LoFP LoFP / users publish artifacts intentionally for demos, documentation, or external collaboration. validate the artifact, actor, and business justification before escalating.

Techniques

Sample rules

Anthropic Artifact Shared Publicly

Description

Claude artifacts can be shared with specific audiences. Making an artifact public exposes its contents to unauthenticated viewers on the internet. An attacker with access to sensitive artifacts can publish them publicly to push intellectual property, credentials embedded in prompts, or other confidential material outside organizational controls.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "claude_artifact_sharing_updated"
| eval Esql.audience_types = FIELD_EXTRACT(anthropic.audit.audience, "type")
| where Esql.audience_types is not null and mv_contains(Esql.audience_types, "anyone_with_link")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*, Esql.audience_types