEndpointEnabled": false,
"iAMDatabaseAuthenticationEnabled": false,
"licenseModel": "general-public-license",
"masterUsername": "admin",
"monitoringInterval": 0,
"multiAZ": false,
"networkType": "IPV4",
"optionGroupMemberships": [
{
"optionGroupName": "default:mysql-8-0",
"status": "in-sync"
}
],
"pendingModifiedValues": {
"masterUserPassword": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"performanceInsightsEnabled": false,
"preferredBackupWindow": "04:41-05:11",
"preferredMaintenanceWindow": "tue:03:39-tue:04:09",
"publiclyAccessible": false,
"readReplicaDBInstanceIdentifiers": [],
"storageEncrypted": false,
"storageThroughput": 0,
"storageType": "gp2",
"tagList": [
{
"key": "StratusRedTeam",
"value": "true"
}
],
"vpcSecurityGroups": [
{
"status": "active",
"vpcSecurityGroupId": "sg-0a1ae80d31d1e9c86"
}
]
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1133, T1556, T1556.009↳ also matches CreateDBCluster, ModifyDBInstance
References #
CreateDBSecurityGroup
#Description
Creates a new DB security group (EC2-Classic only) and associates it with an Amazon RDS resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1e1bbcf3-cb4a-4d9f-b6b7-8dc3461c7792",
"eventName": "CreateDBSecurityGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "13b53091-8438-4075-b3cc-67f79fabcdcb",
"requestParameters": {
"dBSecurityGroupDescription": "dwfix EC2-Classic test SG",
"dBSecurityGroupName": "dwfix-ec2classic-sg"
},
"responseElements": {
"dBSecurityGroupArn": "arn:aws:rds:us-west-1:123456789012:secgrp:dwfix-ec2classic-sg",
"dBSecurityGroupDescription": "dwfix EC2-Classic test SG",
"dBSecurityGroupName": "dwfix-ec2classic-sg",
"eC2SecurityGroups": [],
"iPRanges": [],
"ownerId": "123456789012",
"vpcId": "vpc-0cf63cfb072f7d61f"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches AuthorizeDBSecurityGroupIngress, DeleteDBSecurityGroup, RevokeDBSecurityGroupIngress Kusto #
T1098, T1098.001, T1562, T1562.007↳ also matches AuthorizeDBSecurityGroupIngress, DeleteDBSecurityGroup, RevokeDBSecurityGroupIngress
CreateDBSnapshot
#Description
Creates a snapshot of a DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0516b66a-77ec-4479-a82d-0cda54d3fc5d",
"eventName": "CreateDBSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:19:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "63f3081b-eb64-472c-96ec-c9a24028320c",
"requestParameters": {
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBSnapshotIdentifier": "exfiltration",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"responseElements": {
"allocatedStorage": 10,
"availabilityZone": "us-east-1b",
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBSnapshotArn": "arn:aws:rds:us-east-1:123837392027:snapshot:exfiltration",
"dBSnapshotIdentifier": "exfiltration",
"dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
"dedicatedLogVolume": false,
"encrypted": false,
"engine": "mysql",
"engineVersion": "8.0.32",
"iAMDatabaseAuthenticationEnabled": false,
"instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
"licenseModel": "general-public-license",
"masterUsername": "admin",
"optionGroupName": "default:mysql-8-0",
"percentProgress": 0,
"port": 3306,
"processorFeatures": [],
"snapshotTarget": "region",
"snapshotType": "manual",
"status": "creating",
"storageThroughput": 0,
"storageType": "gp2",
"tagList": [
{
"key": "StratusRedTeam",
"value": "true"
}
],
"vpcId": "vpc-07b33857c7ad1c027"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.001↳ also matches CreateDBClusterSnapshot Panther #
T1537
References #
DeleteDBCluster
#Description
Deletes a previously provisioned DB cluster, including all automated backups if automated backups are enabled.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "The source cluster could not be found or cannot be accessed: dw-probe",
"eventCategory": "Management",
"eventID": "b63bc185-46c0-4abb-9f3a-a318e3c876ec",
"eventName": "DeleteDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cbc9480a-d5db-43da-92e7-8fbde59e2136",
"requestParameters": {
"dBClusterIdentifier": "dw-probe",
"skipFinalSnapshot": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1020↳ also matches ModifyDBCluster Elastic #
T1485↳ also matches DeleteDBInstance, DeleteGlobalCluster Panther #
T1485, T1531↳ also matches DeleteDBInstance
DeleteDBClusterSnapshot
#Description
Deletes a DB cluster snapshot; the snapshot must be in the available state to be deleted.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterSnapshotNotFoundFault",
"errorMessage": "DBClusterSnapshot not found: dw-probe",
"eventCategory": "Management",
"eventID": "7ff19601-41e8-4878-8d2e-da1d384f947d",
"eventName": "DeleteDBClusterSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4823ced9-6962-439a-baca-40c1cfc90c3c",
"requestParameters": {
"dBClusterSnapshotIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1490↳ also matches DeleteDBSnapshot, ModifyDBInstance Panther #
T1070, T1485↳ also matches DeleteDBSnapshot
DeleteDBInstance
#Description
Deletes a previously provisioned DB instance, with the option to create a final snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b5232796-c668-4d71-a006-d9cabb3d607d",
"eventName": "DeleteDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "23ffb7fd-6479-46bd-9db4-62348a02d8a4",
"requestParameters": {
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"deleteAutomatedBackups": true,
"finalDBSnapshotIdentifier": "terraform-20230710121504061500000001-snapshot",
"skipFinalSnapshot": false
},
"responseElements": {
"allocatedStorage": 10,
"associatedRoles": [],
"autoMinorVersionUpgrade": true,
"availabilityZone": "us-east-1b",
"backupRetentionPeriod": 0,
"backupTarget": "region",
"cACertificateIdentifier": "",
"copyTagsToSnapshot": false,
"customerOwnedIpEnabled": false,
"dBInstanceArn": "arn:aws:rds:us-east-1:123837392027:db:terraform-20230710121504061500000001",
"dBInstanceClass": "db.t3.micro",
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBInstanceStatus": "deleting",
"dBName": "stratusredteamsharesnapdb",
"dBParameterGroups": [
{
"dBParameterGroupName": "default.mysql8.0",
"parameterApplyStatus": "in-sync"
}
],
"dBSecurityGroups": [],
"dBSubnetGroup": {
"dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
"subnetGroupStatus": "Complete",
"subnets": [
{
"subnetAvailabilityZone": {
"name": "us-east-1a"
},
"subnetIdentifier": "subnet-0cac13291c6f317ec",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-east-1b"
},
"subnetIdentifier": "subnet-0c8a70cf4fd24084f",
"subnetOutpost": {},
"subnetStatus": "Active"
}
],
"vpcId": "vpc-07b33857c7ad1c027"
},
"dbInstancePort": 0,
"dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
"dedicatedLogVolume": false,
"deletionProtection": false,
"domainMemberships": [],
"endpoint": {
"address": "terraform-20230710121504061500000001.c2m8opohni2g.us-east-1.rds.amazonaws.com",
"hostedZoneId": "Z2R2ITUGPM61AM",
"port": 3306
},
"engine": "mysql",
"engineVersion": "8.0.32",
"httpEndpointEnabled": false,
"iAMDatabaseAuthenticationEnabled": false,
"instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
"licenseModel": "general-public-license",
"masterUsername": "admin",
"monitoringInterval": 0,
"multiAZ": false,
"networkType": "IPV4",
"optionGroupMemberships": [
{
"optionGroupName": "default:mysql-8-0",
"status": "in-sync"
}
],
"pendingModifiedValues": {},
"performanceInsightsEnabled": false,
"preferredBackupWindow": "04:41-05:11",
"preferredMaintenanceWindow": "tue:03:39-tue:04:09",
"publiclyAccessible": false,
"readReplicaDBInstanceIdentifiers": [],
"storageEncrypted": false,
"storageThroughput": 0,
"storageType": "gp2",
"tagList": [
{
"key": "StratusRedTeam",
"value": "true"
}
],
"vpcSecurityGroups": [
{
"status": "active",
"vpcSecurityGroupId": "sg-0a1ae80d31d1e9c86"
}
]
},
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485↳ also matches DeleteDBCluster, DeleteGlobalCluster Panther #
T1485, T1531↳ also matches DeleteDBCluster
References #
DeleteDBSecurityGroup
#Description
Deletes a DB security group after dissociating it from all DB instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSecurityGroupNotFoundFault",
"errorMessage": "DBSecurityGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "0b42e1f0-48b1-4cbf-a46b-d4abc220888d",
"eventName": "DeleteDBSecurityGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "112c7bbe-1f03-421a-bb47-aa5b85244d1f",
"requestParameters": {
"dBSecurityGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches AuthorizeDBSecurityGroupIngress, CreateDBSecurityGroup, RevokeDBSecurityGroupIngress Kusto #
T1098, T1098.001, T1562, T1562.007↳ also matches AuthorizeDBSecurityGroupIngress, CreateDBSecurityGroup, RevokeDBSecurityGroupIngress
DeleteDBSnapshot
#Description
Deletes a DB snapshot; the snapshot must be in the available state to be deleted.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1b51dbcc-50a4-4e5c-a558-69096203818a",
"eventName": "DeleteDBSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "4414a0af-48a6-4807-901f-7f9a8b23d0ce",
"requestParameters": {
"dBSnapshotIdentifier": "exfiltration"
},
"responseElements": {
"allocatedStorage": 10,
"availabilityZone": "us-east-1b",
"dBInstanceIdentifier": "terraform-20230710121504061500000001",
"dBSnapshotArn": "arn:aws:rds:us-east-1:123837392027:snapshot:exfiltration",
"dBSnapshotIdentifier": "exfiltration",
"dbiResourceId": "db-PDUCDGLRGDVGNFIUKF4FRJGEGY",
"dedicatedLogVolume": false,
"encrypted": false,
"engine": "mysql",
"engineVersion": "8.0.32",
"iAMDatabaseAuthenticationEnabled": false,
"instanceCreateTime": "Jul 10, 2023 12:19:33 PM",
"licenseModel": "general-public-license",
"masterUsername": "admin",
"optionGroupName": "default:mysql-8-0",
"originalSnapshotCreateTime": "Jul 10, 2023 12:20:17 PM",
"percentProgress": 100,
"port": 3306,
"processorFeatures": [],
"snapshotCreateTime": "Jul 10, 2023 12:20:17 PM",
"snapshotTarget": "region",
"snapshotType": "manual",
"status": "deleted",
"storageThroughput": 0,
"storageType": "gp2",
"tagList": [],
"vpcId": "vpc-07b33857c7ad1c027"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1490↳ also matches DeleteDBClusterSnapshot, ModifyDBInstance Panther #
T1070, T1485↳ also matches DeleteDBClusterSnapshot
References #
DeleteGlobalCluster
#Description
Deletes a global database cluster and removes the primary and all secondary DB clusters that are part of it.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "GlobalClusterNotFoundFault",
"errorMessage": "Global cluster 'ddddd' not found",
"eventCategory": "Management",
"eventID": "76135edb-a9c1-4ecf-bbdf-187f8f459497",
"eventName": "DeleteGlobalCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f18c1630-1780-4d7a-9930-9e5a893c140e",
"requestParameters": {
"globalClusterIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485↳ also matches DeleteDBCluster, DeleteDBInstance
DescribeDBInstances
#Description
Returns information about provisioned RDS DB instances, including their configuration, status, and endpoint details.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "193dd028-8c45-4b6a-9339-ed4358ca0105",
"eventName": "DescribeDBInstances",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:16:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "802f63f1-f396-4ee4-bf02-25f136f28b87",
"requestParameters": {
"dBInstanceIdentifier": "terraform-20230710121504061500000001"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeDBSnapshots
References #
DescribeDBSnapshots
#Description
Returns information about DB snapshots for a specified DB instance or all snapshots accessible to the account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "5eeb7559-5684-48c2-9583-a4309fed632b",
"eventName": "DescribeDBSnapshots",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:21:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "8f1799a7-b750-436e-8d46-078bdff4a328",
"requestParameters": {
"dBSnapshotIdentifier": "exfiltration",
"includePublic": false,
"includeShared": false
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeDBInstances Panther #
T1580↳ also matches DescribeDBClusterSnapshots
References #
ModifyDBCluster
#Description
Modifies settings for a DB cluster, including engine version, storage, and backup retention period.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "DBCluster not found",
"eventCategory": "Management",
"eventID": "4bc29181-b8e2-4bb5-8bb3-741ab9ea815c",
"eventName": "ModifyDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8edbbb6f-1580-424c-95d4-74666c9b7e54",
"requestParameters": {
"allowEngineModeChange": false,
"allowMajorVersionUpgrade": false,
"applyImmediately": false,
"dBClusterIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1020↳ also matches DeleteDBCluster Elastic #
T1485, T1578, T1578.005↳ also matches ModifyDBInstance T1098, T1098.001↳ also matches ModifyDBInstance Splunk #
ModifyDBInstance API call includes a new…T1110, T1586, T1586.003↳ also matches ModifyDBInstance Panther #
T1490, T1562↳ also matches ModifyDBInstance T1098, T1133, T1562.007↳ also matches ModifyDBInstance
ModifyDBClusterSnapshotAttribute
#Description
Adds or removes attributes on a DB cluster snapshot, including cross-account copy and restore permissions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterSnapshotNotFoundFault",
"errorMessage": "DBClusterSnapshot not found: dw-probe",
"eventCategory": "Management",
"eventID": "01036be9-f9fa-4095-bdee-317c9501ec4f",
"eventName": "ModifyDBClusterSnapshotAttribute",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0c702e56-47b4-4948-8120-dfdbef357bff",
"requestParameters": {
"attributeName": "dw-probe",
"dBClusterSnapshotIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1537↳ also matches ModifyDBSnapshotAttribute YARA-L #
T1537↳ also matches ModifyDBSnapshotAttribute Panther #
T1537↳ also matches ModifyDBSnapshotAttribute
ModifyDBInstance
#Description
Modifies settings for a DB instance, including instance class, allocated storage, and multi-AZ configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "46351ca1-760e-4eef-b3ff-19723e13fbf8",
"eventName": "ModifyDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2022-08-05T09:19:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "59e6b621-2f12-415b-bde4-21fa2dc7c113",
"requestParameters": {
"allowMajorVersionUpgrade": false,
"applyImmediately": true,
"dBInstanceIdentifier": "database-1",
"deletionProtection": true,
"masterUserPassword": "****"
},
"responseElements": {
"allocatedStorage": 5,
"associatedRoles": [],
"autoMinorVersionUpgrade": true,
"availabilityZone": "us-west-2a",
"backupRetentionPeriod": 7,
"backupTarget": "region",
"cACertificateIdentifier": "rds-ca-2019",
"copyTagsToSnapshot": true,
"customerOwnedIpEnabled": false,
"dBInstanceArn": "arn:aws:rds:us-west-2:111111111111:db:database-1",
"dBInstanceClass": "db.m6g.large",
"dBInstanceIdentifier": "database-1",
"dBInstanceStatus": "available",
"dBParameterGroups": [
{
"dBParameterGroupName": "default.postgres14",
"parameterApplyStatus": "in-sync"
}
],
"dBSecurityGroups": [],
"dBSubnetGroup": {
"dBSubnetGroupDescription": "default",
"dBSubnetGroupName": "default",
"subnetGroupStatus": "Complete",
"subnets": [
{
"subnetAvailabilityZone": {
"name": "us-west-2b"
},
"subnetIdentifier": "subnet-43225f35",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-west-2a"
},
"subnetIdentifier": "subnet-e55d7881",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-west-2c"
},
"subnetIdentifier": "subnet-0beddb972f034bdaa",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-west-2c"
},
"subnetIdentifier": "subnet-2d70cd75",
"subnetOutpost": {},
"subnetStatus": "Active"
}
],
"vpcId": "vpc-5f02343b"
},
"dbInstancePort": 0,
"dbiResourceId": "db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
"deletionProtection": true,
"domainMemberships": [],
"endpoint": {
"address": "database-1.ce6wk5bvtc0t.us-west-2.rds.amazonaws.com",
"hostedZoneId": "Z1PVIF0B656C1W",
"port": 5432
},
"engine": "postgres",
"engineVersion": "14.2",
"enhancedMonitoringResourceArn": "arn:aws:logs:us-west-2:111111111111:log-group:RDSOSMetrics:log-stream:db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
"httpEndpointEnabled": false,
"iAMDatabaseAuthenticationEnabled": false,
"instanceCreateTime": "Aug 5, 2022 9:02:51 AM",
"kmsKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
"latestRestorableTime": "Aug 5, 2022 9:12:31 AM",
"licenseModel": "postgresql-license",
"masterUsername": "postgres",
"monitoringInterval": 60,
"monitoringRoleArn": "arn:aws:iam::111111111111:role/rds-monitoring-role",
"multiAZ": false,
"networkType": "IPV4",
"optionGroupMemberships": [
{
"optionGroupName": "default:postgres-14",
"status": "in-sync"
}
],
"pendingModifiedValues": {
"masterUserPassword": "****"
},
"performanceInsightsEnabled": true,
"performanceInsightsKMSKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
"performanceInsightsRetentionPeriod": 7,
"preferredBackupWindow": "06:35-07:05",
"preferredMaintenanceWindow": "sat:11:44-sat:12:14",
"publiclyAccessible": false,
"readReplicaDBInstanceIdentifiers": [],
"storageEncrypted": true,
"storageThroughput": 0,
"storageType": "standard",
"tagList": [],
"vpcSecurityGroups": [
{
"status": "active",
"vpcSecurityGroupId": "sg-46cfd020"
}
]
},
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "AWS Internal",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLAKJDBQGB",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
"principalId": "AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com",
"sessionContext": {
"attributes": {
"creationDate": "2022-08-05T08:47:55Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"principalId": "AROAYTOGP2RLDF6WP4HD6",
"type": "Role",
"userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode | is_null | | 3 rules | kusto, panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1020Elastic #
T1485, T1578, T1578.005↳ also matches ModifyDBCluster T1485, T1490↳ also matches DeleteDBClusterSnapshot, DeleteDBSnapshot T1098, T1098.001↳ also matches ModifyDBCluster Splunk #
ModifyDBInstance API call includes a new masterUserPassword…T1110, T1586, T1586.003ModifyDBInstance API call includes a new…T1110, T1586, T1586.003↳ also matches ModifyDBCluster Kusto #
T1537Panther #
T1098T1490, T1562↳ also matches ModifyDBCluster T1098, T1133, T1562.007↳ also matches ModifyDBCluster
References #
ModifyDBSnapshotAttribute
#Description
Adds or removes attributes on a manual DB snapshot, including cross-account copy and restore permissions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "2d19ab1e-82e9-4302-ad10-a405b50c8d49",
"eventName": "ModifyDBSnapshotAttribute",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:22:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "d6d4e27c-49b8-4eaa-971d-601d4368846d",
"requestParameters": {
"attributeName": "restore",
"dBSnapshotIdentifier": "exfiltration",
"valuesToAdd": [
"193672423079"
]
},
"responseElements": {
"dBSnapshotAttributes": [
{
"attributeName": "restore",
"attributeValues": [
"193672423079"
]
}
],
"dBSnapshotIdentifier": "exfiltration"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1537↳ also matches ModifyDBClusterSnapshotAttribute YARA-L #
T1537↳ also matches ModifyDBClusterSnapshotAttribute Panther #
T1537↳ also matches ModifyDBClusterSnapshotAttribute
References #
RestoreDBInstanceFromDBSnapshot
#Description
Creates a new DB instance from a DB snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:RestoreDBInstanceFromDBSnapshot on resource: arn:aws:rds:us-west-2:811596193553:db:vol-8e100f305b7a6fef3",
"eventID": "39b68aa6-4805-4fc8-af84-0381cd75282b",
"eventName": "RestoreDBInstanceFromDBSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2020-05-16T20:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "0d2cceb2-8bfe-48b5-8011-c8026be025d5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.63.7.255",
"userAgent": "aws-cli/1.14.44 Python/3.6.9 Linux/5.3.0-51-generic botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1020Elastic #
T1074, T1074.002, T1578, T1578.002, T1578.004↳ also matches RestoreDBInstanceFromS3 Panther #
T1020
References #
RestoreDBInstanceFromS3
#Description
Creates a new DB instance from a MySQL database backup stored in Amazon S3.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1074, T1074.002, T1578, T1578.002, T1578.004↳ also matches RestoreDBInstanceFromDBSnapshot
RevokeDBSecurityGroupIngress
#Description
Revokes ingress from a DB security group for previously authorized IP ranges or EC2 security groups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSecurityGroupNotFoundFault",
"errorMessage": "DBSecurityGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "c0f54107-344b-4abb-9efc-7b7ac399256f",
"eventName": "RevokeDBSecurityGroupIngress",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "34c4da8c-f977-41be-9987-990919906342",
"requestParameters": {
"dBSecurityGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches AuthorizeDBSecurityGroupIngress, CreateDBSecurityGroup, DeleteDBSecurityGroup Kusto #
T1098, T1098.001, T1562, T1562.007↳ also matches AuthorizeDBSecurityGroupIngress, CreateDBSecurityGroup, DeleteDBSecurityGroup
StartExportTask
#Description
Starts an export of DB snapshot or DB cluster data to Amazon S3 in Parquet format.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "Cross-account pass role is not allowed.",
"eventCategory": "Management",
"eventID": "f4bca42d-d427-424d-894a-cf968af4c8c8",
"eventName": "StartExportTask",
"eventSource": "rds.amazonaws.com",
"eventTime": "2024-08-18T15:44:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1087c7dc-a750-4b8c-86f7-f0f4316fba2e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_507e6b2d-9561-4119-be31-e29bfee30f4d cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#rds.start-export-task",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1213, T1213.006, T1567, T1567.002Panther #
T1537
References #
AddRoleToDBCluster
#Description
Associates an Identity and Access Management (IAM) role with an Neptune DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "DBCluster not found: dwfix-aurora-cl",
"eventCategory": "Management",
"eventID": "5d0a5e7d-55be-42a3-b995-0109d0b46b29",
"eventName": "AddRoleToDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "104fe301-bf71-414e-850f-5aa845d2cfa8",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl",
"featureName": "s3Export",
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1078.004, T1098.001↳ also matches AddRoleToDBInstance
AddRoleToDBInstance
#Description
Associates an Amazon Web Services Identity and Access Management (IAM) role with a DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance not found: dwfix-aurora-inst",
"eventCategory": "Management",
"eventID": "6c2e7b92-3813-4ed9-a979-c199e9ab290b",
"eventName": "AddRoleToDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0581a30c-289f-48cd-bc1b-9e7d6c8d142b",
"requestParameters": {
"dBInstanceIdentifier": "dwfix-aurora-inst",
"featureName": "s3Export",
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1078.004, T1098.001↳ also matches AddRoleToDBCluster
AddSourceIdentifierToSubscription
#Description
Adds a source identifier to an existing event notification subscription.
ApplyPendingMaintenanceAction
#Description
Applies a pending maintenance action to a resource (for example, to an Amazon DocumentDB instance).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterCombinationException",
"errorMessage": "There is no pending system-update action for arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl",
"eventCategory": "Management",
"eventID": "0cfe758f-88ae-4bee-890d-d05852a41e31",
"eventName": "ApplyPendingMaintenanceAction",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:50:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5af2abdd-eb85-4e48-a6d1-1539ea50e56d",
"requestParameters": {
"applyAction": "system-update",
"optInType": "undo-opt-in",
"resourceIdentifier": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BacktrackDBCluster
#Description
Backtracks a DB cluster to a specific time, without creating a new DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "Could not find specified DB Cluster",
"eventCategory": "Management",
"eventID": "41f15628-d5f0-492f-832f-b305ee77d64b",
"eventName": "BacktrackDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7a9383d3-4dcc-4d83-a25f-8113916373e4",
"requestParameters": {
"backtrackTo": "Jun 29, 2026, 10:35:01 PM",
"dBClusterIdentifier": "dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelExportTask
#Description
Cancels an export task in progress that is exporting a snapshot or cluster to Amazon S3.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ExportTaskNotFoundFault",
"errorMessage": "The export task dw-probe doesn't exist.",
"eventCategory": "Management",
"eventID": "f172af85-24b2-41d9-93c3-943501a5ef2f",
"eventName": "CancelExportTask",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "68f69ced-cb6c-43b9-b6ea-24d81832663e",
"requestParameters": {
"exportTaskIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CopyDBClusterParameterGroup
#Description
Copies the specified cluster parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3b28ba6c-dbd0-45f0-bdb5-8bed4c154e40",
"eventName": "CopyDBClusterParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "171c0663-dec8-436b-9dd8-d900971900c3",
"requestParameters": {
"sourceDBClusterParameterGroupIdentifier": "dwfix-aurora-pg",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"targetDBClusterParameterGroupDescription": "dwfix copy of aurora cluster PG",
"targetDBClusterParameterGroupIdentifier": "dwfix-aurora-pg-copy"
},
"responseElements": {
"dBClusterParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:cluster-pg:dwfix-aurora-pg-copy",
"dBClusterParameterGroupName": "dwfix-aurora-pg-copy",
"dBParameterGroupFamily": "aurora-mysql8.0",
"description": "dwfix copy of aurora cluster PG"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CopyDBClusterSnapshot
#Description
Copies a snapshot of a cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterSnapshotNotFoundFault",
"errorMessage": "DBClusterSnapshot not found: dwfix-aurora-snap",
"eventCategory": "Management",
"eventID": "e3955c6b-984e-4ef5-bb0d-706d9e81660c",
"eventName": "CopyDBClusterSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d5403a0a-a4f4-4ad6-8112-852e443c3a16",
"requestParameters": {
"sourceDBClusterSnapshotIdentifier": "dwfix-aurora-snap",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"targetDBClusterSnapshotIdentifier": "dwfix-aurora-snap-copy"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1537↳ also matches CopyDBSnapshot
CopyDBParameterGroup
#Description
Copies the specified DB parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The parameter DBParameterGroupName is not a valid identifier. Identifiers must begin with a letter; must contain only ASCII letters, digits, and hyphens; and must not end with a hyphen or contain two consecutive hyphens.",
"eventCategory": "Management",
"eventID": "f3e0076a-adb8-4098-bcbb-f290de80cc3d",
"eventName": "CopyDBParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "65890272-139e-41ef-b5b7-3dd2fee4a295",
"requestParameters": {
"sourceDBParameterGroupIdentifier": "default.aurora-mysql8.0",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"targetDBParameterGroupDescription": "dwfix copy of aurora-mysql8.0 instance PG",
"targetDBParameterGroupIdentifier": "dwfix-inst-pg-copy"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CopyDBSnapshot
#Description
Copies the specified DBSnapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "19a4e40d-ea26-4842-9892-49c40ca2ce92",
"eventName": "CopyDBSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:16:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6791bea2-70ec-4c2c-8845-9a6c6b9f91e0",
"requestParameters": {
"sourceDBSnapshotIdentifier": "dwfix-snap",
"targetDBSnapshotIdentifier": "dwfix-snap2"
},
"responseElements": {
"allocatedStorage": 20,
"backupRetentionPeriod": 0,
"dBInstanceIdentifier": "dwfix-db",
"dBSnapshotArn": "arn:aws:rds:us-west-1:123456789012:snapshot:dwfix-snap2",
"dBSnapshotIdentifier": "dwfix-snap2",
"dbiResourceId": "db-4R7RSIWQWQ3B6KT64HCC5BEO5Y",
"dedicatedLogVolume": false,
"encrypted": false,
"engine": "mysql",
"engineVersion": "8.4.8",
"iAMDatabaseAuthenticationEnabled": false,
"instanceCreateTime": "Jun 29, 2026, 8:10:46 PM",
"licenseModel": "general-public-license",
"masterUsername": "admin",
"multiTenant": false,
"optionGroupName": "default:mysql-8-4",
"originalSnapshotCreateTime": "Jun 29, 2026, 8:14:16 PM",
"percentProgress": 0,
"port": 3306,
"preferredBackupWindow": "08:45-09:15",
"processorFeatures": [],
"snapshotCreateTime": "Jun 29, 2026, 8:12:16 PM",
"snapshotTarget": "region",
"snapshotType": "manual",
"sourceDBSnapshotIdentifier": "arn:aws:rds:us-west-1:123456789012:snapshot:dwfix-snap",
"sourceRegion": "us-west-1",
"status": "creating",
"storageEncryptionType": "none",
"storageThroughput": 0,
"storageType": "gp2",
"tagList": [],
"vpcId": "vpc-0cf63cfb072f7d61f"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1537↳ also matches CopyDBClusterSnapshot
CopyOptionGroup
#Description
Copies the specified option group.
CreateBlueGreenDeployment
#Description
Creates a blue/green deployment.
CreateCustomDBEngineVersion
#Description
Creates a custom DB engine version (CEV).
CreateDBClusterEndpoint
#Description
Creates a new custom endpoint and associates it with an Amazon Neptune DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "The source cluster could not be found or cannot be accessed: dwfix-aurora-cl",
"eventCategory": "Management",
"eventID": "2ad59d1d-44fc-483a-b605-9baad9978ae8",
"eventName": "CreateDBClusterEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "82f93d46-d79c-4451-acdc-883ae401c2ae",
"requestParameters": {
"dBClusterEndpointIdentifier": "dwfix-aurora-ep",
"dBClusterIdentifier": "dwfix-aurora-cl",
"endpointType": "READER",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDBClusterParameterGroup
#Description
Creates a new cluster parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3b4ac246-fc79-418f-ac56-89d9b10624fe",
"eventName": "CreateDBClusterParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:04:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "607a6a16-7f03-4053-ba98-62637ef407eb",
"requestParameters": {
"dBClusterParameterGroupName": "dwfix-cpg",
"dBParameterGroupFamily": "aurora-mysql8.0",
"description": "dw"
},
"responseElements": {
"dBClusterParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:cluster-pg:dwfix-cpg",
"dBClusterParameterGroupName": "dwfix-cpg",
"dBParameterGroupFamily": "aurora-mysql8.0",
"description": "dw"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDBInstanceReadReplica
#Description
Creates a DB instance that acts as a Read Replica of a source DB instance.
CreateDBParameterGroup
#Description
Creates a new DB parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "82a13ccc-8d2b-46dc-bddd-7b2319eaf5f6",
"eventName": "CreateDBParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:04:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eb24ef0d-cf6d-410b-94e1-6c585f33b4c6",
"requestParameters": {
"dBParameterGroupFamily": "mysql8.0",
"dBParameterGroupName": "dwfix-pg",
"description": "dw"
},
"responseElements": {
"dBParameterGroupArn": "arn:aws:rds:us-west-1:123456789012:pg:dwfix-pg",
"dBParameterGroupFamily": "mysql8.0",
"dBParameterGroupName": "dwfix-pg",
"description": "dw"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDBProxy
#Description
Creates a new DB proxy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c5152636-58fc-4b58-ae3d-cecc7f6c0793",
"eventName": "CreateDBProxy",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:05:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "74e4098a-c901-4a65-81fa-41a4496e302b",
"requestParameters": {
"auth": [
{
"authScheme": "SECRETS",
"iAMAuth": "DISABLED",
"secretArn": "arn:aws:secretsmanager:us-west-1:123456789012:secret:dwfix-rds-secret-iRLiD0"
}
],
"dBProxyName": "dwfix-rds-proxy",
"debugLogging": false,
"engineFamily": "MYSQL",
"requireTLS": false,
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"vpcSubnetIds": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
]
},
"responseElements": {
"dBProxy": {
"auth": [
{
"authScheme": "SECRETS",
"clientPasswordAuthType": "MYSQL_CACHING_SHA2_PASSWORD",
"iAMAuth": "DISABLED",
"secretArn": "arn:aws:secretsmanager:us-west-1:123456789012:secret:dwfix-rds-secret-iRLiD0"
}
],
"createdDate": "2026-06-29T23:05:09Z",
"dBProxyArn": "arn:aws:rds:us-west-1:123456789012:db-proxy:prx-039d3b611bb0b1c65",
"dBProxyName": "dwfix-rds-proxy",
"debugLogging": false,
"defaultAuthScheme": "NONE",
"endpoint": "dwfix-rds-proxy.proxy-cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
"endpointNetworkType": "IPV4",
"engineFamily": "MYSQL",
"idleClientTimeout": 1800,
"requireTLS": false,
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role",
"status": "creating",
"targetConnectionNetworkType": "IPV4",
"vpcId": "vpc-0cf63cfb072f7d61f",
"vpcSecurityGroupIds": [
"sg-063fc1a8302bc48a4"
],
"vpcSubnetIds": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
]
}
},
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T23:05:08Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDBProxyEndpoint
#Description
Creates a DBProxyEndpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "73a1808e-5d88-4c8b-88cc-cee3f9e8d5f5",
"eventName": "CreateDBProxyEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "49d09d9a-2b48-433f-8231-9c36cea7db97",
"requestParameters": {
"dBProxyEndpointName": "dwfix-rds-proxy-ep",
"dBProxyName": "dwfix-rds-proxy",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"targetRole": "READ_WRITE",
"vpcSubnetIds": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
]
},
"responseElements": {
"dBProxyEndpoint": {
"createdDate": "2026-06-29T23:10:41Z",
"dBProxyEndpointArn": "arn:aws:rds:us-west-1:123456789012:db-proxy-endpoint:prx-endpoint-0bcdbb60003e9e7f0",
"dBProxyEndpointName": "dwfix-rds-proxy-ep",
"dBProxyName": "dwfix-rds-proxy",
"endpoint": "dwfix-rds-proxy-ep.endpoint.proxy-cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
"endpointNetworkType": "IPV4",
"endpointType": "CUSTOM",
"isDefault": false,
"status": "creating",
"targetRole": "READ_WRITE",
"vpcId": "vpc-0cf63cfb072f7d61f",
"vpcSecurityGroupIds": [
"sg-063fc1a8302bc48a4"
],
"vpcSubnetIds": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
]
}
},
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T23:09:39Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDBShardGroup
#Description
Creates a new DB shard group for Aurora Limitless Database.
CreateDBSubnetGroup
#Description
Creates a new subnet group.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "726b9d86-35ea-49a3-b87a-2c44f9b5ddad",
"eventName": "CreateDBSubnetGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:15:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "1c4b0074-47c4-4ed7-84e7-9e77445e4caf",
"requestParameters": {
"dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
"subnetIds": [
"subnet-0cac13291c6f317ec",
"subnet-0c8a70cf4fd24084f"
],
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-share-snap-vpc"
}
]
},
"responseElements": {
"dBSubnetGroupArn": "arn:aws:rds:us-east-1:123837392027:subgrp:stratus-red-team-share-snap-vpc",
"dBSubnetGroupDescription": "Database subnet group for stratus-red-team-share-snap-vpc",
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc",
"subnetGroupStatus": "Complete",
"subnets": [
{
"subnetAvailabilityZone": {
"name": "us-east-1a"
},
"subnetIdentifier": "subnet-0cac13291c6f317ec",
"subnetOutpost": {},
"subnetStatus": "Active"
},
{
"subnetAvailabilityZone": {
"name": "us-east-1b"
},
"subnetIdentifier": "subnet-0c8a70cf4fd24084f",
"subnetOutpost": {},
"subnetStatus": "Active"
}
],
"supportedNetworkTypes": [
"IPV4"
],
"vpcId": "vpc-07b33857c7ad1c027"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateEventSubscription
#Description
Creates an Amazon DocumentDB event notification subscription.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "SNSTopicArnNotFoundFault",
"errorMessage": "Failed to create Subscription because of Topic arn:aws:sns:us-west-1:123456789012:nonexistent Not Found.",
"eventCategory": "Management",
"eventID": "fed51df5-43cb-483e-8e1e-6df7222c7e2e",
"eventName": "CreateEventSubscription",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:04:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "69223f30-76d7-4057-b398-ccf4aac94f83",
"requestParameters": {
"snsTopicArn": "arn:aws:sns:us-west-1:123456789012:nonexistent",
"subscriptionName": "dwfix-es"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateGlobalCluster
#Description
Creates an Amazon DocumentDB global cluster that can span multiple multiple Amazon Web Services Regions.
CreateIntegration
#Description
Creates a zero-ETL integration with Amazon Redshift.
CreateOptionGroup
#Description
Creates a new option group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "842a2d40-93bf-4b89-b786-ce88933827d3",
"eventName": "CreateOptionGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:04:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "53bb303a-3b0d-47b4-9abb-e6fd69364f41",
"requestParameters": {
"engineName": "mysql",
"majorEngineVersion": "8.0",
"optionGroupDescription": "dw",
"optionGroupName": "dwfix-og"
},
"responseElements": {
"allowsVpcAndNonVpcInstanceMemberships": true,
"engineName": "mysql",
"majorEngineVersion": "8.0",
"optionGroupArn": "arn:aws:rds:us-west-1:123456789012:og:dwfix-og",
"optionGroupDescription": "dw",
"optionGroupName": "dwfix-og",
"options": []
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTenantDatabase
#Description
Creates a tenant database in a DB instance that uses the multi-tenant configuration.
DeleteBlueGreenDeployment
#Description
Deletes a blue/green deployment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BlueGreenDeploymentNotFoundFault",
"errorMessage": "Blue Green Deployment 'ddddd' doesn't exist.",
"eventCategory": "Management",
"eventID": "7f4ae431-9c37-44bb-93a5-7ee94f4696a9",
"eventName": "DeleteBlueGreenDeployment",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6cbcf1fe-0314-49db-9617-4f70717aa2de",
"requestParameters": {
"blueGreenDeploymentIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCustomDBEngineVersion
#Description
Deletes a custom engine version.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "The custom engine version you requested may not exist or you don't have the required permission.",
"eventCategory": "Management",
"eventID": "59e1d6dd-9993-4700-8e79-693d40c09bee",
"eventName": "DeleteCustomDBEngineVersion",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "46eadd9f-817f-4fe4-a23b-faa148a8e828",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBClusterAutomatedBackup
#Description
Deletes automated backups using the DbClusterResourceId value of the source DB cluster or the Amazon Resource Name (ARN) of the automated backups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The parameter db-cluster-resource-id isn't a valid DbClusterResourceId. The DbClusterResourceId must begin with the prefix cluster- and contain only ASCII letters and digits.",
"eventCategory": "Management",
"eventID": "3774e05b-3263-4c96-a97a-c45fbe4d0044",
"eventName": "DeleteDBClusterAutomatedBackup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0ab8ae93-98d5-4653-9ca2-52b69dba4a7a",
"requestParameters": {
"dbClusterResourceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490↳ also matches DeleteDBInstanceAutomatedBackup
DeleteDBClusterEndpoint
#Description
Deletes a custom endpoint and removes it from an Amazon Neptune DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterEndpointNotFoundFault",
"errorMessage": "DBClusterEndpoint dw-probe not found",
"eventCategory": "Management",
"eventID": "004d6b43-9d13-49e8-ac2d-b012d396eeeb",
"eventName": "DeleteDBClusterEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6be982cb-15f5-4286-bbf3-08ec0d15f32d",
"requestParameters": {
"dBClusterEndpointIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBClusterParameterGroup
#Description
Deletes a specified cluster parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBClusterParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "29f34925-ae1f-4d5a-8a9f-2813ba0c3f36",
"eventName": "DeleteDBClusterParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "02e8d173-34fc-4a47-a09f-9751de64831c",
"requestParameters": {
"dBClusterParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBInstanceAutomatedBackup
#Description
Deletes automated backups using the DbiResourceId value of the source DB instance or the Amazon Resource Name (ARN) of the automated backups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "You must enter either DbInstanceAutomatedBackupsArn or DbiResourceId.",
"eventCategory": "Management",
"eventID": "15d20f64-4ae7-4f27-941c-f38b777c66b0",
"eventName": "DeleteDBInstanceAutomatedBackup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:45:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6bcff2d5-2b5c-4376-a323-14c48cc1811c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490↳ also matches DeleteDBClusterAutomatedBackup
DeleteDBParameterGroup
#Description
Deletes a specified DBParameterGroup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "9ad975e7-b4cb-43b6-82ca-e25a694d133f",
"eventName": "DeleteDBParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d8627746-22ae-4d05-bbfc-e7a1b1a433fa",
"requestParameters": {
"dBParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBProxy
#Description
Deletes an existing DB proxy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "35df340f-5744-40e6-88a6-61a55961df3d",
"eventName": "DeleteDBProxy",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f6eda1a7-2b60-4aff-bd1b-393f2d894f4e",
"requestParameters": {
"dBProxyName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:58Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBProxyEndpoint
#Description
Deletes a DBProxyEndpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyEndpointNotFoundFault",
"errorMessage": "DBProxyEndpoint 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "aed23f99-b301-48df-abb3-04fe3627258d",
"eventName": "DeleteDBProxyEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8ce32283-8f14-4f68-9fbb-723bec98f1bb",
"requestParameters": {
"dBProxyEndpointName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:58Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBShardGroup
#Description
Deletes an Aurora Limitless Database DB shard group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBShardGroupNotFoundFault",
"errorMessage": "DB shard group not found or can not be accessed",
"eventCategory": "Management",
"eventID": "a51fe6f1-be94-40ec-84d9-f35d55d65be5",
"eventName": "DeleteDBShardGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7ba32d1b-320c-429b-aed4-e10daa8c242b",
"requestParameters": {
"dBShardGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDBSubnetGroup
#Description
Deletes a subnet group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSubnetGroupNotFoundFault",
"errorMessage": "DB subnet group 'dw-probe' does not exist.",
"eventCategory": "Management",
"eventID": "e43ec713-9120-4004-8e70-d98842eb5227",
"eventName": "DeleteDBSubnetGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "822bfc13-f6fe-4038-b7f9-fb1c72aef36b",
"requestParameters": {
"dBSubnetGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteEventSubscription
#Description
Deletes an Amazon DocumentDB event notification subscription.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "SubscriptionNotFoundFault",
"errorMessage": "Event Subscription dw-probe not found.",
"eventCategory": "Management",
"eventID": "0cb7b7fd-3228-426a-82a4-cd530a4003a9",
"eventName": "DeleteEventSubscription",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "243e0e80-0f54-4977-b0af-95da825de5ef",
"requestParameters": {
"subscriptionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIntegration
#Description
Deletes a zero-ETL integration with Amazon Redshift.
DeleteOptionGroup
#Description
Deletes an existing option group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "OptionGroupNotFoundFault",
"errorMessage": "Specified OptionGroupName: dw-probe not found.",
"eventCategory": "Management",
"eventID": "9d084e30-6bd4-483c-8e91-45acb6014b68",
"eventName": "DeleteOptionGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fef2925a-e7c3-4270-acec-8c2bba2dd7ba",
"requestParameters": {
"optionGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTenantDatabase
#Description
Deletes a tenant database from your DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance not found: dw-probe",
"eventCategory": "Management",
"eventID": "611088e5-06fa-40c4-9c2c-fc6dc0440aaf",
"eventName": "DeleteTenantDatabase",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "43e04f5c-1c30-4402-82ae-80fa9f3bc964",
"requestParameters": {
"dBInstanceIdentifier": "dw-probe",
"skipFinalSnapshot": false,
"tenantDBName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterDBProxyTargets
#Description
Remove the association between one or more DBProxyTarget data structures and a DBProxyTargetGroup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "e98492a8-7351-4d5c-a471-2606d7c104a4",
"eventName": "DeregisterDBProxyTargets",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7d817d8b-7fe3-4319-b08d-f34dd452fcdd",
"requestParameters": {
"dBProxyName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:59Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountAttributes
#Description
Lists all of the attributes for a customer account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b73a8e9d-7b64-43a0-b6ec-f9fa72ec5d18",
"eventName": "DescribeAccountAttributes",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "cd303e63-76df-4bd2-a2f5-38cea268f1df",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeBlueGreenDeployments
#Description
Describes one or more blue/green deployments.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "f87c126e-ff77-4c8b-9277-267c81b11c68",
"eventName": "DescribeBlueGreenDeployments",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "4098a577-4037-4fb0-b1ef-3f02e31ca1b4",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeCertificates
#Description
Returns a list of certificate authority (CA) certificates provided by Amazon DocumentDB for this Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "8981c57b-d61a-49f3-b134-a1c6d1674157",
"eventName": "DescribeCertificates",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "3c442b66-1f11-4c80-b4e0-7a30aeef725e",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDBClusterAutomatedBackups
#Description
Displays backups for both current and deleted DB clusters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7a1f1365-66aa-42b6-8d72-afcaa94ebb43",
"eventName": "DescribeDBClusterAutomatedBackups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d8cbe827-6fd8-460f-9197-d141c2d8b034",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBClusterBacktracks
#Description
Returns information about backtracks for a DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "Could not find specified DB Cluster",
"eventCategory": "Management",
"eventID": "629f6650-efc4-48d0-98b6-d9d31ad77170",
"eventName": "DescribeDBClusterBacktracks",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cf2ed184-8981-4b78-a55e-215366c52a33",
"requestParameters": {
"dBClusterIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBClusterEndpoints
#Description
Returns information about endpoints for an Amazon Neptune DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "fab10466-28ed-4ce8-9300-45298faceb4",
"eventName": "DescribeDBClusterEndpoints",
"eventSource": "rds.amazonaws.com",
"eventTime": "2019-07-02T20:36:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "b2effafc-6810-43ad-9fba-68dc01e3f07a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.52.31.206",
"userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeDBClusterParameterGroups
#Description
Returns a list of DBClusterParameterGroup descriptions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "6e669813-bca3-4a5d-a1f1-dd26e88345c0",
"eventName": "DescribeDBClusterParameterGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "ace5e4a6-6ee0-4797-a8af-078b3e20d202",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDBClusterParameters
#Description
Returns the detailed parameter list for a particular cluster parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBClusterParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "9fe3cc58-579c-413d-91ce-15e43c88005f",
"eventName": "DescribeDBClusterParameters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "609fa507-8fa1-4bb6-84d1-ae71ad938f53",
"requestParameters": {
"dBClusterParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBClusters
#Description
Returns information about provisioned Amazon DocumentDB clusters.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7781c787-f07f-47d8-900e-6456f15ff82f",
"eventName": "DescribeDBClusters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "64e4d8e9-c216-4572-94d7-2edb3d392665",
"requestParameters": {
"includeShared": true
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDBClusterSnapshotAttributes
#Description
Returns a list of cluster snapshot attribute names and values for a manual DB cluster snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterSnapshotNotFoundFault",
"errorMessage": "DBClusterSnapshot not found: dw-probe",
"eventCategory": "Management",
"eventID": "495ddcd9-f860-4bac-976a-ac601f82bb98",
"eventName": "DescribeDBClusterSnapshotAttributes",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7c852f64-8e7f-4a94-b893-bce6b777b9ca",
"requestParameters": {
"dBClusterSnapshotIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBClusterSnapshots
#Description
Returns information about cluster snapshots.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "61a0f81e-f7ae-41ef-9675-09ba66de605c",
"eventName": "DescribeDBClusterSnapshots",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "781f3f1b-d22f-4bef-ab01-538e8e94cac9",
"requestParameters": {
"includePublic": false,
"includeShared": false
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1580↳ also matches DescribeDBSnapshots
References #
DescribeDBEngineVersions
#Description
Returns a list of the available engines.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "6fd95e78-7e26-4de6-87fc-8a4fa7394544",
"eventName": "DescribeDBEngineVersions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "0a7c8907-73ce-46d7-bf30-7c1d338fe818",
"requestParameters": {
"defaultOnly": false,
"listSupportedCharacterSets": true,
"marker": "bWFyaWFkYgoxMC42LjE0"
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDBInstanceAutomatedBackups
#Description
Displays backups for both current and deleted instances.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "ef4d7934-bb3d-430a-80de-7128c84333bd",
"eventName": "DescribeDBInstanceAutomatedBackups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2019-07-02T20:36:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a8bedc23-f7e0-4548-ba20-7a5fb6f60bd5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.52.31.206",
"userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeDBLogFiles
#Description
Returns a list of DB log files for the DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance not found: dw-probe",
"eventCategory": "Management",
"eventID": "6dff181f-0cc2-400e-8908-78a3fe2ee875",
"eventName": "DescribeDBLogFiles",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c019a902-c34b-4ac7-a1b4-f9c87704261e",
"requestParameters": {
"dBInstanceIdentifier": "dw-probe",
"fileLastWritten": 0,
"fileSize": 0
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBMajorEngineVersions
#Description
Describes the properties of specific major versions of DB engines.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "73624923-4a5e-4c5a-b32e-f3aa9732e66b",
"eventName": "DescribeDBMajorEngineVersions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "36a6d43a-1dbc-48b6-b36e-18f11bd21824",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBParameterGroups
#Description
Returns a list of DBParameterGroup descriptions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "491d711a-5d8c-4a74-9d06-ba68fd00056d",
"eventName": "DescribeDBParameterGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5011b253-0a6c-4923-a841-f5b2638eb5a3",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDBParameters
#Description
Returns the detailed parameter list for a particular DB parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "015e865b-b822-451a-bc77-3fe7fc04c5b6",
"eventName": "DescribeDBParameters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4cfc76d5-d15b-4054-ba73-27e8b036ad2e",
"requestParameters": {
"dBParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBProxies
#Description
Returns information about DB proxies.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:DescribeDBProxies on resource: *",
"eventID": "cb8923b6-3bf1-4a97-a820-412d125fa71e",
"eventName": "DescribeDBProxies",
"eventSource": "rds.amazonaws.com",
"eventTime": "2020-06-10T05:32:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "ac29d92c-edf5-409f-a1ec-d0d59b3da622",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA1SGW6G0UATGTBPYU",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"sessionContext": {
"attributes": {
"creationDate": "2020-06-10T05:32:42Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeDBProxyEndpoints
#Description
Returns information about DB proxy endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b3da2f3a-6452-4dc5-9733-4b15603351c5",
"eventName": "DescribeDBProxyEndpoints",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "849ed635-4090-47cb-a40e-001de317f0a9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T18:32:27Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBProxyTargetGroups
#Description
Returns information about DB proxy target groups, represented by DBProxyTargetGroup data structures.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "99bc6cc1-b6f9-4353-a700-fcbb8d6247c5",
"eventName": "DescribeDBProxyTargetGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7f6d5012-6064-4b66-8ead-9036dd6bf8a2",
"requestParameters": {
"dBProxyName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T18:45:19Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBProxyTargets
#Description
Returns information about DBProxyTarget objects.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "fd9f5e15-c1f9-433f-ac5d-f636916b1c68",
"eventName": "DescribeDBProxyTargets",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3b1c2be9-c138-4846-954d-67d184a491e8",
"requestParameters": {
"dBProxyName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T18:45:19Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBRecommendations
#Description
Describes the recommendations to resolve the issues for your DB instances, DB clusters, and DB parameter groups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0e6e3258-e422-4b02-85ae-ad62cfebbf37",
"eventName": "DescribeDBRecommendations",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "48c07b07-1b33-42a3-a084-edba0943f292",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBSecurityGroups
#Description
Returns a list of DBSecurityGroup descriptions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "2e61e3c7-bb96-43c7-ab5e-0304d78fab71",
"eventName": "DescribeDBSecurityGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2017-03-04T22:12:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "9cfe6765-0127-11e7-b9e9-e1a60774bf",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "3.254.5.251",
"userAgent": "Boto/2.10.0 (win32)",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeDBShardGroups
#Description
Describes existing Aurora Limitless Database DB shard groups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0417cad9-17ac-434f-9e19-45660568e134",
"eventName": "DescribeDBShardGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "537b3231-ecf6-4826-99e8-59b064174584",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBSnapshotAttributes
#Description
Returns a list of DB snapshot attribute names and values for a manual DB snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSnapshotNotFoundFault",
"errorMessage": "DBSnapshot not found: dw-probe",
"eventCategory": "Management",
"eventID": "adf251bf-b53d-4eb5-afa7-4b5a1f33a4b6",
"eventName": "DescribeDBSnapshotAttributes",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9798b9e4-caa1-4706-b7c4-7617b69b4af3",
"requestParameters": {
"dBSnapshotIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBSnapshotTenantDatabases
#Description
Describes the tenant databases that exist in a DB snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8a29e9e7-2606-42d3-8d0c-d9736a2354ff",
"eventName": "DescribeDBSnapshotTenantDatabases",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "09864b42-dffd-4d22-9c71-591d60986f65",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDBSubnetGroups
#Description
Returns a list of DBSubnetGroup descriptions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "026541c4-3ca9-4fd7-952d-7f9fd5515077",
"eventName": "DescribeDBSubnetGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:15:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "830a9734-b8df-4b53-bb47-817997a213dc",
"requestParameters": {
"dBSubnetGroupName": "stratus-red-team-share-snap-vpc"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_06a62bf9-ef89-43a1-a17b-5234dcbf4cb4 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeEngineDefaultClusterParameters
#Description
Returns the default engine and system parameter information for the cluster database engine.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "ParameterGroupFamily dw-probe is not a valid parameter group family",
"eventCategory": "Management",
"eventID": "902ea466-ca93-403c-a744-ab44aa6f0604",
"eventName": "DescribeEngineDefaultClusterParameters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6e5e54e9-237b-4022-b87f-de5cddf977c1",
"requestParameters": {
"dBParameterGroupFamily": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeEngineDefaultParameters
#Description
Returns the default engine and system parameter information for the specified database engine.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "ParameterGroupFamily dw-probe is not a valid parameter group family",
"eventCategory": "Management",
"eventID": "f5ea8d95-0c21-4f01-9288-6467169086bc",
"eventName": "DescribeEngineDefaultParameters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4a7e1c7f-390e-4958-851e-3057bf94c9c7",
"requestParameters": {
"dBParameterGroupFamily": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeEventCategories
#Description
Displays a list of categories for all event source types, or, if specified, for a specified source type.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "d41e2a20-ec6c-4bd6-8a50-421447bafa9f6",
"eventName": "DescribeEventCategories",
"eventSource": "rds.amazonaws.com",
"eventTime": "2018-10-17T20:17:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "fff43f9a-864e-4324-be30-0ddc460b8534",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeEvents
#Description
Returns events related to instances, security groups, snapshots, and DB parameter groups for the past 14 days.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "ecea916b-8348-4166-ab7d-18be871f30bb",
"eventName": "DescribeEvents",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "70d98fa6-103e-4a91-b075-d14217e851cf",
"requestParameters": {
"duration": 1440
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeEventSubscriptions
#Description
Lists all the subscription descriptions for a customer account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "5c052932-3417-4553-a355-17bcfec19b4f",
"eventName": "DescribeEventSubscriptions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "abfb158d-1dcf-4ada-949c-c2d103e0870a",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeExportTasks
#Description
Returns information about a snapshot or cluster export to Amazon S3.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: rds:DescribeExportTasks",
"eventID": "da34bd05-b6bc-4139-8dcc-ada5f15447cf",
"eventName": "DescribeExportTasks",
"eventSource": "rds.amazonaws.com",
"eventTime": "2020-06-10T05:32:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "b1b89c2a-da4d-4adc-a1d0-a0947b54d88c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeGlobalClusters
#Description
Returns information about Amazon DocumentDB global clusters.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a292c6c3-0652-4f90-b921-21a76356f7f8",
"eventName": "DescribeGlobalClusters",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "fbe93792-975f-4dd5-9465-0d5bd106196f",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeIntegrations
#Description
Describe one or more zero-ETL integrations with Amazon Redshift.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "47ab6f8c-0e74-44dc-942a-bf0234573f8e",
"eventName": "DescribeIntegrations",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "37af21d9-09ba-4b47-84b3-b71ed304e201",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeOptionGroupOptions
#Description
Describes all available options.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid DB engine",
"eventCategory": "Management",
"eventID": "fa13c179-48a7-4ecd-ab90-196e06f32bc0",
"eventName": "DescribeOptionGroupOptions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1eb7d0e5-8369-4050-bcfd-1d68dd730c74",
"requestParameters": {
"engineName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeOptionGroups
#Description
Describes the available option groups.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "6a29520a-c41e-4282-a27c-6f230ffeab3b",
"eventName": "DescribeOptionGroups",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "11bf4dba-e1ef-447a-9a63-c802bbc2c1dc",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeOrderableDBInstanceOptions
#Description
Returns a list of orderable instance options for the specified engine.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "5bb4f93c-6f73-4f40-80e9-d97c55b033af",
"eventName": "DescribeOrderableDBInstanceOptions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "37bee226-7c1a-44f5-942f-da7f1df1533d",
"requestParameters": {
"engine": "sqlserver-ee",
"engineVersion": "15.00.4312.2.v1",
"marker": "ZGIucjUuMnhsYXJnZQpsaWNlbnNlLWluY2x1ZGVkCjE1LjAwLjQzMTIuMi52MQpZCmdwMg==",
"vpc": true
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribePendingMaintenanceActions
#Description
Returns a list of resources (for example, instances) that have at least one pending maintenance action.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "cddff16f-6b27-42a6-9c64-f4fcfc932ef4",
"eventName": "DescribePendingMaintenanceActions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2023-07-10T12:28:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "08e95c0c-c20d-4d9d-924d-bf16d98dc6a6",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeReservedDBInstances
#Description
Returns information about reserved DB instances for this account, or about a specified reserved DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "7bb78a69-0fac-46af-9d57-d6c2d1eafef0",
"eventName": "DescribeReservedDBInstances",
"eventSource": "rds.amazonaws.com",
"eventTime": "2018-10-17T20:17:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "bff42367-e8d2-4097-b500-eb53b693834",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeReservedDBInstancesOfferings
#Description
Lists available reserved DB instance offerings.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "719594a8f-6e92-45a0-b2e3-87bfd8f4828e",
"eventName": "DescribeReservedDBInstancesOfferings",
"eventSource": "rds.amazonaws.com",
"eventTime": "2019-07-02T20:36:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "87efc12f-b31b-4abc-ae19-78f237622d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.52.31.206",
"userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeServerlessV2PlatformVersions
#Description
Describes the properties of specific platform versions for Aurora Serverless v2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dd7b0bc1-bfa9-4b45-8aed-1647e41d5e2d",
"eventName": "DescribeServerlessV2PlatformVersions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "279d454e-32af-4c52-8508-e362effaa062",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSourceRegions
#Description
Returns a list of the source Amazon Web Services Regions where the current Amazon Web Services Region can create a read replica, copy a DB snapshot from, or replicate automated backups from.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "f6ed9a29-ab82-45fd-9af8-6cf876c99b27",
"eventName": "DescribeSourceRegions",
"eventSource": "rds.amazonaws.com",
"eventTime": "2018-10-17T20:17:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "b1a561c1-0a1b-4b06-9958-0abb230fefd9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTenantDatabases
#Description
Describes the tenant databases in a DB instance that uses the multi-tenant configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "132d7e61-a820-4d58-ad01-ea6ac014a111",
"eventName": "DescribeTenantDatabases",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:32:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b4108539-f477-40c7-92b4-7b6021545968",
"requestParameters": {
"maxRecords": 100
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeValidDBInstanceModifications
#Description
You can call DescribeValidDBInstanceModifications to learn what modifications you can make to your DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance not found: dw-probe",
"eventCategory": "Management",
"eventID": "6754f7f0-c075-4592-9a15-0291ab3bf50c",
"eventName": "DescribeValidDBInstanceModifications",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T18:45:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5ea93d0c-7295-4743-b7fe-b1f55189a216",
"requestParameters": {
"dBInstanceIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableHttpEndpoint
#Description
Disables the HTTP endpoint for the specified DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterCombinationException",
"errorMessage": "An unknown error occurred",
"eventCategory": "Management",
"eventID": "ed57452a-a4db-4e47-867c-ced2fbcce918",
"eventName": "DisableHttpEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:50:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9b5da9d6-c5e1-44c9-a18a-f0e6de26a665",
"requestParameters": {
"resourceArn": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DownloadDBLogFilePortion
#Description
Downloads all or a portion of the specified log file.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1552.001
EnableHttpEndpoint
#Description
Enables the HTTP endpoint for the DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterCombinationException",
"errorMessage": "An unknown error occurred",
"eventCategory": "Management",
"eventID": "58a51782-2fe5-4b95-8790-087053fa8974",
"eventName": "EnableHttpEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:50:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "84068bff-a1b2-47dc-bf1b-f5ffa4a2d91b",
"requestParameters": {
"resourceArn": "arn:aws:rds:us-west-1:123456789012:cluster:dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
FailoverDBCluster
#Description
Forces a failover for a cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDBClusterStateFault",
"errorMessage": "Database cluster:dwfix-aurora-cl should have at least two database instances for failover.",
"eventCategory": "Management",
"eventID": "ed3d0423-d58c-4edb-b9bc-c3002786f230",
"eventName": "FailoverDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d27ef57a-db44-49c3-88a1-0778206bb443",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1499↳ also matches FailoverGlobalCluster
FailoverGlobalCluster
#Description
Promotes the specified secondary DB cluster to be the primary DB cluster in the global cluster when failing over a global cluster occurs.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1499↳ also matches FailoverDBCluster
ModifyActivityStream
#Description
Changes the audit policy state of a database activity stream to either locked (default) or unlocked.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: rds:ModifyActivityStream because no identity-based policy allows the rds:ModifyActivityStream action",
"eventCategory": "Management",
"eventID": "e5dfb544-8e8f-42a0-a8a1-182f1adffcd0",
"eventName": "ModifyActivityStream",
"eventSource": "rds.amazonaws.com",
"eventTime": "2024-08-18T15:49:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d72b80c4-4492-4fc2-a749-c12e6abd871f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_76ba4fbc-8896-492d-bd45-8de66c9423fd cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#rds.modify-activity-stream",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
References #
ModifyCertificates
#Description
Override the system-default Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate for Amazon RDS for new DB instances, or remove the override.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "94170d4c-e4a6-43ae-87f7-e51a3feb16c7",
"eventName": "ModifyCertificates",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "802194c5-3202-4524-9dd1-2a81cb3cd161",
"requestParameters": {
"removeCustomerOverride": true
},
"responseElements": {
"certificateArn": "arn:aws:rds:us-west-1::cert:rds-ca-rsa2048-g1",
"certificateIdentifier": "rds-ca-rsa2048-g1",
"certificateType": "CA",
"customerOverride": false,
"thumbprint": "0f7fb44cf65fc3b2b9133305fd11bc80973a36d5",
"validFrom": "May 19, 2021, 7:04:06 PM",
"validTill": "May 19, 2061, 8:04:06 PM"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyCurrentDBClusterCapacity
#Description
Set the capacity of an Aurora Serverless v1 DB cluster to a specific value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "DBCluster dw-probe not found.",
"eventCategory": "Management",
"eventID": "d4c9423a-ef41-48c9-ab61-d1ba90b0adf8",
"eventName": "ModifyCurrentDBClusterCapacity",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eb70486e-4cf7-44d9-9222-683a8d832abb",
"requestParameters": {
"dBClusterIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyCustomDBEngineVersion
#Description
Modifies the status of a custom engine version (CEV).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "The custom engine version you requested may not exist or you don't have the required permission.",
"eventCategory": "Management",
"eventID": "cdca7bbe-6ed9-4e4b-affa-9e9f268ecd40",
"eventName": "ModifyCustomDBEngineVersion",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "24e60c91-e95f-47ad-85cd-98b931eddcab",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBClusterEndpoint
#Description
Modifies the properties of an endpoint in an Amazon Neptune DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterEndpointNotFoundFault",
"errorMessage": "DBClusterEndpoint dw-probe not found",
"eventCategory": "Management",
"eventID": "355669ee-d5b6-4a82-82ae-3462c0b78490",
"eventName": "ModifyDBClusterEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cc179c45-82aa-45c8-9a99-a3b16cc7f53a",
"requestParameters": {
"dBClusterEndpointIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBClusterParameterGroup
#Description
Modifies the parameters of a cluster parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "Parameter group does not exist",
"eventCategory": "Management",
"eventID": "2f510134-1e3d-4de0-b897-52089135cba7",
"eventName": "ModifyDBClusterParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3dc81995-55be-4f35-b815-d62e28887609",
"requestParameters": {
"dBClusterParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBParameterGroup
#Description
Modifies the parameters of a DB parameter group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "fe0bd158-09e6-4b4a-af84-65e37eab32bc",
"eventName": "ModifyDBParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0c9e66bb-84c3-43b0-85d8-f8d9df5524af",
"requestParameters": {
"dBParameterGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBProxy
#Description
Changes the settings for an existing DB proxy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "6f26a692-7270-4319-9bbd-8368fd8da80d",
"eventName": "ModifyDBProxy",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:24:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f71ea064-dda3-48f3-8881-60d4241ad26f",
"requestParameters": {
"dBProxyName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:59Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBProxyEndpoint
#Description
Changes the settings for an existing DB proxy endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyEndpointNotFoundFault",
"errorMessage": "DBProxyEndpoint 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "430c7773-a667-4c4d-bc7e-96c4a7e9e698",
"eventName": "ModifyDBProxyEndpoint",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b02a12f1-9db8-4923-bc8f-0ff4ad13c8bb",
"requestParameters": {
"dBProxyEndpointName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:59Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBProxyTargetGroup
#Description
Modifies the properties of a DBProxyTargetGroup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBProxyNotFoundFault",
"errorMessage": "DBProxy 'ddddd' not found.",
"eventCategory": "Management",
"eventID": "51e207a8-d85f-43b3-a60c-1d7296a94cb4",
"eventName": "ModifyDBProxyTargetGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e9ba07de-938b-4ff0-97a0-aff130a3c1e5",
"requestParameters": {
"dBProxyName": "ddddd",
"targetGroupName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T19:24:59Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBRecommendation
#Description
Updates the recommendation status and recommended action status for the specified recommendation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBRecommendationNotFoundFault",
"errorMessage": " The recommendation with ID dw-probe can’t be found.",
"eventCategory": "Management",
"eventID": "005eb219-8baa-4613-9c72-4347d811dd29",
"eventName": "ModifyDBRecommendation",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3003ca7f-a7f5-4ba5-8ca3-84d7cac1778d",
"requestParameters": {
"recommendationId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBShardGroup
#Description
Modifies the settings of an Aurora Limitless Database DB shard group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBShardGroupNotFoundFault",
"errorMessage": "The DB shard group with requested identifier in requested account doesn't exist.",
"eventCategory": "Management",
"eventID": "4b86cc5b-f519-4973-a7e5-ddb77798db2e",
"eventName": "ModifyDBShardGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cf2d216f-5291-47df-b2b7-fe3ad675892b",
"requestParameters": {
"dBShardGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBSnapshot
#Description
Updates a manual DB snapshot with a new engine version.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSnapshotNotFoundFault",
"errorMessage": "Could not find snapshot with name dw-probe",
"eventCategory": "Management",
"eventID": "33208c54-5fcd-411a-8595-52387b60c6c4",
"eventName": "ModifyDBSnapshot",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "19a7fa0a-f2f0-478d-9c81-032c257e4446",
"requestParameters": {
"dBSnapshotIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDBSubnetGroup
#Description
Modifies an existing subnet group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBSubnetGroupNotFoundFault",
"errorMessage": "DB subnet group 'dw-probe' does not exist.",
"eventCategory": "Management",
"eventID": "7b344e9f-3ad7-489f-8a69-ec5440e8cfe4",
"eventName": "ModifyDBSubnetGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dd8cb2ff-2add-437e-9be1-25676043af0f",
"requestParameters": {
"dBSubnetGroupName": "dw-probe",
"subnetIds": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyEventSubscription
#Description
Modifies an existing Amazon DocumentDB event notification subscription.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "SubscriptionNotFoundFault",
"errorMessage": "Event Subscription dw-probe not found.",
"eventCategory": "Management",
"eventID": "c54fef95-cafe-4d2e-93fa-9413371e552c",
"eventName": "ModifyEventSubscription",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3f8dc110-2a3b-4dda-bbf2-fe9172a25789",
"requestParameters": {
"subscriptionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyGlobalCluster
#Description
Modify a setting for an Amazon DocumentDB global cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "GlobalClusterNotFoundFault",
"errorMessage": "Global cluster 'ddddd' not found",
"eventCategory": "Management",
"eventID": "1d71db55-49b6-4ad0-9d5c-6f89101180e3",
"eventName": "ModifyGlobalCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9b6aad86-170d-4259-b02d-53765083b8fb",
"requestParameters": {
"globalClusterIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIntegration
#Description
Modifies a zero-ETL integration with Amazon Redshift.
ModifyOptionGroup
#Description
Modifies an existing option group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "OptionGroupNotFoundFault",
"errorMessage": "Specified OptionGroupName: dw-probe not found.",
"eventCategory": "Management",
"eventID": "6d7332bb-50dc-4e61-a9a6-49c81f7d7d0d",
"eventName": "ModifyOptionGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "59228979-c0bd-4e16-a8c4-3311e2454480",
"requestParameters": {
"applyImmediately": false,
"optionGroupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTenantDatabase
#Description
Modifies an existing tenant database in a DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance not found: dw-probe",
"eventCategory": "Management",
"eventID": "df49e12a-8dea-4501-91a4-7a32e95976f5",
"eventName": "ModifyTenantDatabase",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e4ea53dd-885d-4fe8-a5c2-4baf9e300d80",
"requestParameters": {
"dBInstanceIdentifier": "dw-probe",
"tenantDBName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PromoteReadReplica
#Description
Promotes a Read Replica DB instance to a standalone DB instance.
PromoteReadReplicaDBCluster
#Description
Not supported.
PurchaseReservedDBInstancesOffering
#Description
Purchases a reserved DB instance offering.
RebootDBCluster
#Description
You might need to reboot your DB cluster, usually for maintenance reasons.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "The source cluster could not be found or cannot be accessed: dwfix-aurora-cl",
"eventCategory": "Management",
"eventID": "13754226-cbca-46ce-ba11-96ad0a163f7c",
"eventName": "RebootDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T22:40:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "14986bba-3f25-45e0-8398-7936d3fb5ef9",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1499↳ also matches RebootDBInstance, RebootDBShardGroup
RebootDBInstance
#Description
You might need to reboot your instance, usually for maintenance reasons.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDBInstanceStateFault",
"errorMessage": "Can only reboot db instances with state in: available, storage-optimization, storage-initialization, incompatible-credentials, incompatible-parameters. Instance dwfix-db has state: backing-up.",
"eventCategory": "Management",
"eventID": "ba7e3a7e-e055-45aa-8d4e-0b20e168b15f",
"eventName": "RebootDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T20:16:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "88f04d9e-5243-4eb4-8a72-628c6f61d92e",
"requestParameters": {
"dBInstanceIdentifier": "dwfix-db"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1499↳ also matches RebootDBCluster, RebootDBShardGroup
RebootDBShardGroup
#Description
You might need to reboot your DB shard group, usually for maintenance reasons.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1499↳ also matches RebootDBCluster, RebootDBInstance
RegisterDBProxyTargets
#Description
Associate one or more DBProxyTarget data structures with a DBProxyTargetGroup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5f2bf599-ca6b-4c32-9199-08b3c3d9a030",
"eventName": "RegisterDBProxyTargets",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5ba5eb3d-dd8e-45b1-85bb-f7506a244e00",
"requestParameters": {
"dBClusterIdentifiers": [
"dwfix-aurora-cl"
],
"dBProxyName": "dwfix-rds-proxy"
},
"responseElements": {
"dBProxyTargets": [
{
"port": 3306,
"rdsResourceId": "dwfix-aurora-cl",
"targetHealth": {
"state": "REGISTERING"
},
"type": "TRACKED_CLUSTER"
},
{
"endpoint": "dwfix-aurora-inst.cxoiy62mcpe0.us-west-1.rds.amazonaws.com",
"port": 3306,
"rdsResourceId": "dwfix-aurora-inst",
"targetHealth": {
"state": "REGISTERING"
},
"type": "RDS_INSTANCE"
}
]
},
"sourceIPAddress": "rds.amazonaws.com",
"userAgent": "rds.amazonaws.com",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"invokedBy": "rds.amazonaws.com",
"principalId": "AIDAEXAMPLE00000000",
"sessionContext": {
"attributes": {
"creationDate": "2026-06-29T23:09:39Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveFromGlobalCluster
#Description
Detaches an Amazon DocumentDB secondary cluster from a global cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Malformed db cluster arn dw-probe",
"eventCategory": "Management",
"eventID": "a1dbca2d-7403-4590-9188-6e1b71099c25",
"eventName": "RemoveFromGlobalCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "97a1bf3e-1a4c-45d8-867b-2f3039a4dfa7",
"requestParameters": {
"dbClusterIdentifier": "dw-probe",
"globalClusterIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveRoleFromDBCluster
#Description
Disassociates an Identity and Access Management (IAM) role from a DB cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterRoleNotFoundFault",
"errorMessage": "Role ARN arn:aws:iam::123456789012:role/dwfix-rds-proxy-role with Feature Name s3Export cannot be found for DB Cluster: dwfix-aurora-cl. Verify your role ARN and try again.",
"eventCategory": "Management",
"eventID": "83814f07-3ff5-4bc5-9ed3-6f3c113060d0",
"eventName": "RemoveRoleFromDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0b3e924e-a22f-4396-a062-5d65e7774573",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl",
"featureName": "s3Export",
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveRoleFromDBInstance
#Description
Disassociates an Amazon Web Services Identity and Access Management (IAM) role from a DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDBInstanceStateFault",
"errorMessage": "The dwfix-aurora-inst DB instance is associated with a database cluster. Manage the arn:aws:iam::123456789012:role/dwfix-rds-proxy-role IAM role from the cluster instead of from the DB instance.",
"eventCategory": "Management",
"eventID": "1620472e-a375-4b72-990e-78f8cf7f3692",
"eventName": "RemoveRoleFromDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f783dc77-58be-46e9-aaf2-f3ba90bc91eb",
"requestParameters": {
"dBInstanceIdentifier": "dwfix-aurora-inst",
"featureName": "s3Export",
"roleArn": "arn:aws:iam::123456789012:role/dwfix-rds-proxy-role"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveSourceIdentifierFromSubscription
#Description
Removes a source identifier from an existing Amazon DocumentDB event notification subscription.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "SubscriptionNotFoundFault",
"errorMessage": "Event Subscription dw-probe not found.",
"eventCategory": "Management",
"eventID": "5f8b57df-f60d-4b5e-9917-ed40fa65a2ef",
"eventName": "RemoveSourceIdentifierFromSubscription",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8571bc5b-b90f-4351-8456-c87569f267bf",
"requestParameters": {
"sourceIdentifier": "dw-probe",
"subscriptionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetDBClusterParameterGroup
#Description
Modifies the parameters of a cluster parameter group to the default value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBClusterParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "9202709f-540b-482f-a548-89dbc0110c6d",
"eventName": "ResetDBClusterParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a9ec99e4-a983-4b41-801a-d87a674758d6",
"requestParameters": {
"dBClusterParameterGroupName": "dw-probe",
"resetAllParameters": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetDBParameterGroup
#Description
Modifies the parameters of a DB parameter group to the engine/system default value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBParameterGroupNotFoundFault",
"errorMessage": "DBParameterGroup not found: dw-probe",
"eventCategory": "Management",
"eventID": "3ef87552-e4db-439d-a7da-5e409db4ab8a",
"eventName": "ResetDBParameterGroup",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a278ad03-f616-44a1-80f2-343eb42619a4",
"requestParameters": {
"dBParameterGroupName": "dw-probe",
"resetAllParameters": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RestoreDBClusterFromS3
#Description
Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket.
RestoreDBClusterFromSnapshot
#Description
Creates a new cluster from a snapshot or cluster snapshot.
RestoreDBClusterToPointInTime
#Description
Restores a cluster to an arbitrary point in time.
RestoreDBInstanceToPointInTime
#Description
Restores a DB instance to an arbitrary point-in-time.
StartActivityStream
#Description
Starts a database activity stream to monitor activity on the database.
StartDBCluster
#Description
Restarts the stopped cluster that is specified by DBClusterIdentifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDBClusterStateFault",
"errorMessage": "DbCluster dwfix-aurora-cl is in available state but expected it to be one of stopped,inaccessible-encryption-credentials-recoverable.",
"eventCategory": "Management",
"eventID": "c17e4973-6632-429e-863b-1d42c271da73",
"eventName": "StartDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:05:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e8621a03-bdff-47bc-afe1-20f4c83cb006",
"requestParameters": {
"dBClusterIdentifier": "dwfix-aurora-cl"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartDBInstance
#Description
Starts an Amazon RDS DB instance that was stopped using the Amazon Web Services console, the stop-db-instance CLI command, or the StopDBInstance operation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterCombinationException",
"errorMessage": "aurora-mysql DB instances are not eligible for stopping and starting.",
"eventCategory": "Management",
"eventID": "7ba348b1-d51b-427d-a371-e6fb518ab9c1",
"eventName": "StartDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T23:10:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c7f11522-9f30-4744-99b1-fc3f8582a059",
"requestParameters": {
"dBInstanceIdentifier": "dwfix-aurora-inst"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartDBInstanceAutomatedBackupsReplication
#Description
Enables replication of automated backups to a different Amazon Web Services Region.
StopActivityStream
#Description
Stops a database activity stream that was started using the Amazon Web Services console, the start-activity-stream CLI command, or the StartActivityStream operation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562.008
StopDBCluster
#Description
Stops the running cluster that is specified by DBClusterIdentifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBClusterNotFoundFault",
"errorMessage": "DBCluster dw-probe not found.",
"eventCategory": "Management",
"eventID": "eed534b1-113a-4f74-923a-e303c510f256",
"eventName": "StopDBCluster",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3e80fd66-dcc0-4b74-96ab-794e8cd5dd3f",
"requestParameters": {
"dBClusterIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StopDBInstance
#Description
Stops an Amazon RDS DB instance temporarily.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "DBInstanceNotFoundFault",
"errorMessage": "DBInstance dw-probe not found.",
"eventCategory": "Management",
"eventID": "bfc408a6-0f40-4a68-b6f2-832b81345b7d",
"eventName": "StopDBInstance",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1fb378ce-67e4-4692-b03d-a1af2ce8a294",
"requestParameters": {
"dBInstanceIdentifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StopDBInstanceAutomatedBackupsReplication
#Description
Stops automated backup replication for a DB instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The SourceDBInstanceArn you provided isn't a valid Amazon Resource Name (ARN).",
"eventCategory": "Management",
"eventID": "45ccc06e-5d4c-4d9c-8890-a582235b0466",
"eventName": "StopDBInstanceAutomatedBackupsReplication",
"eventSource": "rds.amazonaws.com",
"eventTime": "2026-06-29T19:25:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "26930ecc-11fb-4359-bdb5-76659fcc10ca",
"requestParameters": {
"sourceDBInstanceArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SwitchoverBlueGreenDeployment
#Description
Switches over a blue/green deployment.
SwitchoverGlobalCluster
#Description
Switches over the specified secondary Amazon DocumentDB cluster to be the new primary Amazon DocumentDB cluster in the global database cluster.
SwitchoverReadReplica
#Description
Switches over an Oracle standby database in an Oracle Data Guard environment, making it the new primary database.