Suspicious activity

Compute instance list API call was made from a Tor IP address

Risk Level

Informational (4)

Platform(s)
  • N/A

Description

Orca detected that an API call to list compute instances was made from a Tor IP address. This action may indicate of a presence of an unauthorized actor in the cloud environment, since listing compute instances is a common enumeration action attackers conduct in the reconnaissance phase.
  • Recommended Mitigation

    It is recommended to review relevant Audit Log event and principal's activity that issued this API call.