Suspicious activity

Anomaly detection: Permissive role accessed unusual services

Risk Level

Informational (4)



Unlike in the past, a role that was assumed by another account started executing API calls. in addition there were unusual services accessed in the cloud account. The role was identified by Orca as a permissive role, which in case of compromise can put the cloud account at a higher risk. Therefor those findings might indicate on a malicious usage of the role permissions.
  • Recommended Mitigation

    It is recommended to review the relevant CloudTrail events and principals that issued this API calls.