LoFP LoFP / users browsing many stale or revoked shared chat links during incident response or legal review can produce bursts of access failures. confirm whether the activity matches an approved investigation before escalating.

Techniques

Sample rules

Anthropic Excessive Chat Access Failures

Description

Detects a single authenticated user generating an unusually high number of denied Claude chat access attempts in a 24-hour window. That pattern fits automated chat enumeration or attempts to reach conversations outside the actor’s permissions. Unauthenticated shared-link actors lack user.id and are excluded.

Detection logic

from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    event.action == "claude_chat_access_failed" and
    user.id is not null
| stats
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.anthropic_audit_claude_chat_id_values = values(anthropic.audit.claude_chat_id),
    Esql.anthropic_audit_claude_project_id_values = values(anthropic.audit.claude_project_id),
    Esql.source_ip_values = values(source.ip),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.user_email_values = values(user.email),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.id, organization.id, source.ip
| where Esql.event_count >= 20
| keep user.id, organization.id, source.ip, Esql.*