Suspicious activity

Anomaly detection: Unusual service principal access from cli



Service principal can execute API through console/CLI. If a service principal started executing multiple API calls from CLI unlike before it may indicate a presence of an unauthorized actor in the cloud environment since this kind of activity is seen mostly when attackers conduct reconnaissance actions in order to map the internal environment and spread inside the environment. It was detected that service principal {AzureServicePrincipal} executed increasing number of APIs from CLI unlike before.