Techniques
Sample rules
Anthropic Organization IP Restriction Deleted
- source: elastic
- technicques:
- T1562
Description
Organization IP restrictions limit Anthropic administrative access to approved network ranges. Deleting one widens where a compromised admin session or API key can be used. The audit event does not always carry the deleted CIDR or restriction identifier, so treat this as an early signal and pivot to nearby IP restriction create or update events for the same organization.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "org_ip_restriction_deleted"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*