LoFP LoFP / platform or security administrators disable compliance logging during onboarding, integration testing, or log pipeline migrations. verify the actor, source ip, and whether logging was re-enabled promptly. planned changes can be exempted from this rule.

Techniques

Sample rules

Anthropic Compliance API Logging Disabled

Description

Compliance API logging feeds the anthropic.audit dataset that Anthropic audit detections run on. An attacker with administrative access can disable it so later role grants, API key creation, exports, and authentication changes stop reaching this data source. This rule detects the disable action itself. Activity that happens after logging stops may not appear in logs-anthropic.audit-*.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "org_compliance_api_settings_updated" and
    anthropic.audit.compliance_api_logging_enabled == false
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*