heroui logo

Anthropic Artifact Shared Publicly

Elastic Detection Rules

View Source
Summary
Detects when Claude (Anthropic) artifacts are shared with a public audience (anyone_with_link) using Anthropic Audit Logs. The rule scans for artifact sharing updates (anthropic.audit) where the audience includes anyone_with_link, indicating potential exfiltration or leakage of credentials, customer data, or proprietary material to the internet. It maps to MITRE ATT&CK technique T1567 (Exfiltration Over Web Service) under the Exfiltration tactic (TA0010). Investigations typically verify the audience type, inspect the artifact content and any embedded secrets, check for related chat access failures or data exports by the same actor, and correlate with other activity in the same window. False positives include DevRel/training or demos where non-sensitive content is shared with a marketing/training justification. Remediation involves revoking public sharing, inventorying related artifacts modified by the same actor, and treating any embedded secrets as compromised.
Categories
  • Cloud
Data Sources
  • Cloud Service
ATT&CK Techniques
  • T1567
Created: 2026-09-12