Identity / Access
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
An unexpected authentication property, permission or identity relationship.
Telemetry contract: IdP, factor lifecycle, consent, token-validation and workload audit data where available.
Candidate method [unvalidated until tested]: Separate observed state changes, provider risk detections and inferred anomaly features.
Benign alternatives and limits: Recovery, legitimate consent, role changes and delegated administration require investigation context.

Text equivalent and full-size diagram
Recovery and delegated administration can be authorized.
Recorded changes for one account: new MFA factor, elevated role, protected-application access.
Check whether an approved recovery or role change explains the sequence. Verify the support ticket, actor and device.
Recovery and delegated administration can produce similar records.
Evidence tags: Identity and access · Cloud and SaaS. Statistical forms: contextual, collective.
Browse articles and guides: Identity / Access.
Reported incidents and detection interpretations
UNC3944 help-desk compromise and SaaS data theft
Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.
Observed [source-reported]: UNC3944 persuaded help desks to change MFA controls and used compromised privileged identities to reach protected applications. Mandiant: UNC3944 Targets SaaS Applications.
Anomaly interpretation [inferred]: Prioritize factor changes followed by unfamiliar access, accounting for the support ticket and strength of identity verification.
Telemetry to validate: IdP factor lifecycle, device enrollment, sign-ins, application assignments and support records.
Boundary / competing explanation: Legitimate device replacement produces similar events; a reset alone does not establish an account takeover.
ATT&CK [author-mapped behavior, not actor attribution]: T1098.005 — Account Manipulation: Device Registration
Storm-0558 forged-token mailbox access
Period: 2023. Evidence: campaign reported by the cited source.
Observed [source-reported]: Storm-0558 used an acquired Microsoft consumer signing key to forge tokens accepted for enterprise mailbox access. Microsoft: Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email.
Anomaly interpretation [inferred]: Correlate mailbox access with identity and token context. Absence of an expected tenant sign-in can be a lead, not proof of token forgery.
Telemetry to validate: Mailbox-access audit, application/session context and provider-side token-validation evidence where available.
Boundary / competing explanation: The key was acquired, not forged. Tenant logs do not necessarily expose the token material or all provider validation decisions.
ATT&CK [author-mapped behavior, not actor attribution]: T1550.001 — Use Alternate Authentication Material: Application Access Token
Crosslinks: Sequence · Graph / Relationship. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.
Illustrative scenarios (not additional incidents):
-
A user who normally authenticates with MFA suddenly registers a new authentication factor and then performs privileged actions within the same session.
-
An employee account that has never approved third-party apps grants OAuth consent to a new application requesting mail read, file access, and offline token permissions.
-
A service principal starts authenticating to new resources or from new workload infrastructure outside its historical pattern. Distinguish application-only token flows from delegated-user refresh-token behavior.
-
A privileged admin account that normally signs in with one managed device starts authenticating with a new device and a newly enrolled MFA method on the same day.
-
A user with stable sign-in behavior suddenly shows unusual token reuse across multiple applications or sessions inconsistent with their normal access pattern.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Valid credentials used from an unexpected context · New local, domain, cloud, or service account · Credential, group, role, or account-property modification · Email forwarding rule created · Cloud secrets, keys, or tokens retrieved · Low-volume failures distributed across many accounts.
Collection references: User Account Authentication · User Account Modification · Web Credential Usage. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.