elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.85k stars 462 forks source link

[New Rule] AWS RDS DB Instance or Cluster Password Modified #3844

Closed imays11 closed 18 hours ago

imays11 commented 5 days ago

Issues

Summary

Identifies the modification of the master password for an AWS RDS DB instance or cluster. DB instances may contain sensitive data that can be abused if accessed by unauthorized actors. Amazon RDS API operations never return the password, so this operation provides a means to regain access if the password is lost. Adversaries with the proper permissions can take advantage of this to evade defenses and gain unauthorized access to a DB instance or cluster as to support persistence mechanisms or privilege escalation.

Screenshot 2024-06-27 at 11 47 03 PM