Graph / Relationship
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
A new or unusual edge, path or community relationship.
Telemetry contract: Verified identities, effective permissions, resource ownership, authentication and network observations.
Candidate method [unvalidated until tested]: Define graph direction, edge meaning, observation window and novelty against a past-only graph.
Benign alternatives and limits: Migrations, new projects and automated infrastructure can legitimately create many edges.

Text equivalent and full-size diagram
Projects and migrations create legitimate edges; novelty is not attribution.
One service identity has an established permission relationship with Application A and a newly observed grant to an administrative resource.
Edges point from the identity to the resource and represent permission, not network traffic or successful access.
Compare against a past-only graph. Migrations and new projects can explain new edges; verify use separately.
Evidence tags: Identity and access · Cloud and SaaS. Statistical forms: contextual, collective.
Browse articles and guides: Graph / Relationship.
Reported incidents and detection interpretations
Midnight Blizzard compromise of Microsoft
Period: Reported January 2024. Evidence: incident reported by the cited source.
Observed [source-reported]: Microsoft described a compromised legacy OAuth application being used to grant malicious applications Exchange full_access_as_app access. Microsoft: Midnight Blizzard: Guidance for responders on nation-state attack.
Anomaly interpretation [inferred]: Model principal, application, consent and mailbox-access edges. Investigate a new privileged path rather than treating each grant as an isolated event.
Telemetry to validate: Application credentials, consent and role-assignment audit history; EWS access.
Boundary / competing explanation: A new graph edge is not proof of abuse, and the report does not establish that graph analytics detected the intrusion.
ATT&CK [author-mapped behavior, not actor attribution]: T1098 — Account Manipulation
Storm-1283 OAuth-enabled cryptomining
Period: Reported December 2023. Evidence: campaign reported by the cited source.
Observed [source-reported]: The compromised subscription owner granted the attacker-created application Contributor permissions, enabling subsequent VM deployment. Microsoft: Threat actors misuse OAuth applications to automate financially driven attacks.
Anomaly interpretation [inferred]: Trace the new user-to-application-to-subscription path and its first resource actions. Link authorization changes to what the newly authorized principal actually did.
Telemetry to validate: Directory audit, Azure role assignments and resource deployment activity.
Boundary / competing explanation: Infrastructure-as-code can produce similar edges; compare ownership, approval and expected resource scope.
ATT&CK [author-mapped behavior, not actor attribution]: T1098 — Account Manipulation
Crosslinks: State-Change · Identity / Access. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.
Illustrative scenarios (not additional incidents):
-
A low-privilege user is suddenly added to a group that creates a new privilege path to domain admin through nested Active Directory memberships.
-
An IAM role that normally accesses only one application is granted trust relationships that connect it to multiple high-value cloud resources it never touched before.
-
A workstation begins communicating with a server segment that is normally reachable only by backup or management systems, creating a new network edge outside its usual community.
-
A SaaS account that historically had no relationship to executive mailboxes suddenly gains delegated access to several senior leadership accounts.
-
A service account becomes the bridge between two previously separate environments by authenticating to both the on-prem domain and cloud admin plane, creating an unusual cross-environment path.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Credential, group, role, or account-property modification · Remote administrative service used between systems · Process injection or in-memory execution · Accounts, groups, roles, or permissions enumerated.
Collection references: Active Directory Object Modification · Logon Session Creation · Network Connection Creation. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.