LoFP LoFP / platform, security, and observability teams create admin api keys during integration setup or scheduled key rotation. verify the actor, `anthropic.audit.scopes`, and whether the creation matches an approved change.

Techniques

Sample rules

Anthropic Admin API Key Created

Description

Admin API keys grant programmatic access to organization and compliance APIs outside an interactive browser session. An attacker who creates one after compromise can automate role grants, exports, and logging changes without holding a user session that would time out under SSO. The key also survives password resets and IdP lockout if defenders revoke the interactive account but miss the API credential.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "iam") and
    event.action == "admin_api_key_created"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*