Spaces:
Running
Running
Funny interactions: sent an email directly to a the company employee who was using Kali linux
#6
by
pedrobento988
- opened
๐: Handle ticket:
Finding ID: asdasdas
Finding Type: PenTest:IAMUser/KaliLinux
Finding Description: The API DescribeTargetGroups was invoked from a remote host with IP address 131.61.204.178 that is potentially running the Kali Linux penetration testing tool.
Updated At: 2025-06-04T04:10:14.297Z
Account ID: 123456789012
Action Type: AWS_API_CALL
Severity: Medium
Principal ID: KBUIBIFNIIBUBI232:jsmith
User Name: jsmith
API Call: DescribeTargetGroups
Port: N/A
IP Address: 131.61.204.178
Region: eu-west-1
๐ค: I've sent an email to John Smith requesting more information about this activity. Once we receive his response, we can further assess the situation and determine if additional actions are necessary.