Techniques
Sample rules
Anthropic Magic Link Second Factor Disabled
- source: elastic
- technicques:
- T1556
Description
Magic link second factor adds an extra authentication step to passwordless sign-in for Anthropic. An attacker with administrative access can turn it off so magic link logins no longer require the second factor, which makes stolen or attacker-controlled mailboxes usable for interactive access. This often shows up alongside SSO weakening when the attacker wants a fallback authentication path outside the corporate IdP.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "org_magic_link_second_factor_toggled" and
anthropic.audit.enabled == false
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*