Suspicious activity

Anomaly detection: Role executed multiple API calls which resulted in access denied

Risk Level

Hazardous (3)

Platform(s)

Description

Unlike in the past, the role has started executing multiple API calls which results in access denied. This action may indicate of a presence of an unauthorized actor in the cloud environment, since this kind of activity is seen mostly when attackers conducting reconnaissance actions in order to map the internal environment and spread inside the environment.
  • Recommended Mitigation

    It is recommended to review relevant CloudTrail event and principal that issued this API call to determine if this is a legit activity.