Skip to content
Threat Feed
medium advisory

Anthropic Organization Member and Group Enumeration Reconnaissance

Adversaries are performing reconnaissance within Anthropic organizations by chaining user and group enumeration actions, signaling intent for account takeover or unauthorized data access.

This threat brief focuses on discovery activities observed within Anthropic organization audit logs. Threat actors are utilizing legitimate platform API actions to map the organizational structure of a tenant. By chaining multiple distinct read operations - specifically listing users, exporting member lists, and viewing group configurations - attackers gain visibility into internal teams, role structures, and high-value accounts. This reconnaissance phase typically precedes malicious activity such as privilege escalation, unauthorized role grants, or targeted data exfiltration. Because these actions leverage standard identity and access management (IAM) functionality, defenders must distinguish between legitimate administrative audits and unauthorized discovery by non-administrative users.

Impact

Successful reconnaissance allows an adversary to identify and target high-privilege accounts for takeover, facilitate unauthorized role grants, or perform targeted data collection. This activity poses a significant risk to organizational confidentiality and identity integrity, especially if the account is later used to modify SSO settings, invite malicious external actors, or exfiltrate enterprise-grade GenAI configurations.

Recommendation

  • Implement monitoring for the chaining of organizational discovery actions as outlined in the detection logic below.
  • Review and tighten least-privilege policies regarding identity read actions and member exports for non-administrative user roles.
  • Audit recent role grants, team invites, and SSO configuration changes when this discovery pattern is identified.
  • Validate identified activity against known IT service tickets or scheduled compliance audits to reduce false positives.

Immediate actions

Deploy detection logic to monitor for multiple discovery actions by non-admin users

Detection Engineering 48h

Threat Hunt

Identify users performing more than two unique discovery actions in a 10-minute window

T1087.004 medium high confidence hunt now

Data: Anthropic Audit Logs

Enrichment needed

  • Source IP and User Agent patterns (SOC) To differentiate automated reconnaissance from legitimate interactive admin sessions

Mitigations

Restrict member export and group view permissions to verified IAM administrators

medium_term IT Operations

T1069.003