Suspicious activity

Describe EC2 instance API call was made from a malicious IP

Risk Level

Informational (4)

Platform(s)
  • N/A

Description

Orca detected that an API call to list EC2 instances was made from a malicious IP. Listing EC2 instances is a common enumeration action attackers conduct in the reconnaissance phase.
  • Recommended Mitigation

    It is recommended to rotate the exposed aws access key immediately.