Suspicious activity

Service account key was deleted from malicious IP address

Risk Level

Informational (4)

Platform(s)
  • N/A

Description

Orca detected that an API call to delete service account key was made from a malicious IP address, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to clean the persistence mechanism in the cloud account.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, review the actions of the service account.