Anthropic Artifact Shared Publicly


Description

Claude artifacts can be shared with specific audiences. Making an artifact public exposes its contents to unauthenticated viewers on the internet. An attacker with access to sensitive artifacts can publish them publicly to push intellectual property, credentials embedded in prompts, or other confidential material outside organizational controls.

Query · esql

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "claude_artifact_sharing_updated"
| eval Esql.audience_types = FIELD_EXTRACT(anthropic.audit.audience, "type")
| where Esql.audience_types is not null and mv_contains(Esql.audience_types, "anyone_with_link")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*, Esql.audience_types

Investigation fields

Pivot points the source recommends for triage.

  • @timestamp
  • event.action
  • event.id
  • organization.id
  • anthropic.audit.claude_artifact_id
  • anthropic.audit.audience
  • anthropic.audit.actor.type
  • user.email
  • user.id
  • source.ip
  • user_agent.original

Known false positives

  • Users publish artifacts intentionally for demos, documentation, or external collaboration. Validate the artifact, actor, and business justification before escalating.

Analyst notes

Investigating Anthropic Artifact Shared Publicly

A Claude artifact's sharing audience includes anyone_with_link (open internet). Each sharing change is its own alert/artifact ID.

Unauthorized = no marketing/training justification, artifact holds credentials/customer/proprietary content, or the same actor recently had chat access failures / data exports. Close as FP for intentional external demos with non-sensitive content.

Possible investigation steps

  • Verify audience includes anyone_with_link via flattened audience (FIELD_EXTRACT + mv_contains or event.original) and note anthropic.audit.claude_artifact_id.
  • Validate actor (email/IP/UA). Inspect artifact content for secrets or proprietary data when accessible.
  • Look for related chat access failures or data exports from the same actor in the same window.

False positive analysis

  • DevRel/training publishes are FP when the artifact is non-sensitive and a marketing/training request exists.

Response and remediation

  • On unauthorized publication: revoke public sharing, inventory other artifacts modified by the same actor, and treat any embedded secrets as compromised.
Raw source Anthropic Artifact Shared Publicly · Elastic TOML
Esc
Published by elastic/detection-rules ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[metadata]
creation_date = "2026/09/12"
integration = ["anthropic"]
maturity = "production"
min_stack_comments = "FIELD_EXTRACT for flattened fields requires 9.5.0"
min_stack_version = "9.5.0"
updated_date = "2026/09/25"

[rule]
author = ["Elastic"]
description = """
Claude artifacts can be shared with specific audiences. Making an artifact public exposes its contents to
unauthenticated viewers on the internet. An attacker with access to sensitive artifacts can publish them publicly to
push intellectual property, credentials embedded in prompts, or other confidential material outside organizational
controls.
"""
false_positives = [
    """
    Users publish artifacts intentionally for demos, documentation, or external collaboration. Validate the artifact,
    actor, and business justification before escalating.
    """,
]
from = "now-9m"
language = "esql"
license = "Elastic License v2"
name = "Anthropic Artifact Shared Publicly"
note = """## Triage and analysis

### Investigating Anthropic Artifact Shared Publicly

A Claude artifact's sharing audience includes `anyone_with_link` (open internet). Each sharing change is its own
alert/artifact ID.

Unauthorized = no marketing/training justification, artifact holds credentials/customer/proprietary content, or the
same actor recently had chat access failures / data exports. Close as FP for intentional external demos with
non-sensitive content.

#### Possible investigation steps

- Verify audience includes `anyone_with_link` via flattened `audience` (`FIELD_EXTRACT` + `mv_contains` or
  `event.original`) and note `anthropic.audit.claude_artifact_id`.
- Validate actor (email/IP/UA). Inspect artifact content for secrets or proprietary data when accessible.
- Look for related chat access failures or data exports from the same actor in the same window.

### False positive analysis

- DevRel/training publishes are FP when the artifact is non-sensitive and a marketing/training request exists.

### Response and remediation

- On unauthorized publication: revoke public sharing, inventory other artifacts modified by the same actor, and
  treat any embedded secrets as compromised.
"""
references = ["https://platform.claude.com/docs/en/api/compliance/activities/list"]
risk_score = 47
rule_id = "14290b38-a8dd-474d-bfd7-cce282f4f745"
severity = "medium"
tags = [
    "Domain: GenAI",
    "Platform: Anthropic",
    "Data Source: Anthropic Audit Logs",
    "Use Case: Threat Detection",
    "Resources: Investigation Guide",
    "Rule Type: ES|QL",
    "Tactic: Exfiltration",
    "Mitre Atlas: AML.T0025",
]
timestamp_override = "event.ingested"
type = "esql"

query = '''
from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "configuration") and
    event.action == "claude_artifact_sharing_updated"
| eval Esql.audience_types = FIELD_EXTRACT(anthropic.audit.audience, "type")
| where Esql.audience_types is not null and mv_contains(Esql.audience_types, "anyone_with_link")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*, Esql.audience_types
'''


[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1567"
name = "Exfiltration Over Web Service"
reference = "https://attack.mitre.org/techniques/T1567/"


[rule.threat.tactic]
id = "TA0010"
name = "Exfiltration"
reference = "https://attack.mitre.org/tactics/TA0010/"
[[rule.threat_mappings]]
framework = "MITRE ATLAS"
version = "2026.08"
[[rule.threat_mappings.threat]]
framework = "MITRE ATLAS"
[[rule.threat_mappings.threat.technique]]
id = "AML.T0025"
name = "Exfiltration via Cyber Means"
reference = "https://atlas.mitre.org/techniques/AML.T0025/"


[rule.threat_mappings.threat.tactic]
id = "AML.TA0010"
name = "Exfiltration"
reference = "https://atlas.mitre.org/tactics/AML.TA0010/"

[rule.investigation_fields]
field_names = [
    "@timestamp",
    "event.action",
    "event.id",
    "organization.id",
    "anthropic.audit.claude_artifact_id",
    "anthropic.audit.audience",
    "anthropic.audit.actor.type",
    "user.email",
    "user.id",
    "source.ip",
    "user_agent.original",
]

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.