Anthropic Excessive Chat Access Failures
Description
Detects a single authenticated user generating an unusually high number of denied Claude chat access attempts in a 24-hour window. That pattern fits automated chat enumeration or attempts to reach conversations outside the actor's permissions. Unauthenticated shared-link actors lack user.id and are excluded.
Query · esql
from logs-anthropic.audit-*
| where
data_stream.dataset == "anthropic.audit" and
event.action == "claude_chat_access_failed" and
user.id is not null
| stats
Esql.event_count = count(*),
Esql.event_id_values = values(event.id),
Esql.anthropic_audit_claude_chat_id_values = values(anthropic.audit.claude_chat_id),
Esql.anthropic_audit_claude_project_id_values = values(anthropic.audit.claude_project_id),
Esql.source_ip_values = values(source.ip),
Esql.user_agent_original_values = values(user_agent.original),
Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
Esql.user_email_values = values(user.email),
Esql.timestamp_first_seen = min(@timestamp),
Esql.timestamp_last_seen = max(@timestamp)
by user.id, organization.id, source.ip
| where Esql.event_count >= 20
| keep user.id, organization.id, source.ip, Esql.*
Investigation fields
Pivot points the source recommends for triage.
user.idorganization.idsource.ipEsql.event_countEsql.event_id_valuesEsql.user_email_valuesEsql.anthropic_audit_claude_chat_id_valuesEsql.anthropic_audit_claude_project_id_valuesEsql.source_ip_valuesEsql.user_agent_original_valuesEsql.anthropic_audit_actor_type_valuesEsql.timestamp_first_seenEsql.timestamp_last_seen
Known false positives
- Users browsing many stale or revoked shared chat links during incident response or legal review can produce bursts of access failures. Confirm whether the activity matches an approved investigation before escalating.
Analyst notes
Investigating Anthropic Excessive Chat Access Failures
Alert keys: user.id, organization.id, and source.ip (plus user.email when present). The rule aggregates ≥20
claude_chat_access_failed events for one authenticated user in that org/IP over 24 hours. Unauthenticated
shared-link failures lack user.id and are out of scope.
True positive: high failure-to-claude_chat_viewed ratio, sequential/patterned chat IDs, scripting UA. False
positive: legal/IR link review or broken bookmarks with scattered IDs and many successful views nearby.
Possible investigation steps
- Start from the alert keys (
user.id/organization.id/source.ip) and the time window; pivot rawclaude_chat_access_failedevents. - Review chat ID lists: sequential or patterned IDs suggest enumeration; scattered IDs fit shared-link browsing.
- Compare failure volume to
claude_chat_viewedfrom the same actor. High failure-to-success ratio → enumeration. - Check UA/automation signals and whether any failed chat IDs later succeed. Correlate with IAM/SSO/compliance key changes in the same period.
False positive analysis
- Large revoked-link reviews and retrying expired URLs are FP when IDs are scattered and many
claude_chat_viewedsuccesses sit nearby (legal/IR ticket optional corroboration).
Response and remediation
- On confirmed enumeration: revoke sessions, review recently accessed chats, rotate exposed shared links if needed, and check for data export or artifact sharing by the same user.