Delinea - Bulk secret export / access
Detects a single user accessing or exporting an unusually large number of distinct secrets in Delinea Secret Server within a short window. In addition to secret views, this rule also matches export / download /…
Description
Detects a single user accessing or exporting an unusually large number of distinct secrets in Delinea Secret Server within a short window. In addition to secret views, this rule also matches export / download / retrieve operations, which are a stronger signal of vault scraping prior to exfiltration ("secret hoarding"). Tune 'threshold' to your environment's normal access patterns.
Detection logic
Detection requirements
- Platform
- IaaSIdentity ProviderLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 7ab54aed-f97e-4202-a624-3cbd496c3b68
- Tagged by the source as
- CredentialAccessExfiltration
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1