Suspicious activity

AWS root account was used to create EC2 instance



Orca detected that the root account was used to create EC2 instance. This action may indicate of a presence of an unauthorized actor in the cloud environment, since new EC2 instances usually are not created from the root account profile. In case this is a legit action then the root account should not be used in day to day administrative tasks because it can't be deleted and its permissions can't be revoked. If its credentials will be stolen the entire account is at risk.