Skip to main content

Graph / Relationship

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

A new or unusual edge, path or community relationship.

Telemetry contract: Verified identities, effective permissions, resource ownership, authentication and network observations.

Candidate method [unvalidated until tested]: Define graph direction, edge meaning, observation window and novelty against a past-only graph.

Benign alternatives and limits: Migrations, new projects and automated infrastructure can legitimately create many edges.

Graph / relationship anomaly. The synthetic graph adds a permission edge from a service identity to an administrative resource. Its established Application A relationship is also a permission edge; neither arrow proves actual resource use. Projects and migrations create legitimate edges; novelty is not attribution.
Figure 12. Graph / relationship anomaly. The synthetic graph adds a permission edge from a service identity to an administrative resource. Its established Application A relationship is also a permission edge; neither arrow proves actual resource use.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Projects and migrations create legitimate edges; novelty is not attribution.

One service identity has an established permission relationship with Application A and a newly observed grant to an administrative resource.

Edges point from the identity to the resource and represent permission, not network traffic or successful access.

Compare against a past-only graph. Migrations and new projects can explain new edges; verify use separately.

Open original full-size asset

Evidence tags: Identity and access · Cloud and SaaS. Statistical forms: contextual, collective.

Browse articles and guides: Graph / Relationship.

Reported incidents and detection interpretations

Midnight Blizzard compromise of Microsoft​

Period: Reported January 2024. Evidence: incident reported by the cited source.

Observed [source-reported]: Microsoft described a compromised legacy OAuth application being used to grant malicious applications Exchange full_access_as_app access. Microsoft: Midnight Blizzard: Guidance for responders on nation-state attack.

Anomaly interpretation [inferred]: Model principal, application, consent and mailbox-access edges. Investigate a new privileged path rather than treating each grant as an isolated event.

Telemetry to validate: Application credentials, consent and role-assignment audit history; EWS access.

Boundary / competing explanation: A new graph edge is not proof of abuse, and the report does not establish that graph analytics detected the intrusion.

ATT&CK [author-mapped behavior, not actor attribution]: T1098 — Account Manipulation

Storm-1283 OAuth-enabled cryptomining​

Period: Reported December 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: The compromised subscription owner granted the attacker-created application Contributor permissions, enabling subsequent VM deployment. Microsoft: Threat actors misuse OAuth applications to automate financially driven attacks.

Anomaly interpretation [inferred]: Trace the new user-to-application-to-subscription path and its first resource actions. Link authorization changes to what the newly authorized principal actually did.

Telemetry to validate: Directory audit, Azure role assignments and resource deployment activity.

Boundary / competing explanation: Infrastructure-as-code can produce similar edges; compare ownership, approval and expected resource scope.

ATT&CK [author-mapped behavior, not actor attribution]: T1098 — Account Manipulation

Crosslinks: State-Change · Identity / Access. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.

Illustrative scenarios (not additional incidents):

  • A low-privilege user is suddenly added to a group that creates a new privilege path to domain admin through nested Active Directory memberships.

  • An IAM role that normally accesses only one application is granted trust relationships that connect it to multiple high-value cloud resources it never touched before.

  • A workstation begins communicating with a server segment that is normally reachable only by backup or management systems, creating a new network edge outside its usual community.

  • A SaaS account that historically had no relationship to executive mailboxes suddenly gains delegated access to several senior leadership accounts.

  • A service account becomes the bridge between two previously separate environments by authenticating to both the on-prem domain and cloud admin plane, creating an unusual cross-environment path.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Credential, group, role, or account-property modification · Remote administrative service used between systems · Process injection or in-memory execution · Accounts, groups, roles, or permissions enumerated.

Collection references: Active Directory Object Modification · Logon Session Creation · Network Connection Creation. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.