Skip to content

ModifyDBSnapshotAttribute

AWS

ModifyDBSnapshotAttribute

service: AWS - RDS
techniques:

Event

Modifies attributes of a manual DB snapshot. The restore attribute adds or removes authorized accounts; all makes an eligible unencrypted snapshot public. Encrypted snapshots cannot be public and require compatible customer-managed-key access. A shared encrypted snapshot must be copied before restoration; it cannot be restored directly.

Security Context

Unauthorized sharing can support transfer to another cloud account (T1537). Approved sharing is common; changing permissions does not prove the recipient copied or read data. Snapshot contents and ownership require evidence beyond names.

Log Source

AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: ModifyDBSnapshotAttribute. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.dBSnapshotIdentifierManual snapshot whose access changes.
requestParameters.attributeName, valuesToAdd, valuesToRemoveDirection and scope of sharing.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Recover previous attributes and verify added recipients or public access against approval.
  3. Check encryption and KMS policies. Snapshots using the default AWS managed RDS key are not shareable; encrypted cross-account use requires the documented copy path.
  4. Correlate copy and RestoreDBInstanceFromDBSnapshot activity and subsequent database access.

Sample Event

Synthetic scenario. Draco adds an external account to restore permissions. This does not show a completed copy or restore, and the snapshot’s encryption is not supplied.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:33:18Z",
"eventSource": "rds.amazonaws.com",
"eventName": "ModifyDBSnapshotAttribute",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"dBSnapshotIdentifier": "bowtruckle-prod-db-exfil-2026-04-15",
"attributeName": "restore",
"valuesToAdd": [
"555666661337"
]
},
"responseElements": {
"dBSnapshotIdentifier": "bowtruckle-prod-db-exfil-2026-04-15",
"dBSnapshotAttributes": [
{
"attributeName": "restore",
"attributeValues": [
"555666661337"
]
}
]
},
"requestID": "90000000-0000-4000-8000-000101010010",
"eventID": "90000000-0000-4000-8000-000101010011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.