Back to results

Delinea - All events by user

Summarizes every Delinea Platform audit event over the lookback window grouped by the acting user, with no alerting threshold applied. Gives an analyst a single per-principal activity baseline - total events, which…

Description

Summarizes every Delinea Platform audit event over the lookback window grouped by the acting user, with no alerting threshold applied. Gives an analyst a single per-principal activity baseline - total events, which services and event types each user touched, how many distinct source IPs they came from, and their first/last activity in range. Pivot on users with an unusually broad event-type or source-IP footprint, or use it as the starting point for a deeper per-user investigation.

Detection logic

Detection requirements

Platform
ESXiIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice