Skip to content

AuthorizeDBSecurityGroupIngress

AWS

AuthorizeDBSecurityGroupIngress

service: AWS - RDS
techniques:

Event

Adds an authorized IP range or security-group source to an RDS DB security group. This is a legacy DB security-group API, not the ordinary VPC security-group rule API. AWS documents EC2-Classic retirement; do not assume a successful modern non-VPC deployment from this event name.

Security Context

Unauthorized ingress expansion can weaken database network controls. Approved client onboarding is also legitimate. Database authentication and actual network reachability still matter; this request neither reads database data nor proves a connection succeeded.

T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: rds.amazonaws.com and eventName: AuthorizeDBSecurityGroupIngress. Search regional Event history or retained management-event logs, accounting for collection scope and retention.

Key Fields

FieldInvestigation use
requestParameters.dBSecurityGroupNameLegacy DB security group.
requestParameters.cIDRIPRequested source range, when supplied.
responseElements.dBSecurityGroupReturned authorizations and their status, when recorded.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm the resource type and historical deployment context; for current VPC rules, also search AuthorizeSecurityGroupIngress.
  2. Inspect errors and verify authorization status. An authorizing response is not proof of completed propagation.
  3. Recover affected database associations and prior sources; compare the change with approved application access.
  4. Correlate database authentication and query evidence before claiming access or collection.

Sample Event

Synthetic scenario. This historical-style example requests 0.0.0.0/0 for a legacy DB security group. It is not evidence that EC2-Classic resources remain available today. The illustrated authorizing state is not a completed connection. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.

{
"eventVersion": "1.08",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2021-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2021-04-15T21:02:48Z",
"eventSource": "rds.amazonaws.com",
"eventName": "AuthorizeDBSecurityGroupIngress",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"dBSecurityGroupName": "niffler-analytics-default",
"cIDRIP": "0.0.0.0/0"
},
"responseElements": {
"dBSecurityGroup": {
"ownerId": "555123456789",
"dBSecurityGroupName": "niffler-analytics-default",
"dBSecurityGroupDescription": "default",
"iPRanges": [
{
"status": "authorizing",
"cIDRIP": "0.0.0.0/0"
}
],
"eC2SecurityGroups": []
}
},
"requestID": "90000000-0000-4000-8000-000001110110",
"eventID": "90000000-0000-4000-8000-000001110111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.