ModifyDBInstance
ModifyDBInstance
Event
Changes requested settings such as network associations, sizing, credentials, and backup behavior. ApplyImmediately requests application of eligible changes, but timing and restart effects depend on the parameter and pending modifications. PubliclyAccessible does not independently grant network or database access. Existing storage encryption cannot simply be turned off through this API.
Security Context
Unauthorized network changes can weaken cloud firewall controls (contextual T1686.001). Ordinary maintenance uses the same broad API. A security-group ID does not disclose its rules; neither this event nor a public-address flag proves data collection or cross-account transfer.
Log Source
CloudTrail management event with eventSource: rds.amazonaws.com and eventName: ModifyDBInstance. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.dBInstanceIdentifier | Target and deployment type. |
requestParameters.publiclyAccessible, vpcSecurityGroupIds, applyImmediately | Requested changes; inspect actual rules and application timing. |
responseElements.dBInstanceStatus | Modifying is not completion. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare requested changes and previous/pending configuration to approved maintenance.
- Verify actual VPC routes, subnet configuration, security-group rules, endpoint reachability, and database authentication after application.
- Correlate database authentication/query logs and GetSecretValue only when linked evidence supports it.
Sample Event
Synthetic scenario. Draco requests public accessibility and another security group. The sample does not show 0.0.0.0/0 rules, a stolen password, or a successful connection.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:25:31Z", "eventSource": "rds.amazonaws.com", "eventName": "ModifyDBInstance", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBInstanceIdentifier": "bowtruckle-prod-db", "publiclyAccessible": true, "vpcSecurityGroupIds": [ "sg-0123456789abcdef0" ], "applyImmediately": true }, "responseElements": { "dBInstanceIdentifier": "bowtruckle-prod-db", "dBInstanceClass": "db.r5.4xlarge", "engine": "postgres", "dBInstanceStatus": "modifying", "masterUsername": "bowtruckle_admin", "endpoint": { "address": "bowtruckle-prod-db.cabcdef12345.us-east-1.rds.amazonaws.com", "port": 5432, "hostedZoneId": "Z2R2ITUGPM61AM" }, "publiclyAccessible": true, "vpcSecurityGroups": [ { "vpcSecurityGroupId": "sg-0123456789abcdef0", "status": "active" } ] }, "requestID": "90000000-0000-4000-8000-000101010000", "eventID": "90000000-0000-4000-8000-000101010001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.