Techniques
Sample rules
Anthropic Compliance API Key Created
- source: elastic
- technicques:
- T1098
Description
Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
event.action == "api_key_created" and
event.outcome == "success" and
anthropic.audit.scopes is not null and
(
mv_contains(anthropic.audit.scopes, "read:compliance_activities") or
mv_contains(anthropic.audit.scopes, "read:compliance_org_data")
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*