Delinea - Activity by source IP
Summarizes Delinea Platform activity grouped by source IP address over the lookback window, with no alerting threshold applied. For each IP it reports the event count, how many distinct users and services it touched,…
Description
Summarizes Delinea Platform activity grouped by source IP address over the lookback window, with no alerting threshold applied. For each IP it reports the event count, how many distinct users and services it touched, the event-type footprint, and first/last seen. A single IP associated with many distinct accounts can indicate password spraying, a shared NAT / VPN egress, or a compromised host proxying activity; pivot on IPs with an unexpectedly high distinct-user count or originating from unfamiliar networks.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 3185bf9b-29dd-40fa-8477-e2fd4172e3ce
- Tagged by the source as
- DiscoveryInitialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1