Delinea - Configuration changes
Threshold-free audit trail of state-changing modifications to Delinea platform configuration over the lookback window - authentication profiles, security / access policies, SSO or identity-provider (SAML / OIDC /…
Description
Threshold-free audit trail of state-changing modifications to Delinea platform configuration over the lookback window - authentication profiles, security / access policies, SSO or identity-provider (SAML / OIDC / federation) settings, IP range / restriction rules, integration / webhook / connector settings, and role / permission changes. Read-only "viewed" events are excluded so only add / update / delete / enable / disable actions remain. The matching analytic rule only fires on its own schedule; this query lets an analyst review the full change history and inspect the FieldChanges before/after. Tune 'configPattern' to your tenant's event taxonomy.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 3 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 7adfee87-8c63-4625-a2db-c6971a3233b6
- Tagged by the source as
- DefenseEvasionPersistence
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1