RestoreDBInstanceFromDBSnapshot
RestoreDBInstanceFromDBSnapshot
Event
Restores a snapshot into a new DB instance rather than overwriting the source. The restored state reflects the snapshot time, not necessarily current production data. A shared encrypted snapshot requires a copy before restoration. PubliclyAccessible does not independently supply routing, permissive security groups, database credentials, or unrestricted access.
Security Context
An unauthorized restore can stage collection (contextual T1530). Disaster recovery and testing commonly restore snapshots. A creating response is not an available database, and a different subnet-group name does not establish a different VPC or bypassed controls.
Log Source
AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: RestoreDBInstanceFromDBSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.dBSnapshotIdentifier, dBInstanceIdentifier | Source snapshot and new destination identity. |
requestParameters.publiclyAccessible, vpcSecurityGroupIds, dBSubnetGroupName | Requested network context; inspect actual group rules and subnets. |
responseElements | Initial status and encryption; verify final configuration. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Verify source ownership, snapshot time, encryption, KMS access, and restore authorization.
- Follow the instance to availability and inspect its real VPC, routes, security groups, and database authentication.
- Correlate connections and queries before claiming extraction. Review ModifyDBSnapshotAttribute only where it relates to this source.
Sample Event
Synthetic scenario. Draco requests a public-addressable restore in default-sandbox. The response is creating; neither the subnet group’s VPC nor the security group’s rules or a successful login are shown.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:53:14Z", "eventSource": "rds.amazonaws.com", "eventName": "RestoreDBInstanceFromDBSnapshot", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBInstanceIdentifier": "phoenix-prod-db-restored-temp", "dBSnapshotIdentifier": "phoenix-prod-db-snapshot-2026-04-12", "dBInstanceClass": "db.r6g.large", "publiclyAccessible": true, "vpcSecurityGroupIds": [ "sg-0123456789abcdef0" ], "dBSubnetGroupName": "default-sandbox" }, "responseElements": { "dBInstanceIdentifier": "phoenix-prod-db-restored-temp", "dBInstanceClass": "db.r6g.large", "engine": "postgres", "dBInstanceStatus": "creating", "masterUsername": "occamy_admin", "allocatedStorage": 200, "preferredBackupWindow": "07:00-08:00", "backupRetentionPeriod": 0, "vpcSecurityGroups": [ { "vpcSecurityGroupId": "sg-0123456789abcdef0", "status": "active" } ], "publiclyAccessible": true, "storageType": "gp3", "storageEncrypted": true, "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001", "dbInstanceArn": "arn:aws:rds:us-east-1:555123456789:db:phoenix-prod-db-restored-temp" }, "requestID": "90000000-0000-4000-8000-000110100000", "eventID": "90000000-0000-4000-8000-000110100001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.