Stop compute instance API call was made from a malicious IP address
Suspicious activity
Stop compute instance API call was made from a malicious IP address
Risk Level
Imminent Compromised (2)
Platform(s)
Description
Orca detected that an API call to stop compute instance was made from a malicious IP address - {MaliciousIp.MaliciousIp}. This action may indicate of a presence of an unauthorized actor in the cloud environment, since stopping compute instance API call was sourced from a malicious IP address - {MaliciousIp.MaliciousIp}.
Recommended Mitigation
It is recommended to review relevant Audit Log event, the compute instance and the principal's activity that issued this API call.