{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/anthropic-audit-logs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Anthropic (Audit Logs)"],"_cs_severities":["medium"],"_cs_tags":["GenAI","Discovery","Cloud","UEBA"],"_cs_type":"advisory","_cs_vendors":["Anthropic"],"content_html":"\u003cp\u003eThis threat brief focuses on discovery activities observed within Anthropic organization audit logs. Threat actors are utilizing legitimate platform API actions to map the organizational structure of a tenant. By chaining multiple distinct read operations - specifically listing users, exporting member lists, and viewing group configurations - attackers gain visibility into internal teams, role structures, and high-value accounts. This reconnaissance phase typically precedes malicious activity such as privilege escalation, unauthorized role grants, or targeted data exfiltration. Because these actions leverage standard identity and access management (IAM) functionality, defenders must distinguish between legitimate administrative audits and unauthorized discovery by non-administrative users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful reconnaissance allows an adversary to identify and target high-privilege accounts for takeover, facilitate unauthorized role grants, or perform targeted data collection. This activity poses a significant risk to organizational confidentiality and identity integrity, especially if the account is later used to modify SSO settings, invite malicious external actors, or exfiltrate enterprise-grade GenAI configurations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for the chaining of organizational discovery actions as outlined in the detection logic below.\u003c/li\u003e\n\u003cli\u003eReview and tighten least-privilege policies regarding identity read actions and member exports for non-administrative user roles.\u003c/li\u003e\n\u003cli\u003eAudit recent role grants, team invites, and SSO configuration changes when this discovery pattern is identified.\u003c/li\u003e\n\u003cli\u003eValidate identified activity against known IT service tickets or scheduled compliance audits to reduce false positives.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:09:17Z","date_published":"2026-10-01T20:09:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-anthropic-recon/","summary":"Adversaries are performing reconnaissance within Anthropic organizations by chaining user and group enumeration actions, signaling intent for account takeover or unauthorized data access.","title":"Anthropic Organization Member and Group Enumeration Reconnaissance","url":"https://feed.craftedsignal.io/briefs/2026-10-anthropic-recon/"}],"language":"en","title":"CraftedSignal Threat Feed - Anthropic (Audit Logs)","version":"https://jsonfeed.org/version/1.1"}