Anthropic Organization Domain Boundary Changed

edit
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Anthropic Organization Domain Boundary Changed

edit

Verified organization domains control which email addresses can join or be pulled into an Anthropic tenant. Verifying, claiming, adding, or removing a domain changes the tenant boundary and can pull in attacker-controlled mailboxes or push out legitimate corporate domains. These events are infrequent and affect organization-wide membership trust.

Rule type: esql

Rule indices: None

Severity: high

Risk score: 73

Runs every: 5m

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Domain: GenAI
  • Platform: Anthropic
  • Data Source: Anthropic Audit Logs
  • Use Case: Identity and Access Audit
  • Use Case: Threat Detection
  • Resources: Investigation Guide
  • Rule Type: ES|QL
  • Tactic: Persistence

Version: 1

Rule authors:

  • Elastic

Rule license: Elastic License v2

Investigation guide

edit

Triage and analysis

Investigating Anthropic Organization Domain Boundary Changed

Verified domains control which email domains are trusted for membership. Verifying, adding, removing, or claiming a domain changes the tenant boundary (attacker-controlled mailboxes in, or corporate domains out).

Unauthorized = domain not on the corporate allowlist / merger plan, domain_claim_initiated without DNS ownership work, or domain change paired with external invites or SSO changes.

Possible investigation steps

  • Read event.action and anthropic.audit.domain (may be empty on org_domain_add_initiated / domain_claim_initiated — pivot org + nearby domain events to recover the name).
  • Validate actor (email/IP/UA for user_actor) against identity admins.
  • For claims/adds, confirm DNS ownership work was planned. Look for related invites, SSO, or membership changes in the same window.

False positive analysis

  • New Enterprise onboarding routinely verifies corporate domains — match change management.

Response and remediation

  • On unauthorized change: revert via Anthropic administration and review users added under the affected domain.

Rule query

edit
from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action in (
        "org_domain_verified",
        "org_domain_removed",
        "org_domain_add_initiated",
        "domain_claim_initiated"
    )
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*

Framework: MITRE ATT&CKTM