<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Anthropic (Audit Logs) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/anthropic-audit-logs/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:09:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/anthropic-audit-logs/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Anthropic Organization Member and Group Enumeration Reconnaissance</title><link>https://feed.craftedsignal.io/briefs/2026-10-anthropic-recon/</link><pubDate>Thu, 01 Oct 2026 20:09:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-anthropic-recon/</guid><description>Adversaries are performing reconnaissance within Anthropic organizations by chaining user and group enumeration actions, signaling intent for account takeover or unauthorized data access.</description><content:encoded><![CDATA[<p>This threat brief focuses on discovery activities observed within Anthropic organization audit logs. Threat actors are utilizing legitimate platform API actions to map the organizational structure of a tenant. By chaining multiple distinct read operations - specifically listing users, exporting member lists, and viewing group configurations - attackers gain visibility into internal teams, role structures, and high-value accounts. This reconnaissance phase typically precedes malicious activity such as privilege escalation, unauthorized role grants, or targeted data exfiltration. Because these actions leverage standard identity and access management (IAM) functionality, defenders must distinguish between legitimate administrative audits and unauthorized discovery by non-administrative users.</p>
<h2 id="impact">Impact</h2>
<p>Successful reconnaissance allows an adversary to identify and target high-privilege accounts for takeover, facilitate unauthorized role grants, or perform targeted data collection. This activity poses a significant risk to organizational confidentiality and identity integrity, especially if the account is later used to modify SSO settings, invite malicious external actors, or exfiltrate enterprise-grade GenAI configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement monitoring for the chaining of organizational discovery actions as outlined in the detection logic below.</li>
<li>Review and tighten least-privilege policies regarding identity read actions and member exports for non-administrative user roles.</li>
<li>Audit recent role grants, team invites, and SSO configuration changes when this discovery pattern is identified.</li>
<li>Validate identified activity against known IT service tickets or scheduled compliance audits to reduce false positives.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>GenAI</category><category>Discovery</category><category>Cloud</category><category>UEBA</category></item></channel></rss>