LoFP LoFP / platform and security teams delete admin api keys during scheduled rotation or decommissioning. check for a nearby `admin_api_key_created` event or an approved change ticket to explain the deletion.

Techniques

Sample rules

Anthropic Admin API Key Deleted

Description

Admin API keys grant programmatic access to organization and compliance APIs. An attacker can delete legitimate admin API keys to break security monitoring or integrations, or to cover tracks after creating replacement credentials they control. Deletion without a nearby rotation event points more at sabotage than routine key hygiene.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "iam") and
    event.action == "admin_api_key_deleted"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*