Anomaly detection: Permissive role increased activity
Suspicious activity
Anomaly detection: Permissive role increased activity
Risk Level
Hazardous (3)
Platform(s)
Description
A suspicious rise in the overall activity of the role. In addition, there was an anomaly in source user-agent. The role was identified by Orca as a permissive role. Those findings might indicate on a malicious usage of the role permissions.
Recommended Mitigation
It is recommended to review relevant CloudTrail events and principals that issued this API calls. In addition, the change in the user-agent field might help to understand the cause of the anomaly.