Techniques
Sample rules
Anthropic Organization Member and Group Enumeration
- source: elastic
- technicques:
- T1069
- T1087
Description
Detects a single user performing at least two distinct organization discovery actions within a 10-minute window: listing users, exporting members, or viewing groups. Chaining these read actions maps membership and group structure and commonly precedes targeted role grants, invites, or data collection against high-value accounts.
Detection logic
from logs-anthropic.audit-*
| where
data_stream.dataset == "anthropic.audit" and
event.action in ("org_members_exported", "org_users_listed", "group_list_viewed") and
user.email is not null
| stats
Esql.event_action_count_distinct = count_distinct(event.action),
Esql.event_action_values = values(event.action),
Esql.event_count = count(*),
Esql.event_id_values = values(event.id),
Esql.source_ip_values = values(source.ip),
Esql.user_agent_original_values = values(user_agent.original),
Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
Esql.user_id_values = values(user.id),
Esql.timestamp_first_seen = min(@timestamp),
Esql.timestamp_last_seen = max(@timestamp)
by user.email, organization.id
| where Esql.event_action_count_distinct >= 2
| keep user.email, organization.id, Esql.*