Anthropic Organization Domain Boundary Changed
editAnthropic Organization Domain Boundary Changed
editVerified organization domains control which email addresses can join or be pulled into an Anthropic tenant. Verifying, claiming, adding, or removing a domain changes the tenant boundary and can pull in attacker-controlled mailboxes or push out legitimate corporate domains. These events are infrequent and affect organization-wide membership trust.
Rule type: esql
Rule indices: None
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: GenAI
- Platform: Anthropic
- Data Source: Anthropic Audit Logs
- Use Case: Identity and Access Audit
- Use Case: Threat Detection
- Resources: Investigation Guide
- Rule Type: ES|QL
- Tactic: Persistence
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Anthropic Organization Domain Boundary Changed
Verified domains control which email domains are trusted for membership. Verifying, adding, removing, or claiming a domain changes the tenant boundary (attacker-controlled mailboxes in, or corporate domains out).
Unauthorized = domain not on the corporate allowlist / merger plan, domain_claim_initiated without DNS ownership
work, or domain change paired with external invites or SSO changes.
Possible investigation steps
-
Read
event.actionandanthropic.audit.domain(may be empty onorg_domain_add_initiated/domain_claim_initiated— pivot org + nearby domain events to recover the name). -
Validate actor (email/IP/UA for
user_actor) against identity admins. - For claims/adds, confirm DNS ownership work was planned. Look for related invites, SSO, or membership changes in the same window.
False positive analysis
- New Enterprise onboarding routinely verifies corporate domains — match change management.
Response and remediation
- On unauthorized change: revert via Anthropic administration and review users added under the affected domain.
Rule query
editfrom logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action in (
"org_domain_verified",
"org_domain_removed",
"org_domain_add_initiated",
"domain_claim_initiated"
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Persistence
- ID: TA0003
- Reference URL: https://attack.mitre.org/tactics/TA0003/
-
Technique:
- Name: Account Manipulation
- ID: T1098
- Reference URL: https://attack.mitre.org/techniques/T1098/