Back to results

Delinea - Authentication failures ranked by account

Surfaces every account with failed authentication activity over the lookback window, ranked by failure count and distinct source IPs - with no alerting threshold applied. The 'Failed authentication spike' analytic…

Description

Surfaces every account with failed authentication activity over the lookback window, ranked by failure count and distinct source IPs - with no alerting threshold applied. The 'Failed authentication spike' analytic rule only fires above a tuned threshold (e.g. 10 in 15m); this hunting query deliberately shows everything below that line so an analyst can spot low-and-slow brute-force or credential-stuffing that stays under the radar. Scoped to authentication events to match that rule; for failures across every service use 'Delinea - Failed operations'. Pivot on accounts with many failures from several IPs, or a single IP hitting many accounts (password spraying).

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice