Delinea - All events by user
Summarizes every Delinea Platform audit event over the lookback window grouped by the acting user, with no alerting threshold applied. Gives an analyst a single per-principal activity baseline - total events, which…
Description
Summarizes every Delinea Platform audit event over the lookback window grouped by the acting user, with no alerting threshold applied. Gives an analyst a single per-principal activity baseline - total events, which services and event types each user touched, how many distinct source IPs they came from, and their first/last activity in range. Pivot on users with an unusually broad event-type or source-IP footprint, or use it as the starting point for a deeper per-user investigation.
Detection logic
Detection requirements
- Platform
- ESXiIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 206c0df6-a756-48a8-9c69-8a0815682327
- Tagged by the source as
- Discovery
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1