Suspicious activity

Virtual machine run command was triggered from Tor IP address

Risk Level

Informational (4)



Orca detected that an API call to start virtual machine was made from a Tor IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to execute commands on virtual machines.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, it is recommended to review which commands were executed using the run command feature.