Delinea - Off-hours privileged activity
Surfaces privileged-activity events (Level == "PrivilegedActivity") that occur outside normal business hours - before 'bizStartHourUtc', after 'bizEndHourUtc', or on a weekend - over the lookback window, with no…
Description
Surfaces privileged-activity events (Level == "PrivilegedActivity") that occur outside normal business hours - before 'bizStartHourUtc', after 'bizEndHourUtc', or on a weekend - over the lookback window, with no alerting threshold applied. Privileged operations such as secret access or configuration changes performed at unusual times can indicate a compromised account, an attacker operating in a different time zone, or insider activity outside oversight. Tune the business-hours window (UTC) to your operating region.
Detection logic
Detection requirements
- Platform
- IaaSIdentity ProviderLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 4c68acd6-286e-4f8c-ac4e-606a41984957
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1