Techniques
Sample rules
Anthropic Admin Role Assigned to User
- source: elastic
- technicques:
- T1098
Description
The organization admin role controls organization settings, integrations, membership, and security configuration in
Anthropic Claude for Enterprise. Membership role changes are reported as claude_user_role_updated with
anthropic.audit.current_role. An attacker can promote a compromised or newly invited account to org admin to turn
initial access into durable control-plane access. From admin, they can disable SSO, mint admin API keys for
automation, start data exports, and weaken audit logging. Workspace-scoped role_assignment_granted grants (for
example bare admin on a workspace) are out of scope for this rule.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
event.action == "claude_user_role_updated" and
anthropic.audit.current_role == "admin"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*