Skip to content

ModifyDBInstance

AWS

ModifyDBInstance

service: AWS - RDS
techniques:

Event

Changes requested settings such as network associations, sizing, credentials, and backup behavior. ApplyImmediately requests application of eligible changes, but timing and restart effects depend on the parameter and pending modifications. PubliclyAccessible does not independently grant network or database access. Existing storage encryption cannot simply be turned off through this API.

Security Context

Unauthorized network changes can weaken cloud firewall controls (contextual T1686.001). Ordinary maintenance uses the same broad API. A security-group ID does not disclose its rules; neither this event nor a public-address flag proves data collection or cross-account transfer.

Log Source

CloudTrail management event with eventSource: rds.amazonaws.com and eventName: ModifyDBInstance. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.dBInstanceIdentifierTarget and deployment type.
requestParameters.publiclyAccessible, vpcSecurityGroupIds, applyImmediatelyRequested changes; inspect actual rules and application timing.
responseElements.dBInstanceStatusModifying is not completion.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare requested changes and previous/pending configuration to approved maintenance.
  3. Verify actual VPC routes, subnet configuration, security-group rules, endpoint reachability, and database authentication after application.
  4. Correlate database authentication/query logs and GetSecretValue only when linked evidence supports it.

Sample Event

Synthetic scenario. Draco requests public accessibility and another security group. The sample does not show 0.0.0.0/0 rules, a stolen password, or a successful connection.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:25:31Z",
"eventSource": "rds.amazonaws.com",
"eventName": "ModifyDBInstance",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"dBInstanceIdentifier": "bowtruckle-prod-db",
"publiclyAccessible": true,
"vpcSecurityGroupIds": [
"sg-0123456789abcdef0"
],
"applyImmediately": true
},
"responseElements": {
"dBInstanceIdentifier": "bowtruckle-prod-db",
"dBInstanceClass": "db.r5.4xlarge",
"engine": "postgres",
"dBInstanceStatus": "modifying",
"masterUsername": "bowtruckle_admin",
"endpoint": {
"address": "bowtruckle-prod-db.cabcdef12345.us-east-1.rds.amazonaws.com",
"port": 5432,
"hostedZoneId": "Z2R2ITUGPM61AM"
},
"publiclyAccessible": true,
"vpcSecurityGroups": [
{
"vpcSecurityGroupId": "sg-0123456789abcdef0",
"status": "active"
}
]
},
"requestID": "90000000-0000-4000-8000-000101010000",
"eventID": "90000000-0000-4000-8000-000101010001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.