Unusual IAM Access Key Created — CreateAccessKey API call from anomalous user agent
Investigating… conclusion will appear when complete.
The investigation determined that IAM user 'okami-dev' created a new access key (AKIADEMOKEY123456789) via an anomalous user agent — aws-cli/2.15.33 on Linux/x86_64 from IP 41.203.78.92 (Lagos, NG), which has never been observed for this identity in the last 90 days.
The user's normal activity baseline is interactive Console sign-ins from US business IPs. No additional high-risk API calls were observed in the hour following key creation, but the anomalous provenance combined with the sensitive action warrants escalation and immediate key deactivation.