AWS RDS DB Snapshot Created
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Identifies when an AWS RDS DB Snapshot is created. This can be used to evade defenses by allowing an attacker to bypass access controls or cover their tracks by reverting an instance to a previous state. This is a building block rule and does not generate alerts on its own. It is meant to be used for correlation with other rules to detect suspicious activity. To generate alerts, create a rule that uses this signal as a building block.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_AWS_RDS_SNAPSHOT_CREATED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS
Detection
Execution Mode
realtime
Log Sources
AWS


