Suspicious activity

User managed policy attached from malicious IP address



Orca detected that a managed policy was attached to a user, the operation was successful. The operation was called from a malicious IP address - {MaliciousIp.MaliciousIp}, which might indicate of a privilege escalation attempt. An attacker with permissions to attach policies, can attach a policy to entities which are in his control.