AWS RDS DB Instance or Cluster Deletion Protection Disabled
Identifies the modification of an AWS RDS DB instance or cluster to remove the deletionProtection feature. Deletion protection is enabled automatically for instances set up through the console and can be used to protect them from unintentional deletion activity. If disabled an instance or cluster can be deleted, destroying sensitive or critical information. Adversaries with the proper permissions can take advantage of this to set up future deletion events against a compromised environment.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2024/06/28"
3integration = ["aws"]
4maturity = "production"
5updated_date = "2025/01/10"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies the modification of an AWS RDS DB instance or cluster to remove the deletionProtection feature. Deletion protection is enabled automatically for instances set up through the console and can be used to protect them from unintentional deletion activity. If disabled an instance or cluster can be deleted, destroying sensitive or critical information. Adversaries with the proper permissions can take advantage of this to set up future deletion events against a compromised environment.
11"""
12false_positives = [
13 """
14 The deletionProtection feature must be disabled as a prerequisite for deletion of a DB instance or cluster. Ensure that the instance should not be modified in this way before taking action.
15 """,
16]
17from = "now-6m"
18index = ["filebeat-*", "logs-aws.cloudtrail-*"]
19language = "eql"
20license = "Elastic License v2"
21name = "AWS RDS DB Instance or Cluster Deletion Protection Disabled"
22note = """
23## Triage and analysis
24
25### Investigating AWS RDS DB Instance or Cluster Deletion Protection Disabled
26
27This rule identifies when the deletion protection feature is removed from an RDS DB instance or cluster. Removing deletion protection is a prerequisite for deleting a DB instance. Adversaries may exploit this feature to permanently delete data in a compromised environment.
28
29#### Possible Investigation Steps
30
31- **Identify the Actor**: Review the `aws.cloudtrail.user_identity.arn` and `aws.cloudtrail.user_identity.access_key_id` fields to identify who made the change. Verify if this actor typically performs such actions and if they have the necessary permissions.
32- **Review the Modification Event**: Identify the DB instance involved and review the event details. Look for `ModifyDBInstance` actions where the deletionProtection parameter was changed.
33 - **Request and Response Parameters**: Check the `aws.cloudtrail.request_parameters` field in the CloudTrail event to identify the DB instance or cluster identifier and any other modifications made to the instance.
34- **Verify the Modified Instance**: Check the DB instance that was modified and its contents to determine the sensitivity of the data stored within it.
35- **Contextualize with Recent Changes**: Compare this modification event against recent changes in RDS DB instance or cluster configurations and deployments. Look for any other recent permissions changes or unusual administrative actions.
36- **Correlate with Other Activities**: Search for related CloudTrail events before and after this change to see if the same actor or IP address engaged in other potentially suspicious activities.
37- **Interview Relevant Personnel**: If the modification was initiated by a user, verify the intent and authorization for this action with the person or team responsible for managing DB instances.
38### False Positive Analysis
39
40- **Legitimate Instance Modification**: Confirm if the DB instance modification aligns with legitimate tasks.
41- **Consistency Check**: Compare the action against historical data of similar actions performed by the user or within the organization. If the action is consistent with past legitimate activities, it might indicate a false alarm.
42
43### Response and Remediation
44
45- **Immediate Review and Reversal**: If the change was unauthorized, reset deletionProtection to true.
46- **Enhance Monitoring and Alerts**: Adjust monitoring systems to alert on similar actions, especially those involving sensitive data or permissions.
47- **Audit Instances and Policies**: Conduct a comprehensive audit of all instances and associated policies to ensure they adhere to the principle of least privilege.
48- **Policy Update**: Review and possibly update your organization’s policies on DB instance access to tighten control and prevent unauthorized access.
49- **Incident Response**: If malicious intent is confirmed, consider it a data breach incident and initiate the incident response protocol. This includes further investigation, containment, and recovery.
50
51### Additional Information:
52
53For further guidance on managing DB instances and securing AWS environments, refer to the [AWS RDS documentation](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_RDS_Managing.html) and AWS best practices for security. Additionally, consult the following resources for specific details on DB instance security:
54- [AWS RDS ModifyDBInstance](https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_ModifyDBInstance.html)
55- [Deleting AWS RDS DB Instance](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_DeleteInstance.html)
56"""
57references = [
58 "https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_ModifyDBInstance.html",
59 "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_DeleteInstance.html",
60]
61risk_score = 47
62rule_id = "f6652fb5-cd8e-499c-8311-2ce2bb6cac62"
63severity = "medium"
64tags = [
65 "Domain: Cloud",
66 "Data Source: AWS",
67 "Data Source: Amazon Web Services",
68 "Data Source: AWS RDS",
69 "Resources: Investigation Guide",
70 "Use Case: Threat Detection",
71 "Tactic: Impact",
72]
73timestamp_override = "event.ingested"
74type = "eql"
75
76query = '''
77any where event.dataset == "aws.cloudtrail"
78 and event.provider == "rds.amazonaws.com"
79 and event.action in ("ModifyDBInstance", "ModifyDBCluster")
80 and event.outcome == "success"
81 and stringContains(aws.cloudtrail.request_parameters, "deletionProtection=false")
82'''
83
84
85[[rule.threat]]
86framework = "MITRE ATT&CK"
87[[rule.threat.technique]]
88id = "T1485"
89name = "Data Destruction"
90reference = "https://attack.mitre.org/techniques/T1485/"
91
92
93[rule.threat.tactic]
94id = "TA0040"
95name = "Impact"
96reference = "https://attack.mitre.org/tactics/TA0040/"
Triage and analysis
Investigating AWS RDS DB Instance or Cluster Deletion Protection Disabled
This rule identifies when the deletion protection feature is removed from an RDS DB instance or cluster. Removing deletion protection is a prerequisite for deleting a DB instance. Adversaries may exploit this feature to permanently delete data in a compromised environment.
Possible Investigation Steps
- Identify the Actor: Review the
aws.cloudtrail.user_identity.arn
andaws.cloudtrail.user_identity.access_key_id
fields to identify who made the change. Verify if this actor typically performs such actions and if they have the necessary permissions. - Review the Modification Event: Identify the DB instance involved and review the event details. Look for
ModifyDBInstance
actions where the deletionProtection parameter was changed.- Request and Response Parameters: Check the
aws.cloudtrail.request_parameters
field in the CloudTrail event to identify the DB instance or cluster identifier and any other modifications made to the instance.
- Request and Response Parameters: Check the
- Verify the Modified Instance: Check the DB instance that was modified and its contents to determine the sensitivity of the data stored within it.
- Contextualize with Recent Changes: Compare this modification event against recent changes in RDS DB instance or cluster configurations and deployments. Look for any other recent permissions changes or unusual administrative actions.
- Correlate with Other Activities: Search for related CloudTrail events before and after this change to see if the same actor or IP address engaged in other potentially suspicious activities.
- Interview Relevant Personnel: If the modification was initiated by a user, verify the intent and authorization for this action with the person or team responsible for managing DB instances.
False Positive Analysis
- Legitimate Instance Modification: Confirm if the DB instance modification aligns with legitimate tasks.
- Consistency Check: Compare the action against historical data of similar actions performed by the user or within the organization. If the action is consistent with past legitimate activities, it might indicate a false alarm.
Response and Remediation
- Immediate Review and Reversal: If the change was unauthorized, reset deletionProtection to true.
- Enhance Monitoring and Alerts: Adjust monitoring systems to alert on similar actions, especially those involving sensitive data or permissions.
- Audit Instances and Policies: Conduct a comprehensive audit of all instances and associated policies to ensure they adhere to the principle of least privilege.
- Policy Update: Review and possibly update your organization’s policies on DB instance access to tighten control and prevent unauthorized access.
- Incident Response: If malicious intent is confirmed, consider it a data breach incident and initiate the incident response protocol. This includes further investigation, containment, and recovery.
Additional Information:
For further guidance on managing DB instances and securing AWS environments, refer to the AWS RDS documentation and AWS best practices for security. Additionally, consult the following resources for specific details on DB instance security:
References
Related rules
- AWS Deletion of RDS Instance or Cluster
- AWS RDS DB Instance Made Public
- AWS RDS DB Instance or Cluster Password Modified
- AWS RDS DB Snapshot Shared with Another Account
- AWS RDS Instance/Cluster Stoppage