Suspicious activity

Anomaly detection: user tried accessing resources that don’t exist

Platform(s)

Description

User tries to call API for resources that don't exist. If a user started executing multiple API calls that return not found error unlike before it may indicate a presence of an unauthorized actor in the cloud environment since this kind of activity is seen mostly when attackers conduct reconnaissance actions in order to map the internal environment and spread inside the environment. It was detected that user {AzureUser} got more not found errors than before, which might be suspicious.
  • Recommended Mitigation

    It is recommended to review relevant ActivityLog event that issued this API call to determine if this is a legit activity.