Anthropic Organization Member and Group Enumeration Reconnaissance
Adversaries are performing reconnaissance within Anthropic organizations by chaining user and group enumeration actions, signaling intent for account takeover or unauthorized data access.
This threat brief focuses on discovery activities observed within Anthropic organization audit logs. Threat actors are utilizing legitimate platform API actions to map the organizational structure of a tenant. By chaining multiple distinct read operations - specifically listing users, exporting member lists, and viewing group configurations - attackers gain visibility into internal teams, role structures, and high-value accounts. This reconnaissance phase typically precedes malicious activity such as privilege escalation, unauthorized role grants, or targeted data exfiltration. Because these actions leverage standard identity and access management (IAM) functionality, defenders must distinguish between legitimate administrative audits and unauthorized discovery by non-administrative users.
Impact
Successful reconnaissance allows an adversary to identify and target high-privilege accounts for takeover, facilitate unauthorized role grants, or perform targeted data collection. This activity poses a significant risk to organizational confidentiality and identity integrity, especially if the account is later used to modify SSO settings, invite malicious external actors, or exfiltrate enterprise-grade GenAI configurations.
Recommendation
- Implement monitoring for the chaining of organizational discovery actions as outlined in the detection logic below.
- Review and tighten least-privilege policies regarding identity read actions and member exports for non-administrative user roles.
- Audit recent role grants, team invites, and SSO configuration changes when this discovery pattern is identified.
- Validate identified activity against known IT service tickets or scheduled compliance audits to reduce false positives.
Immediate actions
Deploy detection logic to monitor for multiple discovery actions by non-admin users
Threat Hunt
Identify users performing more than two unique discovery actions in a 10-minute window
Data: Anthropic Audit Logs
Enrichment needed
- Source IP and User Agent patterns (SOC) To differentiate automated reconnaissance from legitimate interactive admin sessions
Mitigations
Restrict member export and group view permissions to verified IAM administrators
T1069.003