AuthorizeDBSecurityGroupIngress
AuthorizeDBSecurityGroupIngress
Event
Adds an authorized IP range or security-group source to an RDS DB security group. This is a legacy DB security-group API, not the ordinary VPC security-group rule API. AWS documents EC2-Classic retirement; do not assume a successful modern non-VPC deployment from this event name.
Security Context
Unauthorized ingress expansion can weaken database network controls. Approved client onboarding is also legitimate. Database authentication and actual network reachability still matter; this request neither reads database data nor proves a connection succeeded.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: rds.amazonaws.com and eventName: AuthorizeDBSecurityGroupIngress. Search regional Event history or retained management-event logs, accounting for collection scope and retention.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.dBSecurityGroupName | Legacy DB security group. |
requestParameters.cIDRIP | Requested source range, when supplied. |
responseElements.dBSecurityGroup | Returned authorizations and their status, when recorded. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm the resource type and historical deployment context; for current VPC rules, also search AuthorizeSecurityGroupIngress.
- Inspect errors and verify authorization status. An authorizing response is not proof of completed propagation.
- Recover affected database associations and prior sources; compare the change with approved application access.
- Correlate database authentication and query evidence before claiming access or collection.
Sample Event
Synthetic scenario. This historical-style example requests 0.0.0.0/0 for a legacy DB security group. It is not evidence that EC2-Classic resources remain available today. The illustrated authorizing state is not a completed connection. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.08", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2021-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2021-04-15T21:02:48Z", "eventSource": "rds.amazonaws.com", "eventName": "AuthorizeDBSecurityGroupIngress", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBSecurityGroupName": "niffler-analytics-default", "cIDRIP": "0.0.0.0/0" }, "responseElements": { "dBSecurityGroup": { "ownerId": "555123456789", "dBSecurityGroupName": "niffler-analytics-default", "dBSecurityGroupDescription": "default", "iPRanges": [ { "status": "authorizing", "cIDRIP": "0.0.0.0/0" } ], "eC2SecurityGroups": [] } }, "requestID": "90000000-0000-4000-8000-000001110110", "eventID": "90000000-0000-4000-8000-000001110111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.