Back to results

Delinea - Activity by source IP

Summarizes Delinea Platform activity grouped by source IP address over the lookback window, with no alerting threshold applied. For each IP it reports the event count, how many distinct users and services it touched,…

Description

Summarizes Delinea Platform activity grouped by source IP address over the lookback window, with no alerting threshold applied. For each IP it reports the event count, how many distinct users and services it touched, the event-type footprint, and first/last seen. A single IP associated with many distinct accounts can indicate password spraying, a shared NAT / VPN egress, or a compromised host proxying activity; pivot on IPs with an unexpectedly high distinct-user count or originating from unfamiliar networks.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice