Suspicious activity

Managed Identity administration activities committed from Tor IP

Platform(s)

Description

Orca detected that an API call to manage user assigned managed identity were made by the principal - {AzurePrincipal} from a Tor IP, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, since the API calls were made from a Tor IP.
  • Recommended Mitigation

    It is recommended to review the user assigned managed identity which was affected.