Oct. 16, 2023, 3:15 p.m. | /u/whatthe12234

cybersecurity www.reddit.com

We’re seeing an uptick in alerts in our SIEM tool for anonymous IP addresses. They’re supposed to be blocked by policy, but we’re getting alerts of successful sign in with anonymous IP’s.

Upon investigation, it’s been determined that these IPs are related to the iCloud Private Relay.

Is anyone else seeing these alerts in their SIEM tool? If so, what steps did you take in modifying the policy to prevent the creation of the alert?

addresses alerts anonymous apple apple icloud blocked cybersecurity icloud icloud private relay investigation ip addresses ips policy private private relay relay security security alerts siem sign tool

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)