heroui logo

Anthropic User Activity From High Number of Countries

Elastic Detection Rules

View Source
Summary
Detects anomalous Anthropic user activity by the same email across multiple geographic locations and with multiple user agents within a four-hour window, using Anthropic audit logs. The rule requires at least three distinct countries and at least two distinct user agents for a single user.email, and it looks for specific Anthropic actions (e.g., claude_chat_created, claude_chat_updated, claude_file_deleted, etc.). This pattern indicates potential leaked session cookies or credential abuse by a remote adversary using VPN/proxy and may reflect cookie replay or account compromise. It includes triage guidance to verify VPN usage, distinguish legitimate split-tunnel or dual-homed deployments via ASN/UA corroboration, and to escalate when suspicious activity lacks typical login events. The detection is implemented as ES|QL over logs-anthropic.audit-* and returns per-user telemetry (country_count, source_ip_count, user_agent_count, event_count, action values, IPs, and timestamps) to support investigation. MITRE mappings link to T1539 (Steal Web Session Cookie) and T1078 (Valid Accounts) with cloud/Anthropic context, and MITRE ATLAS AML.T0012 (Valid Accounts) under Initial Access. Remediation recommendations include revoking sessions, forcing logout across devices, resetting credentials/MFA, auditing for privileged actions, and confirming user VPN usage during the time window. The rule emphasizes action-based indicators alongside geographic and UA diversity to reduce false positives when legitimate access occurs from corporate or trusted VPNs.
Categories
  • Cloud
  • Web
  • Application
  • Identity Management
Data Sources
  • Application Log
ATT&CK Techniques
  • T0012
  • T1539
  • T1078
  • T1078.004
Created: 2026-10-05