LoFP LoFP / network or security teams remove ip restrictions during office moves, vpn migrations, or policy redesigns. validate the actor, and confirm replacement restrictions were applied if the control is still required.

Techniques

Sample rules

Anthropic Organization IP Restriction Deleted

Description

Organization IP restrictions limit Anthropic administrative access to approved network ranges. Deleting one widens where a compromised admin session or API key can be used. The audit event does not always carry the deleted CIDR or restriction identifier, so treat this as an early signal and pivot to nearby IP restriction create or update events for the same organization.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "org_ip_restriction_deleted"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*