Skip to content

[THREAT-689] Anthropic Compliance API Rules - #2053

Merged
arielkr256 merged 2 commits into
developfrom
anthropic-rules-2
May 12, 2026
Merged

arielkr256 merged 2 commits into
developfrom
anthropic-rules-2

Conversation

@alessandrarizzo

Copy link
Copy Markdown
Contributor

Background

Adds Anthropic Activity log OOTB detection coverage in Experimental status, with a global helper and 17 rules across authentication, access control, configuration, credential management, and compliance.

Changes

Global Helper

  • panther_anthropic_helpers — shared anthropic_alert_context() with actor details, IPs, PantherFlow investigation link, and optional fields

Rules by Severity

High (3)

  • SSO Disabled — SSO toggled off or SSO connection deactivated
  • Primary Owner Transferred — org ownership change
  • IP Restriction Deleted — network access control removed

Medium (8)

  • Excessive Chat Access Failures — >50 failures in 10min per actor (threshold rule)
  • SSO Login Failed — every failed SSO attempt
  • Organization Settings Updated — org-wide config changes, title includes update type
  • MCP Server Created — new external integration, title includes server name
  • Admin API Key Created — admin key lifecycle
  • Admin API Key Deleted — admin key lifecycle
  • Service Key Created — service account key lifecycle
  • Service Key Revoked — service account key lifecycle
  • Spend Limit Deleted — financial control removal
  • Artifact Shared Publicly — artifact audience changed to public

Low (1)

  • MCP Server Deleted — integration removal

Info (3)

  • Role Granted — all role grants for visibility (building baseline of role taxonomy)
  • Integration Connected — user connected external integration (compliance)
  • Org User Deleted — user removal (compliance)

Testing

  • make fmt lint
  • pipenv run panther_analysis_tool test --path rules/anthropic_rules/
@alessandrarizzo
alessandrarizzo requested a review from a team as a code owner May 7, 2026 17:55
@cursor

cursor Bot commented May 7, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Adds new experimental detection content (rules + shared helper) without modifying existing detection logic or runtime infrastructure; main risk is false positives/negatives due to event-field parsing quirks (e.g., string matching on nested type).

Overview
Adds a new panther_anthropic_helpers global helper to standardize Anthropic alert context (actor identifiers, org/IP details, optional event fields, and a PantherFlow investigation link).

Introduces a set of experimental Anthropic.Activity rules covering key lifecycle actions, SSO/security posture changes, org settings/user/admin events, integration/MCP server activity, and a thresholded excessive chat access failure detector; updates alpha-index.md and detection-coverage.json to list this new Anthropic coverage.

Reviewed by Cursor Bugbot for commit d941a92. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256 arielkr256 added the rules Real-time log data detections label May 12, 2026
@arielkr256
arielkr256 enabled auto-merge May 12, 2026 14:27
@arielkr256
arielkr256 added this pull request to the merge queue May 12, 2026
Merged via the queue into develop with commit b326ddf May 12, 2026
18 checks passed
@arielkr256
arielkr256 deleted the anthropic-rules-2 branch May 12, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rules Real-time log data detections

3 participants