Anthropic Impossible Travel Login


Description

Detects successful Anthropic magic link or SSO sign-ins for the same user email from source IP addresses whose query-time geo-locations (via IP_LOCATION) are separated by at least 1,000 km, with implied travel faster than 800 km/h, within a 24-hour window. That pattern can indicate account sharing, VPN or proxy egress mismatches, or an adversary authenticating from a geography far from the legitimate user's baseline.

Query · esql

from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "authentication") and
    event.outcome == "success" and
    event.action in ("magic_link_login_succeeded", "sso_login_succeeded") and
    user.email is not null and
    source.ip is not null
| IP_LOCATION geo = source.ip with { "properties": ["country_name", "city_name", "location"] }
| eval
    Esql.source_geo_lat = st_y(geo.location),
    Esql.source_geo_lon = st_x(geo.location)
| where Esql.source_geo_lat is not null and Esql.source_geo_lon is not null
| stats
    Esql.first_lat = first(Esql.source_geo_lat, @timestamp),
    Esql.first_lon = first(Esql.source_geo_lon, @timestamp),
    Esql.last_lat = last(Esql.source_geo_lat, @timestamp),
    Esql.last_lon = last(Esql.source_geo_lon, @timestamp),
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.event_action_values = values(event.action),
    Esql.source_ip_values = values(source.ip),
    Esql.source_geo_country_name_values = values(geo.country_name),
    Esql.source_geo_city_name_values = values(geo.city_name),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.email
| where Esql.event_count >= 2
| eval
    Esql.p1 = to_geopoint(concat("POINT(", to_string(Esql.first_lon), " ", to_string(Esql.first_lat), ")")),
    Esql.p2 = to_geopoint(concat("POINT(", to_string(Esql.last_lon), " ", to_string(Esql.last_lat), ")"))
| eval
    Esql.distance_km = round(st_distance(Esql.p1, Esql.p2) / 1000.0, 0),
    Esql.window_minutes = date_diff("minute", Esql.timestamp_first_seen, Esql.timestamp_last_seen),
    Esql.travel_kmh = case(Esql.window_minutes > 0, round(Esql.distance_km * 60.0 / Esql.window_minutes, 0), null)
| where Esql.distance_km >= 1000 and Esql.travel_kmh >= 800
| keep user.email, Esql.*

Investigation fields

Pivot points the source recommends for triage.

  • user.email
  • Esql.distance_km
  • Esql.travel_kmh
  • Esql.window_minutes
  • Esql.event_count
  • Esql.event_id_values
  • Esql.event_action_values
  • Esql.source_ip_values
  • Esql.source_geo_country_name_values
  • Esql.source_geo_city_name_values
  • Esql.first_lat
  • Esql.first_lon
  • Esql.last_lat
  • Esql.last_lon
  • Esql.user_agent_original_values
  • Esql.anthropic_audit_actor_type_values
  • Esql.timestamp_first_seen
  • Esql.timestamp_last_seen

Known false positives

  • Users on VPN or proxy egress that geo-resolves through a region distant from the user's physical location. Mobile clients on cellular networks that peer through regional hubs may geo-resolve differently than the user's location.

Analyst notes

Investigating Anthropic Impossible Travel Login

Two successful magic-link or SSO sign-ins for the same user.email appear too far apart, too quickly, to be physical travel. That can be account sharing, VPN/proxy geo mismatch, or adversary authentication from a distant egress.

Note: an A-B-A return to the first location may not alert (first/last coords can be close) — always sort raw Timeline auth events before concluding.

Unauthorized / escalate when the distant IP/UA is unfamiliar, the user denies travel/VPN use, or failures / SSO weakening sit nearby. Close as FP when the user confirms known travel, split home/office VPN, or geo DB noise with matching corporate ASN/UA.

Possible investigation steps

  • Read Esql.distance_km, Esql.travel_kmh, Esql.window_minutes, and the geo/IP value lists — high speed with a country change is stronger than a same-region VPN hop.
  • Timeline-sort successful logins; compare each source.ip, geo, and user_agent.original. A browser→curl/python shift on the distant hop is higher priority than two similar corporate browsers.
  • Pair with Anthropic Multiple Authentication Failures or SSO / magic-link second-factor changes when takeover is plausible.
  • Ask the user only after geo/UA triage: expected travel or VPN egress vs unrecognized location.

False positive analysis

  • VPN pools and anycast/satellite geo misplacements commonly inflate implied speed — corroborate ASN and UA first.

Response and remediation

  • On suspected compromise: revoke sessions, reset credentials/MFA, and review admin or data-access activity after the distant sign-in.
Raw source Anthropic Impossible Travel Login · Elastic TOML
Esc
Published by elastic/detection-rules ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[metadata]
creation_date = "2026/09/15"
integration = ["anthropic"]
maturity = "production"
min_stack_comments = "ES|QL IP_LOCATION requires 9.5.0+. FIRST/LAST aggregations and st_distance require 9.4.0+."
min_stack_version = "9.5.0"
updated_date = "2026/09/25"

[rule]
author = ["Elastic"]
description = """
Detects successful Anthropic magic link or SSO sign-ins for the same user email from source IP addresses whose
query-time geo-locations (via IP_LOCATION) are separated by at least 1,000 km, with implied travel faster than 800 km/h,
within a 24-hour window. That pattern can indicate account sharing, VPN or proxy egress mismatches, or an adversary
authenticating from a geography far from the legitimate user's baseline.
"""
false_positives = [
    """
    Users on VPN or proxy egress that geo-resolves through a region distant from the user's physical location. Mobile
    clients on cellular networks that peer through regional hubs may geo-resolve differently than the user's location.
    """,
]
from = "now-24h"
interval = "1h"
language = "esql"
license = "Elastic License v2"
name = "Anthropic Impossible Travel Login"
note = """## Triage and analysis

### Investigating Anthropic Impossible Travel Login

Two successful magic-link or SSO sign-ins for the same `user.email` appear too far apart, too quickly, to be physical
travel. That can be account sharing, VPN/proxy geo mismatch, or adversary authentication from a distant egress.

Note: an A-B-A return to the first location may not alert (first/last coords can be close) — always sort raw Timeline
auth events before concluding.

Unauthorized / escalate when the distant IP/UA is unfamiliar, the user denies travel/VPN use, or failures / SSO
weakening sit nearby. Close as FP when the user confirms known travel, split home/office VPN, or geo DB noise with
matching corporate ASN/UA.

#### Possible investigation steps

- Read `Esql.distance_km`, `Esql.travel_kmh`, `Esql.window_minutes`, and the geo/IP value lists — high speed with a
  country change is stronger than a same-region VPN hop.
- Timeline-sort successful logins; compare each `source.ip`, geo, and `user_agent.original`. A browser→curl/python
  shift on the distant hop is higher priority than two similar corporate browsers.
- Pair with **Anthropic Multiple Authentication Failures** or SSO / magic-link second-factor changes when takeover is
  plausible.
- Ask the user only after geo/UA triage: expected travel or VPN egress vs unrecognized location.

### False positive analysis

- VPN pools and anycast/satellite geo misplacements commonly inflate implied speed — corroborate ASN and UA first.

### Response and remediation

- On suspected compromise: revoke sessions, reset credentials/MFA, and review admin or data-access activity after the
  distant sign-in.
"""
references = ["https://platform.claude.com/docs/en/api/compliance/activities/list"]
risk_score = 73
rule_id = "e89e4744-039e-4290-9835-63ea42fe531e"
severity = "high"
tags = [
    "Domain: GenAI",
    "Domain: Identity",
    "Platform: Anthropic",
    "Data Source: Anthropic Audit Logs",
    "Use Case: Identity and Access Audit",
    "Use Case: Threat Detection",
    "Resources: Investigation Guide",
    "Rule Type: ES|QL",
    "Tactic: Initial Access",
    "Mitre Atlas: AML.T0012",
]
timestamp_override = "event.ingested"
type = "esql"

query = '''
from logs-anthropic.audit-*
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "authentication") and
    event.outcome == "success" and
    event.action in ("magic_link_login_succeeded", "sso_login_succeeded") and
    user.email is not null and
    source.ip is not null
| IP_LOCATION geo = source.ip with { "properties": ["country_name", "city_name", "location"] }
| eval
    Esql.source_geo_lat = st_y(geo.location),
    Esql.source_geo_lon = st_x(geo.location)
| where Esql.source_geo_lat is not null and Esql.source_geo_lon is not null
| stats
    Esql.first_lat = first(Esql.source_geo_lat, @timestamp),
    Esql.first_lon = first(Esql.source_geo_lon, @timestamp),
    Esql.last_lat = last(Esql.source_geo_lat, @timestamp),
    Esql.last_lon = last(Esql.source_geo_lon, @timestamp),
    Esql.event_count = count(*),
    Esql.event_id_values = values(event.id),
    Esql.event_action_values = values(event.action),
    Esql.source_ip_values = values(source.ip),
    Esql.source_geo_country_name_values = values(geo.country_name),
    Esql.source_geo_city_name_values = values(geo.city_name),
    Esql.user_agent_original_values = values(user_agent.original),
    Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
    Esql.timestamp_first_seen = min(@timestamp),
    Esql.timestamp_last_seen = max(@timestamp)
  by user.email
| where Esql.event_count >= 2
| eval
    Esql.p1 = to_geopoint(concat("POINT(", to_string(Esql.first_lon), " ", to_string(Esql.first_lat), ")")),
    Esql.p2 = to_geopoint(concat("POINT(", to_string(Esql.last_lon), " ", to_string(Esql.last_lat), ")"))
| eval
    Esql.distance_km = round(st_distance(Esql.p1, Esql.p2) / 1000.0, 0),
    Esql.window_minutes = date_diff("minute", Esql.timestamp_first_seen, Esql.timestamp_last_seen),
    Esql.travel_kmh = case(Esql.window_minutes > 0, round(Esql.distance_km * 60.0 / Esql.window_minutes, 0), null)
| where Esql.distance_km >= 1000 and Esql.travel_kmh >= 800
| keep user.email, Esql.*
'''


[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1078"
name = "Valid Accounts"
reference = "https://attack.mitre.org/techniques/T1078/"
[[rule.threat.technique.subtechnique]]
id = "T1078.004"
name = "Cloud Accounts"
reference = "https://attack.mitre.org/techniques/T1078/004/"



[rule.threat.tactic]
id = "TA0001"
name = "Initial Access"
reference = "https://attack.mitre.org/tactics/TA0001/"
[[rule.threat_mappings]]
framework = "MITRE ATLAS"
version = "2026.08"
[[rule.threat_mappings.threat]]
framework = "MITRE ATLAS"
[[rule.threat_mappings.threat.technique]]
id = "AML.T0012"
name = "Valid Accounts"
reference = "https://atlas.mitre.org/techniques/AML.T0012/"


[rule.threat_mappings.threat.tactic]
id = "AML.TA0004"
name = "Initial Access"
reference = "https://atlas.mitre.org/tactics/AML.TA0004/"

[rule.alert_suppression]
group_by = ["user.email"]
missing_fields_strategy = "suppress"

[rule.investigation_fields]
field_names = [
    "user.email",
    "Esql.distance_km",
    "Esql.travel_kmh",
    "Esql.window_minutes",
    "Esql.event_count",
    "Esql.event_id_values",
    "Esql.event_action_values",
    "Esql.source_ip_values",
    "Esql.source_geo_country_name_values",
    "Esql.source_geo_city_name_values",
    "Esql.first_lat",
    "Esql.first_lon",
    "Esql.last_lat",
    "Esql.last_lon",
    "Esql.user_agent_original_values",
    "Esql.anthropic_audit_actor_type_values",
    "Esql.timestamp_first_seen",
    "Esql.timestamp_last_seen",
]

[rule.alert_suppression.duration]
unit = "h"
value = 24

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.