Anthropic Admin API Key Deleted
Description
Admin API keys grant programmatic access to organization and compliance APIs. An attacker can delete legitimate admin API keys to break security monitoring or integrations, or to cover tracks after creating replacement credentials they control. Deletion without a nearby rotation event points more at sabotage than routine key hygiene.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
event.action == "admin_api_key_deleted"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.iduser.emailuser.idanthropic.audit.admin_api_key_idanthropic.audit.actor.admin_api_key_idsource.ipuser_agent.originalanthropic.audit.actor.type
Known false positives
- Platform and security teams delete admin API keys during scheduled rotation or decommissioning. Check for a nearby `admin_api_key_created` event or an approved change ticket to explain the deletion.
Analyst notes
Investigating Anthropic Admin API Key Deleted
Deleting an admin API key can break Fleet/compliance ingestion or admin automation — or remove a defender-owned key after an attacker creates a replacement they control.
Unauthorized = deletion without a matching nearby admin_api_key_created (rotation) or decommission ticket, or
deletion by an unexpected actor paired with logging disablement / exports / SSO changes.
Possible investigation steps
- Note deleted
anthropic.audit.admin_api_key_idand actor. Foruser_actor, validate admin identity (email/IP/UA). Foradmin_api_key_actor, check whether the deleting key (actor.admin_api_key_id) was itself recently created. - Distinguish rotation (create+delete same window, same actor) from standalone deletion.
- Check whether Fleet/compliance ingestion stopped after the delete; correlate with compliance logging changes, exports, or SSO modifications.
False positive analysis
- Scheduled rotation pairs delete with create during maintenance — ticket + sibling create event closes as FP.
Response and remediation
- On unauthorized deletion: restore required integrations with new keys, verify audit ingestion, and review other admin changes by the same actor in the exposure window.