RDS Database Security Group Modification

 Original Source: [Sigma source]
Title: RDS Database Security Group Modification
Status: test
Description:Detects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
References:
  -https://www.gorillastack.com/blog/real-time-events/important-aws-cloudtrail-security-events-tracking/
Author: jamesc-grafana
Date: 2024-07-11
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'rds.amazonaws.com'
    eventName:
      -'AuthorizeDBSecurityGroupIngress'
      -'CreateDBSecurityGroup'
      -'DeleteDBSecurityGroup'
      -'RevokeDBSecurityGroupIngress'

  condition:selection
Falsepositives:
  -Creation of a new Database that needs new security group rules
Level: medium