IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Anthropic Compliance API Key Created

edit

Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.

Rule type: esql

Rule indices: None

Severity: high

Risk score: 73

Runs every: 5m

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Domain: GenAI
  • Platform: Anthropic
  • Data Source: Anthropic Audit Logs
  • Use Case: Identity and Access Audit
  • Use Case: Threat Detection
  • Resources: Investigation Guide
  • Rule Type: ES|QL
  • Tactic: Persistence

Version: 1

Rule authors:

  • Elastic

Rule license: Elastic License v2

Investigation guide

edit

Triage and analysis

Investigating Anthropic Compliance API Key Created

A new API key was created with compliance read scopes (audit/compliance data), distinct from admin API keys used for org administration. Review anthropic.audit.scopes for exact permissions.

Unauthorized = key not in approved inventory / no Fleet or investigation ticket, or creation by an unexpected actor followed by compliance_api_accessed / audit export activity.

Possible investigation steps

  • Record anthropic.audit.api_key_id and scopes. Branch actor (user_actor vs admin_api_key_actor) and validate against known platform admins or parent admin keys.
  • Pivot on that api_key_id for later compliance_api_accessed (programmatic use of the new key).
  • Correlate ±hours for admin role grants, logging disablement, or data exports — recon before further intrusion.

False positive analysis

  • First Fleet onboarding key for an org is expected — require inventory / ticket evidence.

Response and remediation

  • On unauthorized creation: revoke the key and review Compliance API / export activity during the exposure window.

Rule query

edit
from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    event.action == "api_key_created" and
    event.outcome == "success" and
    anthropic.audit.scopes is not null and
    (
        mv_contains(anthropic.audit.scopes, "read:compliance_activities") or
        mv_contains(anthropic.audit.scopes, "read:compliance_org_data")
    )
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*

Framework: MITRE ATT&CKTM