Suspicious activity

List bucket API call was made from malicious IP address

Risk Level

Informational (4)



Orca detected that an API call to list buckets was made from a Malicious IP address. This action may indicate of a presence of an unauthorized actor in the cloud environment, since listing buckets is a common enumeration action attackers conduct in the reconnaissance phase.
  • Recommended Mitigation

    It is recommended to review the relevant GCP audit logs and the principal's activity that issued this API call.