Anomaly detection: Role assumed by external cloud account identity
Suspicious activity
Anomaly detection: Role assumed by external cloud account identity
Risk Level
Informational (4)
Platform(s)
Description
Unlike in the past, the role was assumed by an identity from external cloud account. This action may indicate of a presence of an unauthorized actor in the cloud environment, since this is an unusual activity of the role.
Recommended Mitigation
It is recommended to review relevant CloudTrail event and principal that issued this API call to determine if this is a legit activity.