StartExportTask
StartExportTask
Event
Starts an asynchronous export; this example uses a DB snapshot source. Snapshot exports produce Parquet data for analysis, not a directly restorable RDS snapshot. The bucket must be in the snapshot Region. Export requires appropriate IAM role trust for export.rds.amazonaws.com, S3 permissions, and KMS authorization; selecting a familiar role name does not prove those conditions.
Security Context
Unauthorized export may collect data (T1530) or transfer it to another account (T1537) where destination ownership supports that interpretation. Approved analytics pipelines use the same API. STARTING and zero extracted bytes do not show completed export or caller read access to the output.
Log Source
AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: StartExportTask. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.sourceArn, exportOnly | Source and optional selected subset; omitted exportOnly is not evidence every table was successfully exported. |
requestParameters.s3BucketName, s3Prefix, iamRoleArn, kmsKeyId | Destination and export authorization context. |
responseElements.status, percentProgress | Initial progress; follow task warnings, failures, and completion. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Verify source engine/version support, snapshot state, export scope, and approved task ownership.
- Inspect bucket account/Region, role trust and permissions, and KMS grants/policies. Cross-account S3 export uses the documented API/CLI path.
- Confirm completed outputs and skipped data, then correlate GetObject access. Writing a task does not prove the caller can download its output.
Sample Event
Synthetic scenario. Draco starts an export to fantasticlogs-niffler-archive. The sample shows STARTING with zero extracted bytes; the role’s capabilities, bucket ownership, and a later download are not established.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:55:27Z", "eventSource": "rds.amazonaws.com", "eventName": "StartExportTask", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "exportTaskIdentifier": "phoenix-quarterly-export-2026-q1", "sourceArn": "arn:aws:rds:us-east-1:555123456789:snapshot:phoenix-prod-db-snapshot-2026-04-12", "s3BucketName": "fantasticlogs-niffler-archive", "iamRoleArn": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001", "s3Prefix": "customers/2026-q1/" }, "responseElements": { "exportTaskIdentifier": "phoenix-quarterly-export-2026-q1", "sourceArn": "arn:aws:rds:us-east-1:555123456789:snapshot:phoenix-prod-db-snapshot-2026-04-12", "s3Bucket": "fantasticlogs-niffler-archive", "s3Prefix": "customers/2026-q1/", "iamRoleArn": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001", "status": "STARTING", "percentProgress": 0, "totalExtractedDataInGB": 0, "snapshotTime": "Apr 12, 2026 6:00:00 AM", "taskStartTime": "Apr 15, 2026 8:55:27 PM" }, "requestID": "90000000-0000-4000-8000-000110110100", "eventID": "90000000-0000-4000-8000-000110110101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration Collection
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.