Anomaly detection: Role executing API calls with unusual user agent
Suspicious activity
Anomaly detection: Role executing API calls with unusual user agent
Risk Level
Hazardous (3)
Platform(s)
Description
Unlike in the past, the role executed API calls with user-agent not seen before. This action may indicate of a presence of an unauthorized actor in the cloud environment, since this is an unusual activity of the role.
Recommended Mitigation
It is recommended to review relevant CloudTrail event and principal that issued this API call to determine if this is a legit activity.