Description
Orca detected that an API call to list EC2 instances was made from Tor IP address - {MaliciousIp.MaliciousIp}. This action may indicate of a presence of an unauthorized actor in the cloud environment, since listing EC2 instances is a common enumeration action attackers conduct in the reconnaissance phase.