Back to results

Delinea - Configuration changes

Threshold-free audit trail of state-changing modifications to Delinea platform configuration over the lookback window - authentication profiles, security / access policies, SSO or identity-provider (SAML / OIDC /…

Description

Threshold-free audit trail of state-changing modifications to Delinea platform configuration over the lookback window - authentication profiles, security / access policies, SSO or identity-provider (SAML / OIDC / federation) settings, IP range / restriction rules, integration / webhook / connector settings, and role / permission changes. Read-only "viewed" events are excluded so only add / update / delete / enable / disable actions remain. The matching analytic rule only fires on its own schedule; this query lets an analyst review the full change history and inspect the FieldChanges before/after. Tune 'configPattern' to your tenant's event taxonomy.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 3 ATT&CK techniques it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice