Anthropic Organization Data Export Accessed
editAnthropic Organization Data Export Accessed
editStarting an organization data export only signals intent. Accessing the export archive via its signed URL means the actor actually downloaded chats, projects, user metadata, and configuration. An attacker with administrative access can use this to exfiltrate intellectual property and credentials at scale.
Rule type: esql
Rule indices: None
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Threat Detection
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Collection
- Tactic: Exfiltration
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic Organization Data Export Accessed
The export archive was downloaded (not merely requested). Reconstruct lifecycle with org_data_export_started /
org_data_export_completed for the same organization.id.
Unauthorized = no legal/compliance/offboarding ticket, download without a matching started event or outside the approved window, or export preceded by sudden admin grants / key creation / logging disablement.
Possible investigation steps
-
Identify actor (
user_actor→ email/IP/UA) and whether a started/completed export exists for the same org. - Flag downloads lacking a matching start, or occurring far from any approved hold/migration window.
- Correlate with admin role grants, admin API key creation, compliance logging changes, or SSO modifications.
- Determine whether the archive left approved storage or corporate networks (DLP / egress if available).
False positive analysis
- Planned audit or offboarding exports include a download by authorized staff — ticket closes as FP.
Response and remediation
- On unauthorized access: revoke admin for the actor, contain any copies of the archive, and review other admin changes in the same window.
Rule query
editfrom logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "file") and
event.action == "org_data_export_accessed"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Collection
- ID: TA0009
- Reference URL: https://attack.mitre.org/tactics/TA0009/
-
Technique:
- Name: Data from Cloud Storage
- ID: T1530
- Reference URL: https://attack.mitre.org/techniques/T1530/
-
Tactic:
- Name: Exfiltration
- ID: TA0010
- Reference URL: https://attack.mitre.org/tactics/TA0010/
-
Technique:
- Name: Exfiltration Over Web Service
- ID: T1567
- Reference URL: https://attack.mitre.org/techniques/T1567/