Skip to main content

Identity / Access

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

An unexpected authentication property, permission or identity relationship.

Telemetry contract: IdP, factor lifecycle, consent, token-validation and workload audit data where available.

Candidate method [unvalidated until tested]: Separate observed state changes, provider risk detections and inferred anomaly features.

Benign alternatives and limits: Recovery, legitimate consent, role changes and delegated administration require investigation context.

Identity / access anomaly. A synthetic account registers a new MFA factor, receives an elevated role and accesses a protected application. The sequence needs an authorization and recovery-context check; a recorded change alone is not a compromise finding. Recovery and delegated administration can be authorized.
Figure 14. Identity / access anomaly. A synthetic account registers a new MFA factor, receives an elevated role and accesses a protected application. The sequence needs an authorization and recovery-context check; a recorded change alone is not a compromise finding.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Recovery and delegated administration can be authorized.

Recorded changes for one account: new MFA factor, elevated role, protected-application access.

Check whether an approved recovery or role change explains the sequence. Verify the support ticket, actor and device.

Recovery and delegated administration can produce similar records.

Open original full-size asset

Evidence tags: Identity and access · Cloud and SaaS. Statistical forms: contextual, collective.

Browse articles and guides: Identity / Access.

Reported incidents and detection interpretations

UNC3944 help-desk compromise and SaaS data theft​

Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.

Observed [source-reported]: UNC3944 persuaded help desks to change MFA controls and used compromised privileged identities to reach protected applications. Mandiant: UNC3944 Targets SaaS Applications.

Anomaly interpretation [inferred]: Prioritize factor changes followed by unfamiliar access, accounting for the support ticket and strength of identity verification.

Telemetry to validate: IdP factor lifecycle, device enrollment, sign-ins, application assignments and support records.

Boundary / competing explanation: Legitimate device replacement produces similar events; a reset alone does not establish an account takeover.

ATT&CK [author-mapped behavior, not actor attribution]: T1098.005 — Account Manipulation: Device Registration

Storm-0558 forged-token mailbox access​

Period: 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: Storm-0558 used an acquired Microsoft consumer signing key to forge tokens accepted for enterprise mailbox access. Microsoft: Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email.

Anomaly interpretation [inferred]: Correlate mailbox access with identity and token context. Absence of an expected tenant sign-in can be a lead, not proof of token forgery.

Telemetry to validate: Mailbox-access audit, application/session context and provider-side token-validation evidence where available.

Boundary / competing explanation: The key was acquired, not forged. Tenant logs do not necessarily expose the token material or all provider validation decisions.

ATT&CK [author-mapped behavior, not actor attribution]: T1550.001 — Use Alternate Authentication Material: Application Access Token

Crosslinks: Sequence · Graph / Relationship. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.

Illustrative scenarios (not additional incidents):

  • A user who normally authenticates with MFA suddenly registers a new authentication factor and then performs privileged actions within the same session.

  • An employee account that has never approved third-party apps grants OAuth consent to a new application requesting mail read, file access, and offline token permissions.

  • A service principal starts authenticating to new resources or from new workload infrastructure outside its historical pattern. Distinguish application-only token flows from delegated-user refresh-token behavior.

  • A privileged admin account that normally signs in with one managed device starts authenticating with a new device and a newly enrolled MFA method on the same day.

  • A user with stable sign-in behavior suddenly shows unusual token reuse across multiple applications or sessions inconsistent with their normal access pattern.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Valid credentials used from an unexpected context · New local, domain, cloud, or service account · Credential, group, role, or account-property modification · Email forwarding rule created · Cloud secrets, keys, or tokens retrieved · Low-volume failures distributed across many accounts.

Collection references: User Account Authentication · User Account Modification · Web Credential Usage. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.