Suspicious activity

Service account key was created from a compute engine service account

Platform(s)
  • N/A

Description

Orca detected that an API call to create service account key was made from a compute engine service account, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment trying to establish a persistence mechanism in the cloud account, since this kind of action is not usually performed from internal service account.