heroui logo

Anthropic Organization Member and Group Enumeration

Elastic Detection Rules

View Source
Summary
Detects when a single user performs at least two distinct Anthropic organization discovery actions within a 10-minute window, specifically org_users_listed, org_members_exported, or group_list_viewed in Anthropic audit logs. The rule aggregates by user and organization, counting distinct actions and total events, and raises an alert when two or more actions occur within 10 minutes, indicating potential reconnaissance of tenant membership and group structure that commonly precedes role grants, invites, or data collection. The alert is mapped to MITRE ATT&CK Discovery techniques (T1069 Cloud Groups and T1087 Cloud Account) under TA0007. It includes suppression by user and organization to reduce noise, and provides investigation fields for rapid triage. The rule includes triage guidance, investigation steps, false positives notes related to audits or access reviews, and remediation suggestions such as revoking sessions and tightening least-privilege on identity read actions. References include the Anthropic API compliance activities documentation.
Categories
  • Cloud
Data Sources
  • Application Log
ATT&CK Techniques
  • T1069
  • T1069.003
  • T1087
  • T1087.004
Created: 2026-09-16