Back to results

Delinea - Privilege escalation detected (role / permission changes)

Detects role assignments, permission or right grants, admin grants and elevation events that the acting user has not performed against the same target in the prior 14 days. Only grant-type actions (added / assigned /…

Description

Detects role assignments, permission or right grants, admin grants and elevation events that the acting user has not performed against the same target in the prior 14 days. Only grant-type actions (added / assigned / granted / elevated / approved / created / updated) against role, permission, privilege, admin or entitlement objects are considered; removals and read-only events are excluded, and plain group-membership or ownership events are not matched because they make up most routine directory activity. One alert is produced per actor per run - review the FieldChanges column for the before/after of each change. Tune 'escalationObjects' and 'grantVerbs' to your tenant's event taxonomy, and use 'excludedEventNames', 'excludedServiceTypes' and 'excludedActors' to silence known-benign events, services (for example directory synchronization) and service accounts.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice