Anthropic MCP Server Deleted
Description
Detects when an MCP server integration is deleted from the organization. Removing an approved integration could indicate an attacker covering tracks or unauthorized configuration changes. The mcp_server_name and mcp_server_id fields identify which integration was removed.
Query · python
from panther_anthropic_helpers import anthropic_actor_id, anthropic_alert_context
def rule(event):
return event.get("type") == "mcp_server_deleted"
def title(event):
actor_email = anthropic_actor_id(event)
server_name = event.get("mcp_server_name", "<UNKNOWN_SERVER>")
return f"Anthropic: MCP server [{server_name}] deleted by [{actor_email}]"
def dedup(event):
return anthropic_actor_id(event)
def alert_context(event):
return anthropic_alert_context(event)
Analyst notes
- Find all Anthropic.Activity events with type mcp_server_created by actor:email_address in the 10 minutes after the alert to determine if this was a delete-then-recreate (config fix) or a standalone deletion
- Check if actor:email_address has performed other administrative actions (claude_organization_settings_updated, mcp_server_created) in the 6 hours around the alert to assess if this is part of routine admin work
- Find all alerts for actor:email_address in the past 7 days to check for signs of account compromise preceding this action