Anthropic MCP Server Created


Description

Detects the first successful creation of a Model Context Protocol (MCP) server integration name in an Anthropic organization within the rule history window. MCP servers add external data pathways into Claude and can expose organizational data to third-party infrastructure. This is a New Terms rule keyed on organization.id and anthropic.audit.mcp_server_name so the same connector name can still alert in another tenant, while routine re-creation of an already-seen name in the same organization does not.

Query · kuery

data_stream.dataset: "anthropic.audit" and
    event.category: "configuration" and
    event.action: "mcp_server_created" and
    event.outcome: "success"

Investigation fields

Pivot points the source recommends for triage.

  • @timestamp
  • event.action
  • event.id
  • organization.id
  • anthropic.audit.mcp_server_id
  • anthropic.audit.mcp_server_name
  • anthropic.audit.actor.type
  • user.email
  • user.id
  • source.ip
  • user_agent.original

Known false positives

  • Teams enable approved MCP connectors for data platforms, ticketing systems, and internal tools during Claude rollouts. Validate the server name, actor, and whether the integration matches an approved request.

Analyst notes

Investigating Anthropic MCP Server Created

First-seen MCP server name for this organization.id within the rule history window. MCP connectors add external data pathways into Claude.

Unauthorized = server name not on approved integration inventory, actor is unexpected/contractor without a request, or creation pairs with data export / public artifact sharing / privilege changes. Close as FP when inventory and pilot/onboarding ticket match.

Possible investigation steps

  • Record anthropic.audit.mcp_server_name / mcp_server_id and actor. For user_actor, validate email/IP/UA against platform admins.
  • Search mcp_server_updated / mcp_server_deleted for the same server ID; look for exports, artifact sharing, or admin role grants in the same window.
  • Close as FP when inventory + pilot ticket match the name; escalate unknown connector names immediately.

False positive analysis

  • Claude pilots commonly introduce first-seen approved connector names from platform teams.

Response and remediation

  • On unauthorized creation: remove the MCP server and review data accessed through the connector during the exposure window.
Raw source Anthropic MCP Server Created · Elastic TOML
Esc
Published by elastic/detection-rules ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[metadata]
creation_date = "2026/09/12"
integration = ["anthropic"]
maturity = "production"
updated_date = "2026/09/25"

[rule]
author = ["Elastic"]
description = """
Detects the first successful creation of a Model Context Protocol (MCP) server integration name in an Anthropic
organization within the rule history window. MCP servers add external data pathways into Claude and can expose
organizational data to third-party infrastructure. This is a New Terms rule keyed on `organization.id` and
`anthropic.audit.mcp_server_name` so the same connector name can still alert in another tenant, while routine
re-creation of an already-seen name in the same organization does not.
"""
false_positives = [
    """
    Teams enable approved MCP connectors for data platforms, ticketing systems, and internal tools during Claude
    rollouts. Validate the server name, actor, and whether the integration matches an approved request.
    """,
]
from = "now-9m"
index = ["logs-anthropic.audit-*"]
language = "kuery"
license = "Elastic License v2"
name = "Anthropic MCP Server Created"
note = """## Triage and analysis

### Investigating Anthropic MCP Server Created

First-seen MCP server name for this `organization.id` within the rule history window. MCP connectors add external
data pathways into Claude.

Unauthorized = server name not on approved integration inventory, actor is unexpected/contractor without a request,
or creation pairs with data export / public artifact sharing / privilege changes. Close as FP when inventory and
pilot/onboarding ticket match.

#### Possible investigation steps

- Record `anthropic.audit.mcp_server_name` / `mcp_server_id` and actor. For `user_actor`, validate email/IP/UA
  against platform admins.
- Search `mcp_server_updated` / `mcp_server_deleted` for the same server ID; look for exports, artifact sharing, or
  admin role grants in the same window.
- Close as FP when inventory + pilot ticket match the name; escalate unknown connector names immediately.

### False positive analysis

- Claude pilots commonly introduce first-seen approved connector names from platform teams.

### Response and remediation

- On unauthorized creation: remove the MCP server and review data accessed through the connector during the exposure
  window.
"""
references = ["https://platform.claude.com/docs/en/api/compliance/activities/list"]
risk_score = 47
rule_id = "e3acc6d4-cd6e-4748-baeb-1c57a0f37635"
severity = "medium"
tags = [
    "Domain: GenAI",
    "Platform: Anthropic",
    "Data Source: Anthropic Audit Logs",
    "Use Case: Threat Detection",
    "Use Case: UEBA",
    "Resources: Investigation Guide",
    "Rule Type: New Terms",
    "Tactic: Persistence",
    "Mitre Atlas: AML.T0081",
]
timestamp_override = "event.ingested"
type = "new_terms"

query = '''
data_stream.dataset: "anthropic.audit" and
    event.category: "configuration" and
    event.action: "mcp_server_created" and
    event.outcome: "success"
'''


[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1176"
name = "Software Extensions"
reference = "https://attack.mitre.org/techniques/T1176/"


[rule.threat.tactic]
id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[[rule.threat_mappings]]
framework = "MITRE ATLAS"
version = "2026.08"
[[rule.threat_mappings.threat]]
framework = "MITRE ATLAS"
[[rule.threat_mappings.threat.technique]]
id = "AML.T0081"
name = "Modify AI Agent Configuration"
reference = "https://atlas.mitre.org/techniques/AML.T0081/"


[rule.threat_mappings.threat.tactic]
id = "AML.TA0006"
name = "Persistence"
reference = "https://atlas.mitre.org/tactics/AML.TA0006/"

[rule.investigation_fields]
field_names = [
    "@timestamp",
    "event.action",
    "event.id",
    "organization.id",
    "anthropic.audit.mcp_server_id",
    "anthropic.audit.mcp_server_name",
    "anthropic.audit.actor.type",
    "user.email",
    "user.id",
    "source.ip",
    "user_agent.original",
]

[rule.new_terms]
field = "new_terms_fields"
value = ["organization.id", "anthropic.audit.mcp_server_name"]
[[rule.new_terms.history_window_start]]
field = "history_window_start"
value = "now-14d"


Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.