LoFP LoFP / a user repeatedly clicking an expired or invalid magic link from the same browser session can produce several failures before requesting a new link or signing in successfully.

Techniques

Sample rules

Anthropic Multiple Authentication Failures

Description

Detects at least five failed Anthropic authentication events for the same user email within one hour. Failures are matched by authentication category and failure outcome (for example magic-link or SSO login failures). That pattern fits repeated guessing, stale magic link abuse, or automated login attempts against one account.

Detection logic

from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "authentication") and
    event.outcome == "failure" and
    user.email is not null
| stats
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.event_action_values = values(event.action),
    Esql.source_ip_values = values(source.ip),
    Esql.source_ip_distinct_count = count_distinct(source.ip),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.email
| where Esql.event_count >= 5
| keep user.email, Esql.*