Service account key was deleted from malicious IP address
Suspicious activity
Service account key was deleted from malicious IP address
Risk Level
Imminent Compromised (2)
Platform(s)
Description
Orca detected that an API call to delete service account key was made from a malicious IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to clean the persistence mechanism in the cloud account.
Recommended Mitigation
It is recommended to review the permissions which were used to make this api call. In addition, review the actions of the service account.