Detection rules › Sigma
AWS RDS Master Password Change
Detects the change of database master password. It may be a part of data exfiltration.
Known false positives
- Benign changes to a db instance
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Exfiltration |
Telemetry coverage
Rules detecting the same action
These rules filter on the same operation.
- AWS Credential Access RDS Password reset (Splunk)
- AWS RDS DB Instance Made Public (Elastic)
- AWS RDS DB Instance or Cluster Deletion Protection Disabled (Elastic)
- AWS RDS DB Instance or Cluster Password Modified (Elastic)
- AWS RDS Deletion Protection Disabled (Panther)
- AWS RDS Instance Modified to be Publicly Accessible (Panther)
- AWS RDS Master Password Updated (Panther)
- AWS RDS Snapshot Deleted (Elastic)
Rule body
title: AWS RDS Master Password Change
id: 8a63cdd4-6207-414a-85bc-7e032bd3c1a2
status: test
description: Detects the change of database master password. It may be a part of data exfiltration.
references:
- https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/rds__explore_snapshots/main.py
author: faloker
date: 2020-02-12
modified: 2022-10-05
tags:
- attack.exfiltration
- attack.t1020
logsource:
product: aws
service: cloudtrail
detection:
selection_source:
eventSource: rds.amazonaws.com
responseElements.pendingModifiedValues.masterUserPassword|contains: '*'
eventName: ModifyDBInstance
condition: selection_source
falsepositives:
- Benign changes to a db instance
level: medium
Stages and Predicates
Stage 0: condition
selection_sourceStage 1: selection_source
selection_source:
eventSource: rds.amazonaws.com
responseElements.pendingModifiedValues.masterUserPassword|contains: '*'
eventName: ModifyDBInstance
Indicators
These rows show field, operator, and value matches.