Delinea - Platform configuration change
Detects state-changing modifications (add / update / delete / enable / disable) to critical Delinea platform settings - authentication profiles and policies, SSO or identity-provider (SAML / OIDC / OAuth /…
Description
Detects state-changing modifications (add / update / delete / enable / disable) to critical Delinea platform settings - authentication profiles and policies, SSO or identity-provider (SAML / OIDC / OAuth / federation) configuration, IP range / restriction rules and webhooks - that the acting user has not performed in the prior 14 days. Configuration tampering is frequently a precursor to defense evasion or persistence; routine changes an administrator makes regularly are baselined out, while a first-ever change still alerts. Matching uses the event name only, not the free-text display message, and produces one alert per actor per run. Tune 'configPattern' to your tenant's event taxonomy, and use 'excludedEventNames', 'excludedServiceTypes' and 'excludedActors' to silence known-benign events, services (for example directory synchronization) and service accounts.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 3 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 7c07194a-8eda-4cb7-9bc4-cd4700eb4c4d
- Tagged by the source as
- DefenseEvasionPersistence
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1