Analytics BIOC
High
✕
Suspicious SaaS API call from a Tor exit node
A SaaS API was called from a Tor exit node.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003)
Attacker's goals:
Conceal information about malicious activities, such as location and network usage.
Investigative actions:
Block all web traffic to and from public Tor entry and exit nodes.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- A Failed API call from a Tor exit node Informational (parent: High)
- Suspicious SaaS API call from a Tor exit node via Mobile Device Medium (parent: High)