Delinea - Failed authentication spike (single account)
Detects when a single account accumulates an unusually high number of failed authentication events within a short window. Only authentication events - MFA, login and sign-in - are considered; the service-wide view of…
Description
Detects when a single account accumulates an unusually high number of failed authentication events within a short window. Only authentication events - MFA, login and sign-in - are considered; the service-wide view of every failure lives in the 'Delinea - Failed operations' hunting query. A failure is a failed MFA result, a failed password factor, or any login fail reason. A burst of failures for one account can indicate brute-force or credential-stuffing activity. Tune 'threshold' to your environment.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- e6d743f2-a538-455f-899c-251926b9071e
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1