Suspicious activity

Anomaly detection: Service account executing API calls with unusual user agent

Risk Level

Hazardous (3)

Platform(s)

Description

Unlike in the past, the service acccount executed API calls with user-agent not seen before. This action may indicate of a presence of an unauthorized actor in the cloud environment, since this is an unusual activity of the role.
  • Recommended Mitigation

    It is recommended to review relevant AuditLog event and principal that issued this API call to determine if this is a legit activity.