LoFP LoFP / security and compliance teams download audit log exports for investigations, regulatory requests, or siem validation. validate the actor and confirm the activity matches an approved ticket.

Techniques

Sample rules

Anthropic Compliance Audit Log Export Accessed

Description

An audit log export archive was accessed, meaning the actor downloaded exported audit activity. Attackers pull audit exports to see what defenders can observe, look for detection gaps, or remove evidence before making other control-plane changes.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "file") and
    event.action == "audit_log_export_accessed"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*