Delinea - Privileged account access anomaly (secret-access volume vs baseline)
Detects when a user's secret-access volume for the current day significantly exceeds their own recent baseline (per-user daily average plus a standard-deviation factor over the prior ~14 days). A sudden spike…
Description
Detects when a user's secret-access volume for the current day significantly exceeds their own recent baseline (per-user daily average plus a standard-deviation factor over the prior ~14 days). A sudden spike relative to a principal's normal behaviour can indicate a compromised privileged account or insider misuse. Tune 'factor' and 'minDaily' to balance noise against coverage.
Detection logic
Detection requirements
- Platform
- IaaSIdentity ProviderLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- e1bfca9b-7980-469f-a57c-16e81451861b
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1