Identifies when an attempt was made to restore an RDS Snapshot. Snapshots are sometimes shared by threat actors in order to exfiltrate bulk data. If the permissions were modified, verify if the snapshot was shared with an unauthorized or unexpected AWS account.
Rule type: query
Risk score: 47
Runs every: 5m
Maximum alerts per execution: 100
- Continuous Monitoring
- Asset Visibility
- Austin Songer
Rule license: Elastic License v2
## Config The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule.