Anthropic MCP Server Deleted


Description

Detects when an MCP server integration is deleted from the organization. Removing an approved integration could indicate an attacker covering tracks or unauthorized configuration changes. The mcp_server_name and mcp_server_id fields identify which integration was removed.

Query · python

from panther_anthropic_helpers import anthropic_actor_id, anthropic_alert_context


def rule(event):
    return event.get("type") == "mcp_server_deleted"


def title(event):
    actor_email = anthropic_actor_id(event)
    server_name = event.get("mcp_server_name", "<UNKNOWN_SERVER>")
    return f"Anthropic: MCP server [{server_name}] deleted by [{actor_email}]"


def dedup(event):
    return anthropic_actor_id(event)


def alert_context(event):
    return anthropic_alert_context(event)

Analyst notes

  1. Find all Anthropic.Activity events with type mcp_server_created by actor:email_address in the 10 minutes after the alert to determine if this was a delete-then-recreate (config fix) or a standalone deletion
  2. Check if actor:email_address has performed other administrative actions (claude_organization_settings_updated, mcp_server_created) in the 6 hours around the alert to assess if this is part of routine admin work
  3. Find all alerts for actor:email_address in the past 7 days to check for signs of account compromise preceding this action
Raw source Anthropic MCP Server Deleted · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
RuleID: Anthropic.Activity.MCP.Server.Deleted
DisplayName: "Anthropic MCP Server Deleted"
Enabled: true
Filename: anthropic_mcp_server_deleted.py
LogTypes:
  - Anthropic.Activity
Severity: Low
Description: >
  Detects when an MCP server integration is deleted from the organization.
  Removing an approved integration could indicate an attacker covering tracks
  or unauthorized configuration changes. The mcp_server_name and mcp_server_id
  fields identify which integration was removed.
Runbook: |
  1. Find all Anthropic.Activity events with type mcp_server_created by actor:email_address in the 10 minutes after the alert to determine if this was a delete-then-recreate (config fix) or a standalone deletion
  2. Check if actor:email_address has performed other administrative actions (claude_organization_settings_updated, mcp_server_created) in the 6 hours around the alert to assess if this is part of routine admin work
  3. Find all alerts for actor:email_address in the past 7 days to check for signs of account compromise preceding this action
Tags:
  - Anthropic
  - Configuration
Reports:
  MITRE ATT&CK:
    - TA0005:T1562  # Impair Defenses
Tests:
  - Name: MCP server deleted
    ExpectedResult: true
    Log:
      {
        "id": "activity_01ABC123",
        "created_at": "2026-05-05T21:46:28Z",
        "organization_id": "org_01XYZ",
        "type": "mcp_server_deleted",
        "mcp_server_id": "mcpsrv_01ABC",
        "mcp_server_name": "Snowflake",
        "actor": {
          "type": "user_actor",
          "email_address": "admin@example.com",
          "user_id": "user_01ABC",
          "ip_address": "10.0.0.1",
          "user_agent": "Mozilla/5.0"
        }
      }
  - Name: MCP server created - not a match
    ExpectedResult: false
    Log:
      {
        "id": "activity_01DEF456",
        "created_at": "2026-05-05T21:52:51Z",
        "organization_id": "org_01XYZ",
        "type": "mcp_server_created",
        "mcp_server_id": "mcpsrv_01DEF",
        "mcp_server_name": "Snowflake",
        "actor": {
          "type": "user_actor",
          "email_address": "admin@example.com",
          "user_id": "user_01ABC",
          "ip_address": "10.0.0.1"
        }
      }


# ------ paired body: anthropic_mcp_server_deleted.py ------

from panther_anthropic_helpers import anthropic_actor_id, anthropic_alert_context


def rule(event):
    return event.get("type") == "mcp_server_deleted"


def title(event):
    actor_email = anthropic_actor_id(event)
    server_name = event.get("mcp_server_name", "<UNKNOWN_SERVER>")
    return f"Anthropic: MCP server [{server_name}] deleted by [{actor_email}]"


def dedup(event):
    return anthropic_actor_id(event)


def alert_context(event):
    return anthropic_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.