Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
Data Detection & Response, Cloud Data Asset Exfiltration |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
An RDS snapshot was exported to an unknown S3 bucket.
The destination bucket has not been seen in your tenant in the last 30 days.
Attacker's Goals
Exfiltrate data to an unknown bucket.
Investigative actions
- Check the legitimacy of the destination bucket.
- Review further logs for the source RDS instance.
- Review further actions performed by the identity.