IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Anthropic Excessive Chat Access Failures

edit

Detects a single authenticated user generating an unusually high number of denied Claude chat access attempts in a 24-hour window. That pattern fits automated chat enumeration or attempts to reach conversations outside the actor’s permissions. Unauthenticated shared-link actors lack user.id and are excluded.

Rule type: esql

Rule indices: None

Severity: medium

Risk score: 47

Runs every: 1h

Searches indices from: now-24h (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Domain: GenAI
  • Platform: Anthropic
  • Data Source: Anthropic Audit Logs
  • Use Case: Threat Detection
  • Use Case: UEBA
  • Resources: Investigation Guide
  • Rule Type: ES|QL
  • Tactic: Discovery

Version: 1

Rule authors:

  • Elastic

Rule license: Elastic License v2

Investigation guide

edit

Triage and analysis

Investigating Anthropic Excessive Chat Access Failures

Alert keys: user.id, organization.id, and source.ip (plus user.email when present). The rule aggregates ≥20 claude_chat_access_failed events for one authenticated user in that org/IP over 24 hours. Unauthenticated shared-link failures lack user.id and are out of scope.

True positive: high failure-to-claude_chat_viewed ratio, sequential/patterned chat IDs, scripting UA. False positive: legal/IR link review or broken bookmarks with scattered IDs and many successful views nearby.

Possible investigation steps

  • Start from the alert keys (user.id / organization.id / source.ip) and the time window; pivot raw claude_chat_access_failed events.
  • Review chat ID lists: sequential or patterned IDs suggest enumeration; scattered IDs fit shared-link browsing.
  • Compare failure volume to claude_chat_viewed from the same actor. High failure-to-success ratio → enumeration.
  • Check UA/automation signals and whether any failed chat IDs later succeed. Correlate with IAM/SSO/compliance key changes in the same period.

False positive analysis

  • Large revoked-link reviews and retrying expired URLs are FP when IDs are scattered and many claude_chat_viewed successes sit nearby (legal/IR ticket optional corroboration).

Response and remediation

  • On confirmed enumeration: revoke sessions, review recently accessed chats, rotate exposed shared links if needed, and check for data export or artifact sharing by the same user.

Rule query

edit
from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    event.action == "claude_chat_access_failed" and
    user.id is not null
| stats
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.anthropic_audit_claude_chat_id_values = values(anthropic.audit.claude_chat_id),
    Esql.anthropic_audit_claude_project_id_values = values(anthropic.audit.claude_project_id),
    Esql.source_ip_values = values(source.ip),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.user_email_values = values(user.email),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.id, organization.id, source.ip
| where Esql.event_count >= 20
| keep user.id, organization.id, source.ip, Esql.*

Framework: MITRE ATT&CKTM