Back to results

Delinea - Failed authentication spike (single account)

Detects when a single account accumulates an unusually high number of failed authentication events within a short window. Only authentication events - MFA, login and sign-in - are considered; the service-wide view of…

Description

Detects when a single account accumulates an unusually high number of failed authentication events within a short window. Only authentication events - MFA, login and sign-in - are considered; the service-wide view of every failure lives in the 'Delinea - Failed operations' hunting query. A failure is a failed MFA result, a failed password factor, or any login fail reason. A burst of failures for one account can indicate brute-force or credential-stuffing activity. Tune 'threshold' to your environment.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice