Suspicious activity

Storage account was created/updated from tor IP address

Risk Level

Informational (4)

Platform(s)

Description

Orca detected that an API call to create/update storage account was made from a tor IP address, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to establish an exfiltration mechanism in the subscription.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, review the access permissions of the storage account.