Suspicious activity

Run EC2 instance API call was made from Tor IP address

Risk Level

Hazardous (3)

Platform(s)
  • N/A

Description

Orca detected that an API call to create EC2 instances was made from Tor IP address. This action may indicate of a presence of an unauthorized actor in the cloud environment, since creating EC2 instances API call was sourced from Tor IP address
  • Recommended Mitigation

    It is recommended to review relevant CloudTrail event, the EC2 instances and the principal's activity that issued this API call.