IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Anthropic Organization User Invite Sent

edit

Sending an organization user invite creates a path for a new member to join the Anthropic tenant with a chosen role. An adversary who compromises an administrator or admin API key can invite a mailbox they control and accept the invite to gain durable access. Invites may target internal corporate addresses or external domains; this rule does not distinguish them because invite events do not carry verified organization domains for reliable comparison.

Rule type: esql

Rule indices: None

Severity: medium

Risk score: 47

Runs every: 5m

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Domain: GenAI
  • Platform: Anthropic
  • Data Source: Anthropic Audit Logs
  • Use Case: Identity and Access Audit
  • Use Case: Threat Detection
  • Resources: Investigation Guide
  • Rule Type: ES|QL
  • Tactic: Persistence

Version: 1

Rule authors:

  • Elastic

Rule license: Elastic License v2

Investigation guide

edit

Triage and analysis

Investigating Anthropic Organization User Invite Sent

A successful org_user_invite_sent creates a path for a new member. Invitee is user.target.email (also related.user); role on accept is anthropic.audit.invited_role when present. Audit events do not include the org’s verified domain list — domain judgment is triage’s job.

Unauthorized / high priority: invitee domain outside known corporate domains, invited_role of admin (or similarly privileged), actor is unexpected / API key, or invite followed by accept + privileged activity. Close as FP when HR/IT ticket names the invitee and role.

Possible investigation steps

  • Compare invitee domain to trusted corporate domains; treat unexpected external domains as higher priority.
  • Branch actor: user_actor (email/IP/UA) vs admin_api_key_actor (anthropic.audit.actor.admin_api_key_id in inventory?).
  • Search for org_user_invite_accepted for the same anthropic.audit.invite_id or invitee email.
  • Look nearby for role grants, SSO changes, or admin API key creation from the same actor.

False positive analysis

  • Routine onboarding invites are FP when an HR/IT ticket names the invitee domain and invited_role.

Response and remediation

  • On unauthorized invite: delete/revoke the pending invite (and remove the user if already accepted), review other IAM changes by the same actor, and rotate compromised admin credentials or API keys.

Rule query

edit
from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "iam") and
    event.action == "org_user_invite_sent" and
    event.outcome == "success"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, related.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*

Framework: MITRE ATT&CKTM