Back to results

Delinea - Failed operations

Surfaces every failed, denied, or errored operation across all Delinea Platform services over the lookback window, with no alerting threshold applied. Failures are identified from failed MFA / password factors, any…

Description

Surfaces every failed, denied, or errored operation across all Delinea Platform services over the lookback window, with no alerting threshold applied. Failures are identified from failed MFA / password factors, any login fail reason, or an event name / message containing failed / error / denied / unauthorized. Unlike the 'Failed authentication spike' rule (auth only, above a tuned threshold) this hunting query is service-wide and shows everything, so an analyst can spot scattered authorization failures, repeated errors against a resource, or low-and-slow access attempts.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice