Analytics BIOC High

Suspicious API call from a Tor exit node

A cloud API was called from a Tor exit node.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Command and Control (TA0011) Initial Access (TA0001)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003) Valid Accounts: Cloud Accounts (T1078.004)
Detector tags: Kubernetes - API OCI Analytics
Attacker's goals:

Conceal information about malicious activities, such as location and network usage.

Investigative actions:

Block all web traffic to and from public Tor entry and exit nodes.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious Kubernetes API call from a Tor exit node High
  • A Failed API call from a Tor exit node Informational (parent: High)