LoFP LoFP / platform and security teams create compliance-scoped api keys when onboarding the anthropic fleet integration or setting up siem ingestion. verify the actor and confirm the key is in the approved credentials inventory.

Techniques

Sample rules

Anthropic Compliance API Key Created

Description

Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    event.action == "api_key_created" and
    event.outcome == "success" and
    anthropic.audit.scopes is not null and
    (
        mv_contains(anthropic.audit.scopes, "read:compliance_activities") or
        mv_contains(anthropic.audit.scopes, "read:compliance_org_data")
    )
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*