Skip to content

StartExportTask

AWS

StartExportTask

service: AWS - RDS
techniques:

Event

Starts an asynchronous export; this example uses a DB snapshot source. Snapshot exports produce Parquet data for analysis, not a directly restorable RDS snapshot. The bucket must be in the snapshot Region. Export requires appropriate IAM role trust for export.rds.amazonaws.com, S3 permissions, and KMS authorization; selecting a familiar role name does not prove those conditions.

Security Context

Unauthorized export may collect data (T1530) or transfer it to another account (T1537) where destination ownership supports that interpretation. Approved analytics pipelines use the same API. STARTING and zero extracted bytes do not show completed export or caller read access to the output.

Log Source

AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: StartExportTask. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.sourceArn, exportOnlySource and optional selected subset; omitted exportOnly is not evidence every table was successfully exported.
requestParameters.s3BucketName, s3Prefix, iamRoleArn, kmsKeyIdDestination and export authorization context.
responseElements.status, percentProgressInitial progress; follow task warnings, failures, and completion.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Verify source engine/version support, snapshot state, export scope, and approved task ownership.
  3. Inspect bucket account/Region, role trust and permissions, and KMS grants/policies. Cross-account S3 export uses the documented API/CLI path.
  4. Confirm completed outputs and skipped data, then correlate GetObject access. Writing a task does not prove the caller can download its output.

Sample Event

Synthetic scenario. Draco starts an export to fantasticlogs-niffler-archive. The sample shows STARTING with zero extracted bytes; the role’s capabilities, bucket ownership, and a later download are not established.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:55:27Z",
"eventSource": "rds.amazonaws.com",
"eventName": "StartExportTask",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"exportTaskIdentifier": "phoenix-quarterly-export-2026-q1",
"sourceArn": "arn:aws:rds:us-east-1:555123456789:snapshot:phoenix-prod-db-snapshot-2026-04-12",
"s3BucketName": "fantasticlogs-niffler-archive",
"iamRoleArn": "arn:aws:iam::555123456789:role/OccamyPipelineRole",
"kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001",
"s3Prefix": "customers/2026-q1/"
},
"responseElements": {
"exportTaskIdentifier": "phoenix-quarterly-export-2026-q1",
"sourceArn": "arn:aws:rds:us-east-1:555123456789:snapshot:phoenix-prod-db-snapshot-2026-04-12",
"s3Bucket": "fantasticlogs-niffler-archive",
"s3Prefix": "customers/2026-q1/",
"iamRoleArn": "arn:aws:iam::555123456789:role/OccamyPipelineRole",
"kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001",
"status": "STARTING",
"percentProgress": 0,
"totalExtractedDataInGB": 0,
"snapshotTime": "Apr 12, 2026 6:00:00 AM",
"taskStartTime": "Apr 15, 2026 8:55:27 PM"
},
"requestID": "90000000-0000-4000-8000-000110110100",
"eventID": "90000000-0000-4000-8000-000110110101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration Collection

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.