Anthropic Multiple Authentication Failures
editAnthropic Multiple Authentication Failures
editDetects at least five failed Anthropic authentication events for the same user email within one hour. Failures are matched by authentication category and failure outcome (for example magic-link or SSO login failures). That pattern fits repeated guessing, stale magic link abuse, or automated login attempts against one account.
Rule type: esql
Rule indices: None
Severity: medium
Risk score: 47
Runs every: 15m
Searches indices from: now-60m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Domain: Identity
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Identity and Access Audit
- Use Case: Threat Detection
- Use Case: UEBA
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Credential Access
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic Multiple Authentication Failures
One mailbox produced a burst of authentication failures (magic-link, SSO, or other auth failures) within an hour. Use IP diversity on the alert to separate focused retries from distributed automation.
Escalate when many distinct IPs hit one email, failures precede a successful login from an unfamiliar IP, or SSO / magic-link second-factor weakening sits nearby. Close as FP for expired magic-link retries from one IP/UA or IdP pilot testing with a ticket.
Possible investigation steps
-
Read
Esql.event_count,Esql.event_action_values,Esql.source_ip_values, andEsql.source_ip_distinct_count. - Low IP diversity → one device/egress (typos, expired links, focused guessing). High diversity → distributed automation or proxy rotation — higher priority.
-
Inspect UA / actor-type values for automation. Search for successful
magic_link_login_succeeded/sso_login_succeededfor the same email or IPs in the window. - Correlate with Anthropic SSO Disabled or Connection Removed or magic-link second-factor disablement when org-scoped admin events are present.
False positive analysis
- Expired magic-link click storms from one IP and named IdP cutover tests are common FPs.
Response and remediation
- On suspected stuffing/takeover: invalidate sessions, reset credentials/MFA, and review successful logins from new IPs. If failures precede a successful unfamiliar login, expand to data access and admin changes.
Rule query
editfrom logs-anthropic.audit-*
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "authentication") and
event.outcome == "failure" and
user.email is not null
| stats
Esql.event_count = count(*),
Esql.event_id_values = values(event.id),
Esql.event_action_values = values(event.action),
Esql.source_ip_values = values(source.ip),
Esql.source_ip_distinct_count = count_distinct(source.ip),
Esql.user_agent_original_values = values(user_agent.original),
Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
Esql.timestamp_first_seen = min(@timestamp),
Esql.timestamp_last_seen = max(@timestamp)
by user.email
| where Esql.event_count >= 5
| keep user.email, Esql.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Credential Access
- ID: TA0006
- Reference URL: https://attack.mitre.org/tactics/TA0006/
-
Technique:
- Name: Brute Force
- ID: T1110
- Reference URL: https://attack.mitre.org/techniques/T1110/