Delinea - Privilege escalation detected (role / permission changes)
Detects role assignments, permission or right grants, admin grants and elevation events that the acting user has not performed against the same target in the prior 14 days. Only grant-type actions (added / assigned /…
Description
Detects role assignments, permission or right grants, admin grants and elevation events that the acting user has not performed against the same target in the prior 14 days. Only grant-type actions (added / assigned / granted / elevated / approved / created / updated) against role, permission, privilege, admin or entitlement objects are considered; removals and read-only events are excluded, and plain group-membership or ownership events are not matched because they make up most routine directory activity. One alert is produced per actor per run - review the FieldChanges column for the before/after of each change. Tune 'escalationObjects' and 'grantVerbs' to your tenant's event taxonomy, and use 'excludedEventNames', 'excludedServiceTypes' and 'excludedActors' to silence known-benign events, services (for example directory synchronization) and service accounts.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- c24252d1-d98c-48db-b2f9-4cb37dd2208a
- Tagged by the source as
- PersistencePrivilegeEscalation
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1