Multi-Event Correlation
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
A composition method joining related evidence, not a fifteenth independent statistical family.
Telemetry contract: Cross-source events with reliable tenant, identity, asset, session and time keys.
Candidate method [unvalidated until tested]: Specify equality keys and temporal constraints; measure the recall cost of each added gate.
Benign alternatives and limits: Unrelated events, duplicate observations and correlated models can inflate confidence without adding independent evidence.

Text equivalent and full-size diagram
Adding a gate can remove true positives as well as false positives.
Identity audit reports a new factor registration, application audit a new privileged session, and storage audit an unusual export destination.
Check matching tenant and account, verified session or asset links, and allowed event order and gaps. Preserve unresolved links rather than inventing a chain.
Deduplicate shared evidence and reject ambiguous joins. Measure how added gates change false alerts and missed attacks; do not add uncalibrated scores. The output is an investigation candidate, not a verdict.
Evidence tags: Identity and access · Endpoint telemetry · Cloud and SaaS. Statistical forms: collective, contextual.
Browse articles and guides: Multi-Event Correlation.
Reported incidents and detection interpretations
UNC3944 help-desk compromise and SaaS data theft
Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.
Observed [source-reported]: Mandiant reported identity manipulation, privileged SaaS access and cloud connector use for data theft across UNC3944 investigations. Mandiant: UNC3944 Targets SaaS Applications.
Anomaly interpretation [inferred]: Join identity-control changes to application sessions and connector transfers where entity and timestamp evidence supports the link. Correlation combines signal families; ordered sequence analysis is one possible component.
Telemetry to validate: Support records, IdP factor events, application sessions, connector jobs and destination ownership.
Boundary / competing explanation: A campaign synthesis is not one victim's complete timeline. Do not merge unrelated users or tenants because their events share a time window.
ATT&CK [author-mapped behavior, not actor attribution]: T1098.005 — Account Manipulation: Device Registration; T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage
BazarCall to Conti intrusion
Period: 2021 case reported on 1 August. Evidence: incident reported by the cited source.
Observed [source-reported]: The DFIR Report documented an intrusion progressing from initial execution through discovery and lateral activity to Conti ransomware deployment. The DFIR Report: BazarCall to Conti Ransomware via Trickbot and Cobalt Strike.
Anomaly interpretation [inferred]: Correlate endpoint execution, discovery and remote-service activity using stable host and account identifiers. Evaluate the linked evidence, not an uncalibrated sum of anomaly scores.
Telemetry to validate: Process trees, authenticated sessions, service events and network connections, with collection delays recorded.
Boundary / competing explanation: Two alerts generated from the same event are not independent corroboration. Missing sensors can break the join without making the behavior benign.
ATT&CK [author-mapped behavior, not actor attribution]: T1087.002 — Account Discovery: Domain Account
Crosslinks: Sequence · State-Change · Data Movement. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.
Illustrative scenarios (not additional incidents):
-
A user shows a new login location, registers a new MFA factor, and then downloads an unusually large number of files in the same session.
-
A workstation triggers a rare parent-child process chain, connects to a newly observed external domain, and then starts compressing many files within 20 minutes.
-
A cloud admin account performs a first-time role assumption, changes bucket permissions, and initiates bulk object access shortly afterward.
-
A mailbox account creates a forwarding rule, shows unusual sign-in properties, and then performs repeated message access and deletion activity.
-
A server begins executing a rare binary, stops sending normal EDR heartbeats, and then generates abnormal outbound traffic to an external IP.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: User opens delivered content followed by execution · Process injection or in-memory execution · Tool or payload transferred internally · Unusual service-ticket requests · Encoded, packed, or obfuscated content.
Collection references: Process Creation · Logon Session Creation · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.