Back to results

Delinea - Sensitive secret accessed by new user (first access in 14 days)

Detects when a user accesses a high-value secret for the first time, with no access to that same secret by that user in the prior 14 days. First-time access to a sensitive secret can indicate lateral movement or…

Description

Detects when a user accesses a high-value secret for the first time, with no access to that same secret by that user in the prior 14 days. First-time access to a sensitive secret can indicate lateral movement or credential targeting. Delinea reports no in-band sensitivity flag, so a secret is treated as high-value when its name or its folder matches 'sensitivePattern' (common privileged naming conventions), or when it appears in 'customSecretNames' / 'customFolders'. Both knobs are meant to be edited at deployment time - the pattern for substring matching, the lists for exact tenant-specific names. The folder is read from the notes document, since the platform leaves the top-level target.containerName empty on secret events.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice