LoFP LoFP / organization administrators, identity teams, and compliance reviewers may list users, export members, and view groups during audits, access reviews, or offboarding. confirm the actor and change ticket before escalating.

Techniques

Sample rules

Anthropic Organization Member and Group Enumeration

Description

Detects a single user performing at least two distinct organization discovery actions within a 10-minute window: listing users, exporting members, or viewing groups. Chaining these read actions maps membership and group structure and commonly precedes targeted role grants, invites, or data collection against high-value accounts.

Detection logic

from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    event.action in ("org_members_exported", "org_users_listed", "group_list_viewed") and
    user.email is not null
| stats
    Esql.event_action_count_distinct = count_distinct(event.action),
    Esql.event_action_values = values(event.action),
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.source_ip_values = values(source.ip),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.user_id_values = values(user.id),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.email, organization.id
| where Esql.event_action_count_distinct >= 2
| keep user.email, organization.id, Esql.*