Skip to content

RestoreDBInstanceFromDBSnapshot

AWS

RestoreDBInstanceFromDBSnapshot

service: AWS - RDS
tactics:
techniques:

Event

Restores a snapshot into a new DB instance rather than overwriting the source. The restored state reflects the snapshot time, not necessarily current production data. A shared encrypted snapshot requires a copy before restoration. PubliclyAccessible does not independently supply routing, permissive security groups, database credentials, or unrestricted access.

Security Context

An unauthorized restore can stage collection (contextual T1530). Disaster recovery and testing commonly restore snapshots. A creating response is not an available database, and a different subnet-group name does not establish a different VPC or bypassed controls.

Log Source

AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: RestoreDBInstanceFromDBSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.dBSnapshotIdentifier, dBInstanceIdentifierSource snapshot and new destination identity.
requestParameters.publiclyAccessible, vpcSecurityGroupIds, dBSubnetGroupNameRequested network context; inspect actual group rules and subnets.
responseElementsInitial status and encryption; verify final configuration.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Verify source ownership, snapshot time, encryption, KMS access, and restore authorization.
  3. Follow the instance to availability and inspect its real VPC, routes, security groups, and database authentication.
  4. Correlate connections and queries before claiming extraction. Review ModifyDBSnapshotAttribute only where it relates to this source.

Sample Event

Synthetic scenario. Draco requests a public-addressable restore in default-sandbox. The response is creating; neither the subnet group’s VPC nor the security group’s rules or a successful login are shown.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:53:14Z",
"eventSource": "rds.amazonaws.com",
"eventName": "RestoreDBInstanceFromDBSnapshot",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"dBInstanceIdentifier": "phoenix-prod-db-restored-temp",
"dBSnapshotIdentifier": "phoenix-prod-db-snapshot-2026-04-12",
"dBInstanceClass": "db.r6g.large",
"publiclyAccessible": true,
"vpcSecurityGroupIds": [
"sg-0123456789abcdef0"
],
"dBSubnetGroupName": "default-sandbox"
},
"responseElements": {
"dBInstanceIdentifier": "phoenix-prod-db-restored-temp",
"dBInstanceClass": "db.r6g.large",
"engine": "postgres",
"dBInstanceStatus": "creating",
"masterUsername": "occamy_admin",
"allocatedStorage": 200,
"preferredBackupWindow": "07:00-08:00",
"backupRetentionPeriod": 0,
"vpcSecurityGroups": [
{
"vpcSecurityGroupId": "sg-0123456789abcdef0",
"status": "active"
}
],
"publiclyAccessible": true,
"storageType": "gp3",
"storageEncrypted": true,
"kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001",
"dbInstanceArn": "arn:aws:rds:us-east-1:555123456789:db:phoenix-prod-db-restored-temp"
},
"requestID": "90000000-0000-4000-8000-000110100000",
"eventID": "90000000-0000-4000-8000-000110100001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection

Techniques:
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.