Delinea - Secret access audit trail
Chronological, per-event audit trail of every Delinea Secret Server secret operation over the lookback window - views, exports, downloads, retrievals, copies, edits and deletes - with no alerting threshold applied.…
Description
Chronological, per-event audit trail of every Delinea Secret Server secret operation over the lookback window - views, exports, downloads, retrievals, copies, edits and deletes - with no alerting threshold applied. Each row records who performed the action, which secret, the derived action verb, the source IP, and the original message. Unlike the 'Secret access fan-out' query (aggregated per user) this is the raw event-by-event trail, ideal for reconstructing exactly what happened to a given secret or what a user did during an incident window.
Detection logic
Detection requirements
- Platform
- IaaSIdentity ProviderLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 51a82b60-4225-49ab-8fc6-c6381fa0f52c
- Tagged by the source as
- CredentialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1