Suspicious activity

CloudTrail trail logging stopped from malicious IP address



Orca detected that an API call to 'StopLogging' CloudTrail events was made from a malicious IP - {MaliciousIp.MaliciousIp}, the operation was successful. Aws CloudTrail service consists of a set of trails, each defines a different logging configuration. By calling the StopLogging api, logging in a specific trail will be disabled. The call from a malicious ip might indicates of an attempt of an attacker to avoid logging.