Suspicious activity

Service account key was created from Tor IP address

Risk Level

Imminent Compromised (2)

Platform(s)

Description

Orca detected that an API call to create service account key was made from a Tor IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to establish a persistence mechanism in the cloud account.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, review the actions of the service account.