Analytics BIOC High

Suspicious SaaS API call from a Tor exit node

A SaaS API was called from a Tor exit node.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003)
Attacker's goals:

Conceal information about malicious activities, such as location and network usage.

Investigative actions:

Block all web traffic to and from public Tor entry and exit nodes.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A Failed API call from a Tor exit node Informational (parent: High)
  • Suspicious SaaS API call from a Tor exit node via Mobile Device Medium (parent: High)