Frequency / Rate
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
Unusual event frequency per entity and unit of observed time.
Telemetry contract: Authentication, API, process or DNS events, with collection completeness and event deduplication.
Candidate method [unvalidated until tested]: Measure count, duration, source diversity and target breadth. Check dispersion and seasonality before choosing a Poisson model.
Benign alternatives and limits: Retries, outages, load tests and shared gateways can resemble an attack burst.

Text equivalent and full-size diagram
Retries, polling and releases can create bursts; sparse attacks may not.
M1: 3; M2: 2; M3: 3; M4: 4; M5: 3; M6: 24 requests per observed minute.
Deduplicate events and verify observation time. Retries, outages and load tests can create benign bursts.
Count occurrences and state the time denominator.
Evidence tags: Identity and access · Network telemetry. Statistical forms: collective.
Browse articles and guides: Frequency / Rate.
Reported incidents and detection interpretations
HTTP/2 Rapid Reset DDoS campaign
Period: August 2023. Evidence: campaign reported by the cited source.
Observed [source-reported]: The HTTP/2 campaign repeatedly opened and reset streams, letting relatively few connections generate exceptional request rates. Cloudflare: HTTP/2 Rapid Reset: deconstructing the record-breaking attack.
Anomaly interpretation [inferred]: Measure stream creation and cancellation per connection and per target, not just source-IP counts. Distribution shape complements aggregate rate.
Telemetry to validate: HTTP/2-aware edge telemetry, reset counters and time-aligned request rates.
Boundary / competing explanation: Ordinary access logs may not expose frame-level resets; encrypted packet metadata alone is insufficient for this feature.
ATT&CK [author-mapped behavior, not actor attribution]: T1499 — Endpoint Denial of Service
Midnight Blizzard compromise of Microsoft
Period: Reported January 2024. Evidence: incident reported by the cited source.
Observed [source-reported]: Microsoft described low-count password attempts against selected accounts through distributed residential proxies. Microsoft: Midnight Blizzard: Guidance for responders on nation-state attack.
Anomaly interpretation [inferred]: This is an evasion case for simple rate thresholds. Aggregate repeated targeting across sources, retaining the affected identities and observation window.
Telemetry to validate: Identity sign-in results, account IDs, source networks and provider risk signals.
Boundary / competing explanation: Do not claim that every tenant-local detector must fail or that unrelated successful logins prove compromise.
ATT&CK [author-mapped behavior, not actor attribution]: T1110.003 — Brute Force: Password Spraying
Crosslinks: Volumetric · Geographic / ASN. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.
Illustrative scenarios (not additional incidents):
-
A single user account generates 45 failed VPN logins in 6 minutes, far above its normal authentication rate.
-
One API client that typically makes 2–3 requests per minute suddenly sends 1,200 token validation requests in 10 minutes.
-
A workstation that usually launches a browser a few times per hour suddenly starts 300 PowerShell processes in 15 minutes.
-
A host that normally performs low-volume name resolution suddenly issues hundreds of DNS queries per minute to many rare domains.
-
A service account that usually accesses one mailbox at a time suddenly performs repeated read operations across dozens of mailboxes in a short window.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Repeated password guessing against an account · Low-volume failures distributed across many accounts · Repeated MFA prompts and denials · Repeated probing of public services · Internal network services or systems scanned.
Collection references: User Account Authentication · Network Connection Creation · Active Directory Credential Request. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.