Anthropic Compliance API Key Created
editAnthropic Compliance API Key Created
editCompliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.
Rule type: esql
Rule indices: None
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Identity and Access Audit
- Use Case: Threat Detection
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Persistence
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic Compliance API Key Created
A new API key was created with compliance read scopes (audit/compliance data), distinct from admin API keys used for
org administration. Review anthropic.audit.scopes for exact permissions.
Unauthorized = key not in approved inventory / no Fleet or investigation ticket, or creation by an unexpected actor
followed by compliance_api_accessed / audit export activity.
Possible investigation steps
-
Record
anthropic.audit.api_key_idand scopes. Branch actor (user_actorvsadmin_api_key_actor) and validate against known platform admins or parent admin keys. -
Pivot on that
api_key_idfor latercompliance_api_accessed(programmatic use of the new key). - Correlate ±hours for admin role grants, logging disablement, or data exports — recon before further intrusion.
False positive analysis
- First Fleet onboarding key for an org is expected — require inventory / ticket evidence.
Response and remediation
- On unauthorized creation: revoke the key and review Compliance API / export activity during the exposure window.
Rule query
editfrom logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
event.action == "api_key_created" and
event.outcome == "success" and
anthropic.audit.scopes is not null and
(
mv_contains(anthropic.audit.scopes, "read:compliance_activities") or
mv_contains(anthropic.audit.scopes, "read:compliance_org_data")
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Persistence
- ID: TA0003
- Reference URL: https://attack.mitre.org/tactics/TA0003/
-
Technique:
- Name: Account Manipulation
- ID: T1098
- Reference URL: https://attack.mitre.org/techniques/T1098/
-
Sub-technique:
- Name: Additional Cloud Credentials
- ID: T1098.001
- Reference URL: https://attack.mitre.org/techniques/T1098/001/