Suspicious activity

Insert compute instance API call was made from a Tor IP address

Risk Level

Imminent Compromised (2)

Platform(s)

Description

Orca detected that an API call to create compute instance was made from a Tor IP address - {MaliciousIp.MaliciousIp}. This action may indicate of a presence of an unauthorized actor in the cloud environment, since creating the new compute instance API call was sourced from a malicious IP address - {MaliciousIp.MaliciousIp}.
  • Recommended Mitigation

    It is recommended to review relevant Audit Log event, the compute instance and the principal's activity that issued this API call.