Suspicious activity

RDS instance with CredentialAccess:RDS/AnomalousBehavior.SuccessfulBruteForce GuardDuty Alert Found

Risk Level

Hazardous (3)



A user successfully logged into an RDS database in your account in an anomalous way after a consistent pattern of unusual failed login attempts.
  • Recommended Mitigation

    Place the database in a private VPC to allow traffic only from the necessary sources and revoke the compromised credentials.