Virtual machine was created/updated from malicious IP address
Suspicious activity
Virtual machine was created/updated from malicious IP address
Risk Level
Informational (4)
Platform(s)
Description
Orca detected that an API call to create/update virtual machine was made from a malicious IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to establish a persistent mechanism or a malicious code execution capability in the subscription.
Recommended Mitigation
It is recommended to review the permissions which were used to make this api call. In addition, review the image and the virtual machine configurations.