Description
Users in the account can execute API calls. If a user started executing multiple API calls which result in access denied it may indicate a presence of an unauthorized actor in the cloud environment since this kind of activity is seen mostly when attackers conduct reconnaissance actions in order to map the internal environment and spread inside the environment. It was detected that the user {AzureUser} has executed multiple API calls that resulted in access denied