
Summary
Detects anomalous Anthropic user activity by the same email across multiple geographic locations and with multiple user agents within a four-hour window, using Anthropic audit logs. The rule requires at least three distinct countries and at least two distinct user agents for a single user.email, and it looks for specific Anthropic actions (e.g., claude_chat_created, claude_chat_updated, claude_file_deleted, etc.). This pattern indicates potential leaked session cookies or credential abuse by a remote adversary using VPN/proxy and may reflect cookie replay or account compromise. It includes triage guidance to verify VPN usage, distinguish legitimate split-tunnel or dual-homed deployments via ASN/UA corroboration, and to escalate when suspicious activity lacks typical login events. The detection is implemented as ES|QL over logs-anthropic.audit-* and returns per-user telemetry (country_count, source_ip_count, user_agent_count, event_count, action values, IPs, and timestamps) to support investigation. MITRE mappings link to T1539 (Steal Web Session Cookie) and T1078 (Valid Accounts) with cloud/Anthropic context, and MITRE ATLAS AML.T0012 (Valid Accounts) under Initial Access. Remediation recommendations include revoking sessions, forcing logout across devices, resetting credentials/MFA, auditing for privileged actions, and confirming user VPN usage during the time window. The rule emphasizes action-based indicators alongside geographic and UA diversity to reduce false positives when legitimate access occurs from corporate or trusted VPNs.
Categories
- Cloud
- Web
- Application
- Identity Management
Data Sources
- Application Log
ATT&CK Techniques
- T0012
- T1539
- T1078
- T1078.004
Created: 2026-10-05