Anthropic Admin API Key Created
editAnthropic Admin API Key Created
editAdmin API keys grant programmatic access to organization and compliance APIs outside an interactive browser session. An attacker who creates one after compromise can automate role grants, exports, and logging changes without holding a user session that would time out under SSO. The key also survives password resets and IdP lockout if defenders revoke the interactive account but miss the API credential.
Rule type: esql
Rule indices: None
Severity: medium
Risk score: 47
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Identity and Access Audit
- Use Case: Threat Detection
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Persistence
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic Admin API Key Created
Admin API keys provide durable programmatic org/compliance access that survives interactive session revocation. Scopes at creation determine blast radius.
Unauthorized = key not in the approved credentials inventory, no integration/onboarding ticket, or creation by an actor who just received admin / ownership and immediately mints a key — especially before exports or SSO changes.
Possible investigation steps
-
Record
anthropic.audit.admin_api_key_idandanthropic.audit.scopesfor later revoke and correlation. -
Branch actor:
user_actor→ isuser.email/source.ip/ UA a known platform admin? Scripting UA is higher priority than a normal browser admin console session. - Check whether the actor recently gained admin or primary ownership; look ±hours for exports, SSO changes, or compliance logging changes from the same org.
- Close as FP when inventory + ticket match. Escalate when the key is unknown or precedes control-plane abuse.
False positive analysis
- Fleet / SIEM onboarding and scheduled rotation routinely create admin keys — require inventory evidence.
Response and remediation
-
On unauthorized creation: revoke the key in Anthropic admin, rotate other admin credentials, and review API activity
attributable to that
anthropic.audit.admin_api_key_idduring the exposure window.
Rule query
editfrom logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
event.action == "admin_api_key_created"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Persistence
- ID: TA0003
- Reference URL: https://attack.mitre.org/tactics/TA0003/
-
Technique:
- Name: Account Manipulation
- ID: T1098
- Reference URL: https://attack.mitre.org/techniques/T1098/
-
Sub-technique:
- Name: Additional Cloud Credentials
- ID: T1098.001
- Reference URL: https://attack.mitre.org/techniques/T1098/001/