ModifyDBSnapshotAttribute
ModifyDBSnapshotAttribute
Event
Modifies attributes of a manual DB snapshot. The restore attribute adds or removes authorized accounts; all makes an eligible unencrypted snapshot public. Encrypted snapshots cannot be public and require compatible customer-managed-key access. A shared encrypted snapshot must be copied before restoration; it cannot be restored directly.
Security Context
Unauthorized sharing can support transfer to another cloud account (T1537). Approved sharing is common; changing permissions does not prove the recipient copied or read data. Snapshot contents and ownership require evidence beyond names.
Log Source
AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: ModifyDBSnapshotAttribute. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.dBSnapshotIdentifier | Manual snapshot whose access changes. |
requestParameters.attributeName, valuesToAdd, valuesToRemove | Direction and scope of sharing. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Recover previous attributes and verify added recipients or public access against approval.
- Check encryption and KMS policies. Snapshots using the default AWS managed RDS key are not shareable; encrypted cross-account use requires the documented copy path.
- Correlate copy and RestoreDBInstanceFromDBSnapshot activity and subsequent database access.
Sample Event
Synthetic scenario. Draco adds an external account to restore permissions. This does not show a completed copy or restore, and the snapshot’s encryption is not supplied.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:33:18Z", "eventSource": "rds.amazonaws.com", "eventName": "ModifyDBSnapshotAttribute", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBSnapshotIdentifier": "bowtruckle-prod-db-exfil-2026-04-15", "attributeName": "restore", "valuesToAdd": [ "555666661337" ] }, "responseElements": { "dBSnapshotIdentifier": "bowtruckle-prod-db-exfil-2026-04-15", "dBSnapshotAttributes": [ { "attributeName": "restore", "attributeValues": [ "555666661337" ] } ] }, "requestID": "90000000-0000-4000-8000-000101010010", "eventID": "90000000-0000-4000-8000-000101010011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.