Suspicious activity

List S3 object API call was made from Tor IP address

Risk Level

Hazardous (3)

Platform(s)
  • N/A

Description

Orca detected that a ListObjects operation attempt. The operation was called from a tor IP address, which might indicate of an asset reconnaissance attempt. An attacker with permissions to list objects, can gain information about entities.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call.