Delinea - Failed operations
Surfaces every failed, denied, or errored operation across all Delinea Platform services over the lookback window, with no alerting threshold applied. Failures are identified from failed MFA / password factors, any…
Description
Surfaces every failed, denied, or errored operation across all Delinea Platform services over the lookback window, with no alerting threshold applied. Failures are identified from failed MFA / password factors, any login fail reason, or an event name / message containing failed / error / denied / unauthorized. Unlike the 'Failed authentication spike' rule (auth only, above a tuned threshold) this hunting query is service-wide and shows everything, so an analyst can spot scattered authorization failures, repeated errors against a resource, or low-and-slow access attempts.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 29231a10-e272-4854-b191-a2d2db4279fa
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1