CreateDBSnapshot
CreateDBSnapshot
Event
Creates a manual snapshot of a DB instance, distinct from a DB cluster snapshot. Creation is asynchronous; confirm availability and encryption before treating it as usable. A manual snapshot is a normal backup mechanism, not inherently malicious.
Security Context
Unauthorized backup creation can stage collection of sensitive data (contextual T1530). Approved backups, troubleshooting, and migrations are common. Creation alone does not transfer data to another account; identify subsequent access and handling before claiming exfiltration.
Log Source
AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: CreateDBSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.dBInstanceIdentifier, dBSnapshotIdentifier | Source and requested backup/image settings; exact paths are shown in the sample. |
responseElements | Returned resource ID and initial state, where present; track to completion. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Resolve the source’s owner, sensitivity, encryption, and expected backup or imaging schedule.
- Follow creation to completion and inspect the resulting resource and included storage. Do not infer contents from names.
- Correlate ModifyDBSnapshotAttribute and actual recipient use; sharing and KMS permissions are separate evidence.
Sample Event
Synthetic scenario. Draco requests a manual snapshot and the response is creating. No sharing operation, recipient access, or data extraction is shown.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:01:14Z", "eventSource": "rds.amazonaws.com", "eventName": "CreateDBSnapshot", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBInstanceIdentifier": "occamy-prod-metadata", "dBSnapshotIdentifier": "occamy-prod-metadata-666-share" }, "responseElements": { "dBSnapshot": { "dBSnapshotIdentifier": "occamy-prod-metadata-666-share", "dBInstanceIdentifier": "occamy-prod-metadata", "engine": "postgres", "engineVersion": "15.5", "snapshotType": "manual", "status": "creating", "port": 5432, "allocatedStorage": 200, "licenseModel": "postgresql-license", "masterUsername": "occamyadmin", "availabilityZone": "us-east-1a", "instanceCreateTime": "Mar 1, 2026, 9:00:00 AM", "percentProgress": 0, "encrypted": true, "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001", "storageType": "gp3" } }, "requestID": "90000000-0000-4000-8000-000010000010", "eventID": "90000000-0000-4000-8000-000010000011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.