Anonymous IP address involving Apple iCloud Private Relay - Cloudbrothers
Since a few weeks I recognized an uptick in Entra ID Protection alerts regarding “Anonymous IP address” detections. Normally this is a high-fidelity indicator that someone is using a Tor browser or some other method to cover their tracks. While this behavior is totally fine in a private setting, in enterprise IT the use of such anonymizers is not considered baseline behavior. While analyzing the related alerts for common patterns I stumbled upon the IP address information. Most of those sign-ins are from IPv6 addresses that are hosted in e.g. Cloudflare datacenters. While the IP address information in Sentinel is not wrong, using a third-party source for IP address enrichment the culprit of those alerts was found fast. Apple iCloud Private Relay. If you don’t know what the Apple iCloud Private Relay service is the About website of Apple gives a good description. iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party
Anonymous IP address involving Apple iCloud Private Relay Fabian Bader included in ARM Automation Azure Entra ID KQL Logic Apps Sentinel SOAR Security 2024-02-04 1126 words 6 minutes Contents Since a few weeks I recognized an uptick in Entra ID Protection alerts regarding "Anonymous IP address" detections. Normally this is a high-fidelity indicator that someone is using a Tor browser or some other method to cover their tracks. While this behavior is totally fine in a private setting, in enterprise IT the use of such anonymizers is not considered baseline behavior. While analyzing the related a
Explore this link on the map →related reading
- Private Cloud Compute: A new frontier for AI privacy in the cloud - Apple Security Researchsecurity.apple.com
- Security incident disclosure — July 2026huggingface.co
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Spur Docsdocs.spur.us
- iMessage, explained - JJTechjjtech.dev
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Apple iOS privacy clampdown 'did little' to reduce trackingtheregister.com
- AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Bloglantian.pub
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- GitHub - open-edge-platform/anomalib: An anomaly detection library comprising state-of-the-art algorithms and features such as experiment management, hyper-parameter optimization, and edge inference. · GitHubgithub.com