Analytics BIOC
High
✕
Suspicious API call from a Tor exit node
A cloud API was called from a Tor exit node.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Command and Control (TA0011) Initial Access (TA0001)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003) Valid Accounts: Cloud Accounts (T1078.004)
Detector tags: Kubernetes - API OCI Analytics
Attacker's goals:
Conceal information about malicious activities, such as location and network usage.
Investigative actions:
Block all web traffic to and from public Tor entry and exit nodes.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious Kubernetes API call from a Tor exit node High
- A Failed API call from a Tor exit node Informational (parent: High)