Suspicious activity

Anomaly detection: Service Principal uses new external subscription

Platform(s)

Description

Service principals can execute API on resources outside of their subscription. If a service principal started executing multiple API calls from subscriptions that weren't seen before it may indicate a presence of an unauthorized actor in the cloud environment since this kind of activity is seen mostly when attackers conduct reconnaissance actions in order to map the internal environment and spread inside the environment. It was detected that the service principal {AzureServicePrincipal} has executed multiple API calls to subscriptions that weren't seen before.