Back to results

Delinea - Platform configuration change

Detects state-changing modifications (add / update / delete / enable / disable) to critical Delinea platform settings - authentication profiles and policies, SSO or identity-provider (SAML / OIDC / OAuth /…

Description

Detects state-changing modifications (add / update / delete / enable / disable) to critical Delinea platform settings - authentication profiles and policies, SSO or identity-provider (SAML / OIDC / OAuth / federation) configuration, IP range / restriction rules and webhooks - that the acting user has not performed in the prior 14 days. Configuration tampering is frequently a precursor to defense evasion or persistence; routine changes an administrator makes regularly are baselined out, while a first-ever change still alerts. Matching uses the event name only, not the free-text display message, and produces one alert per actor per run. Tune 'configPattern' to your tenant's event taxonomy, and use 'excludedEventNames', 'excludedServiceTypes' and 'excludedActors' to silence known-benign events, services (for example directory synchronization) and service accounts.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 3 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice