Description
Orca detected that an API call to list S3 buckets was made from a Tor IP - {MaliciousIp.MaliciousIp}. This action may indicate of a presence of an unauthorized actor in the cloud environment, since listing S3 buckets is a common enumeration action attackers conduct in the reconnaissance phase.