Observation
Point, contextual, collective, conditional, and residual deviations.
A structured foundation for reasoning about anomaly detection before selecting models, writing rules, or mapping behavior to adversary techniques.
Browse suspicious and malicious activity by MITRE ATT&CK tactic. Every activity includes inline links to the vendor-neutral log sources capable of reporting it.
Open the ATT&CK activity and log-source catalog →Technique-level algorithmic detection logic using exact matches, fixed thresholds, allowlists, state changes, and bounded-window correlations, with direct links to the required telemetry sources.
Open the basic detection rule catalog →The activity-to-anomaly catalog maps ATT&CK-aligned behavior to its comparison unit, expected baseline, measurable deviation, applicable anomaly types, and supporting telemetry. It also identifies activity better handled by signatures or policy rules.
Open the activity-to-anomaly mapping catalog →Point, contextual, collective, conditional, and residual deviations.
Trend, level, variance, periodicity, sequence, and change-point behavior.
Drift, tail, entropy, modality, quantile, and dispersion changes.
Multivariate, graph, relationship, spatial, and cross-view anomalies.
Endpoint and operating systems
Identity and authentication
Network infrastructure and traffic
Applications, APIs, and databases
Cloud, containers, and orchestration
Security controls and observability
Define the baseline. State the population, entity, peer group, context, and time window.
Verify observability. Confirm that a source records the activity and retains the required detail.
Separate rarity from meaning. Statistical deviation is evidence to investigate, not a conclusion.