Anonymous IP address involving Apple iCloud Private Relay - Cloudbrothers
Since a few weeks I recognized an uptick in Entra ID Protection alerts regarding “Anonymous IP address” detections. Normally this is a high-fidelity indicator that someone is using a Tor browser or some other method to cover their tracks. While this behavior is totally fine in a private setting, in enterprise IT the use of such anonymizers is not considered baseline behavior. While analyzing the related alerts for common patterns I stumbled upon the IP address information. Most of those sign-ins are from IPv6 addresses that are hosted in e.g. Cloudflare datacenters. While the IP address information in Sentinel is not wrong, using a third-party source for IP address enrichment the culprit of those alerts was found fast. Apple iCloud Private Relay. If you don’t know what the Apple iCloud Private Relay service is the About website of Apple gives a good description. iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party
Anonymous IP address involving Apple iCloud Private Relay Fabian Bader included in ARM Automation Azure Entra ID KQL Logic Apps Sentinel SOAR Security 2024-02-04 1126 words 6 minutes Contents Since a few weeks I recognized an uptick in Entra ID Protection alerts regarding "Anonymous IP address" detections. Normally this is a high-fidelity indicator that someone is using a Tor browser or some other method to cover their tracks. While this behavior is totally fine in a private setting, in enterprise IT the use of such anonymizers is not considered baseline behavior. While analyzing the related a
related reading
- Private Cloud Compute: A new frontier for AI privacy in the cloud - Apple Security Researchsecurity.apple.com
- Security incident disclosure — July 2026huggingface.co
- iMessage, explained - JJTechjjtech.dev
- Spur Docsdocs.spur.us
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Bloglantian.pub
- Apple delays plans to roll out CSAM detection in iOS 15 after privacy backlashtechcrunch.com
- Cloud Email Security - Block Malicious Email Attacks | Abnormal AIabnormal.ai
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Apple iOS privacy clampdown 'did little' to reduce trackingtheregister.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- iOS_Security_Guide_v39_FFapple.com