Anthropic Compliance API Key Created
Description
Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
event.action == "api_key_created" and
event.outcome == "success" and
anthropic.audit.scopes is not null and
(
mv_contains(anthropic.audit.scopes, "read:compliance_activities") or
mv_contains(anthropic.audit.scopes, "read:compliance_org_data")
)
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.idanthropic.audit.api_key_idanthropic.audit.scopesanthropic.audit.actor.typeanthropic.audit.actor.admin_api_key_iduser.emailuser.idsource.ipuser_agent.original
Known false positives
- Platform and security teams create compliance-scoped API keys when onboarding the Anthropic Fleet integration or setting up SIEM ingestion. Verify the actor and confirm the key is in the approved credentials inventory.
Analyst notes
Investigating Anthropic Compliance API Key Created
A new API key was created with compliance read scopes (audit/compliance data), distinct from admin API keys used for
org administration. Review anthropic.audit.scopes for exact permissions.
Unauthorized = key not in approved inventory / no Fleet or investigation ticket, or creation by an unexpected actor
followed by compliance_api_accessed / audit export activity.
Possible investigation steps
- Record
anthropic.audit.api_key_idand scopes. Branch actor (user_actorvsadmin_api_key_actor) and validate against known platform admins or parent admin keys. - Pivot on that
api_key_idfor latercompliance_api_accessed(programmatic use of the new key). - Correlate ±hours for admin role grants, logging disablement, or data exports — recon before further intrusion.
False positive analysis
- First Fleet onboarding key for an org is expected — require inventory / ticket evidence.
Response and remediation
- On unauthorized creation: revoke the key and review Compliance API / export activity during the exposure window.