Anthropic Organization Deletion


Description

Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action. An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier exfiltration activity is harder to reconstruct from the tenant itself.

Query · esql

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action in ("org_deletion_requested", "org_bulk_delete_initiated", "org_deleted_via_bulk")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*

Investigation fields

Pivot points the source recommends for triage.

  • @timestamp
  • event.action
  • event.id
  • organization.id
  • anthropic.audit.actor.type
  • user.email
  • user.id
  • source.ip
  • user_agent.original

Known false positives

  • Planned tenant offboarding, sandbox teardown, or contract termination can produce these events. Confirm the actor and timing against change management or offboarding records before escalating.

Analyst notes

Investigating Anthropic Organization Deletion

Organization deletion / bulk delete removes tenant data, projects, and member access. Treat early actions as urgent — recovery options shrink as the workflow progresses.

Unauthorized = no offboarding / lab-teardown ticket naming this org and actor, or deletion preceded by owner transfer, admin grants, key creation, or data exports without a matching business project.

Possible investigation steps

  • Identify actor (user_actor → email/IP/UA) and organization.id.
  • Urgency by action:
  • org_deletion_requested: intervene immediately if unauthorized.
  • org_bulk_delete_initiated: bulk delete started — escalate IR now.
  • org_deleted_via_bulk: completed — prioritize evidence preservation outside the tenant.
  • Look for preceding primary owner transfer, admin grants, admin API key creation, or data exports.
  • Close as FP only when platform owners confirm scheduled decommission with matching ticket/time/actor.

False positive analysis

  • Sandbox teardown and contract termination are valid — require change management or offboarding records.

Response and remediation

  • On unauthorized activity: engage Anthropic support and internal IR immediately, preserve remaining audit logs (including prior exports), and rotate administrative credentials for the organization.
Raw source Anthropic Organization Deletion · Elastic TOML
Esc
Published by elastic/detection-rules ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[metadata]
creation_date = "2026/09/12"
integration = ["anthropic"]
maturity = "production"
updated_date = "2026/09/25"

[rule]
author = ["Elastic"]
description = """
Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action.
An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to
destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier
exfiltration activity is harder to reconstruct from the tenant itself.
"""
false_positives = [
    """
    Planned tenant offboarding, sandbox teardown, or contract termination can produce these events. Confirm the actor
    and timing against change management or offboarding records before escalating.
    """,
]
from = "now-9m"
language = "esql"
license = "Elastic License v2"
name = "Anthropic Organization Deletion"
note = """## Triage and analysis

### Investigating Anthropic Organization Deletion

Organization deletion / bulk delete removes tenant data, projects, and member access. Treat early actions as urgent —
recovery options shrink as the workflow progresses.

Unauthorized = no offboarding / lab-teardown ticket naming this org and actor, or deletion preceded by owner transfer,
admin grants, key creation, or data exports without a matching business project.

#### Possible investigation steps

- Identify actor (`user_actor` → email/IP/UA) and `organization.id`.
- Urgency by action:
  - `org_deletion_requested`: intervene immediately if unauthorized.
  - `org_bulk_delete_initiated`: bulk delete started — escalate IR now.
  - `org_deleted_via_bulk`: completed — prioritize evidence preservation outside the tenant.
- Look for preceding primary owner transfer, admin grants, admin API key creation, or data exports.
- Close as FP only when platform owners confirm scheduled decommission with matching ticket/time/actor.

### False positive analysis

- Sandbox teardown and contract termination are valid — require change management or offboarding records.

### Response and remediation

- On unauthorized activity: engage Anthropic support and internal IR immediately, preserve remaining audit logs
  (including prior exports), and rotate administrative credentials for the organization.
"""
references = ["https://platform.claude.com/docs/en/api/compliance/activities/list"]
risk_score = 99
rule_id = "11347993-e71f-4659-a903-e9a0e8bd55de"
severity = "critical"
tags = [
    "Domain: GenAI",
    "Platform: Anthropic",
    "Data Source: Anthropic Audit Logs",
    "Use Case: Threat Detection",
    "Resources: Investigation Guide",
    "Rule Type: ES|QL",
    "Tactic: Impact",
]
timestamp_override = "event.ingested"
type = "esql"

query = '''
from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action in ("org_deletion_requested", "org_bulk_delete_initiated", "org_deleted_via_bulk")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
'''


[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1485"
name = "Data Destruction"
reference = "https://attack.mitre.org/techniques/T1485/"

[[rule.threat.technique]]
id = "T1531"
name = "Account Access Removal"
reference = "https://attack.mitre.org/techniques/T1531/"


[rule.threat.tactic]
id = "TA0040"
name = "Impact"
reference = "https://attack.mitre.org/tactics/TA0040/"
[[rule.threat_mappings]]
framework = "MITRE ATLAS"
version = "2026.08"
[[rule.threat_mappings.threat]]
framework = "MITRE ATLAS"

[rule.threat_mappings.threat.tactic]
id = "AML.TA0011"
name = "Impact"
reference = "https://atlas.mitre.org/tactics/AML.TA0011/"

[rule.investigation_fields]
field_names = [
    "@timestamp",
    "event.action",
    "event.id",
    "organization.id",
    "anthropic.audit.actor.type",
    "user.email",
    "user.id",
    "source.ip",
    "user_agent.original",
]

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.