Techniques
Sample rules
Anthropic Artifact Shared Publicly
- source: elastic
- technicques:
- T1567
Description
Claude artifacts can be shared with specific audiences. Making an artifact public exposes its contents to unauthenticated viewers on the internet. An attacker with access to sensitive artifacts can publish them publicly to push intellectual property, credentials embedded in prompts, or other confidential material outside organizational controls.
Detection logic
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "claude_artifact_sharing_updated"
| eval Esql.audience_types = FIELD_EXTRACT(anthropic.audit.audience, "type")
| where Esql.audience_types is not null and mv_contains(Esql.audience_types, "anyone_with_link")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*, Esql.audience_types