Delinea - Sensitive secret accessed by new user (first access in 14 days)
Detects when a user accesses a high-value secret for the first time, with no access to that same secret by that user in the prior 14 days. First-time access to a sensitive secret can indicate lateral movement or…
Description
Detects when a user accesses a high-value secret for the first time, with no access to that same secret by that user in the prior 14 days. First-time access to a sensitive secret can indicate lateral movement or credential targeting. Delinea reports no in-band sensitivity flag, so a secret is treated as high-value when its name or its folder matches 'sensitivePattern' (common privileged naming conventions), or when it appears in 'customSecretNames' / 'customFolders'. Both knobs are meant to be edited at deployment time - the pattern for substring matching, the lists for exact tenant-specific names. The folder is read from the notes document, since the platform leaves the top-level target.containerName empty on secret events.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- a7b167e2-9582-440b-8d47-53df2f73c4f4
- Tagged by the source as
- CredentialAccessInitialAccessLateralMovement
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1