Delinea - Authentication failures ranked by account
Surfaces every account with failed authentication activity over the lookback window, ranked by failure count and distinct source IPs - with no alerting threshold applied. The 'Failed authentication spike' analytic…
Description
Surfaces every account with failed authentication activity over the lookback window, ranked by failure count and distinct source IPs - with no alerting threshold applied. The 'Failed authentication spike' analytic rule only fires above a tuned threshold (e.g. 10 in 15m); this hunting query deliberately shows everything below that line so an analyst can spot low-and-slow brute-force or credential-stuffing that stays under the radar. Scoped to authentication events to match that rule; for failures across every service use 'Delinea - Failed operations'. Pivot on accounts with many failures from several IPs, or a single IP hitting many accounts (password spraying).
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 9ecbc6e0-e40d-4fa3-8d6a-2652418f9c77
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1