Back to results

Delinea - Privileged account access anomaly (secret-access volume vs baseline)

Detects when a user's secret-access volume for the current day significantly exceeds their own recent baseline (per-user daily average plus a standard-deviation factor over the prior ~14 days). A sudden spike…

Description

Detects when a user's secret-access volume for the current day significantly exceeds their own recent baseline (per-user daily average plus a standard-deviation factor over the prior ~14 days). A sudden spike relative to a principal's normal behaviour can indicate a compromised privileged account or insider misuse. Tune 'factor' and 'minDaily' to balance noise against coverage.

Detection logic

Detection requirements

Platform
IaaSIdentity ProviderLinuxmacOSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice