Suspicious activity

Anomaly detection: Role assumed by external cloud account identity

Risk Level

Informational (4)



Unlike in the past, the role was assumed by an identity from external cloud account. This action may indicate of a presence of an unauthorized actor in the cloud environment, since this is an unusual activity of the role.
  • Recommended Mitigation

    It is recommended to review relevant CloudTrail event and principal that issued this API call to determine if this is a legit activity.