Suspicious activity

Anomaly detection: Role executed multiple API calls in ‘Dry-Run’ mode

Risk Level

Hazardous (3)



Unlike in the past, the role has started executing multiple API calls in 'Dry-Run' mode. This action may indicate a presence of an unauthorized actor in the cloud environment, since this kind of activity is seen mostly when attackers are checking their permissions before execution, so they can avoid generating requests that result in access denied.
  • Recommended Mitigation

    It is recommended to review relevant CloudTrail event and principal that issued this API call to determine if this is a legit activity.