Delinea - Rare / first-seen event types
Identifies Delinea Platform event types that appear in the recent window but were never seen during the preceding baseline period, using a leftanti join against the baseline set - with no alerting threshold applied.…
Description
Identifies Delinea Platform event types that appear in the recent window but were never seen during the preceding baseline period, using a leftanti join against the baseline set - with no alerting threshold applied. A brand-new event type can signal a newly enabled feature, a configuration change, or an attacker exercising functionality the environment does not normally use. Pivot on the users and source IPs associated with each first-seen event type to decide whether it is benign. Tune 'baseline' and 'recent' to your environment.
Detection logic
Detection requirements
- Platform
- ESXiIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 634f4212-76e3-485e-a6cc-5b1929476ef8
- Tagged by the source as
- Discovery
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1