Techniques
Sample rules
Anthropic Sensitive Claude Project Role Assigned to User
- source: elastic
- technicques:
- T1098
Description
Detects when a Claude project owner or editor role is granted through a role_assignment_granted event. Project owners
and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with
organization access can grant these roles to persist access to high-value project content without holding organization
admin privileges.
Detection logic
data_stream.dataset: "anthropic.audit" and
event.category: "iam" and
event.action: "role_assignment_granted" and
user.target.roles: ("chat_project:owner" or "chat_project:editor")