Negative Anomaly (Absence)
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
An expected observation is absent during a period where it should be observable.
Telemetry contract: Independent collector health, source heartbeat, delivery status, asset state and expected workload.
Candidate method [unvalidated until tested]: Model expected presence and detection delay separately from actual zero activity.
Benign alternatives and limits: Outage, retirement, filtering, permissions and retention are alternatives to deliberate impairment.

Text equivalent and full-size diagram
An outage or parser failure can look like deliberate impairment.
The example expects one heartbeat every five minutes. Reports were received at minutes 0, 5 and 10; reports expected at 15, 20 and 25 are not observed.
Assessment occurs at minute 28 with a two-minute delivery allowance, so the three example deadlines were 17, 22 and 27. An independent host monitor still reports the server online.
Check the expected-asset roster, source and collector health, delivery delays, filters and retention. Missing telemetry is unknown, not evidence of zero activity or automatically a benign state.
Evidence tags: Cloud and SaaS · Endpoint telemetry · Telemetry health. Statistical forms: contextual, collective.
Browse articles and guides: Negative Anomaly (Absence).
Reported incidents and detection interpretations
SCARLETEEL cloud intrusion
Period: 2023 reporting. Evidence: incident reported by the cited source.
Observed [source-reported]: Sysdig reported attackers disabling CloudTrail logging during SCARLETEEL and described StopLogging-based detection. Sysdig: How to Detect SCARLETEEL with Sysdig Secure.
Anomaly interpretation [inferred]: Combine an explicit logging change with loss of an otherwise expected event stream. Monitor the collection path independently of the source being disabled.
Telemetry to validate: CloudTrail control-plane changes, trail configuration, delivery health and downstream ingestion counters.
Boundary / competing explanation: StopLogging is a positive state-change event; missing logs are a separate inferred signal. Outages and configuration changes are competing explanations.
ATT&CK [author-mapped behavior, not actor attribution]: T1685.002 — Disable or Modify Tools: Disable or Modify Cloud Log
AuKill use before ransomware deployment
Period: January–February 2023 incidents. Evidence: incident series reported by the cited source.
Observed [source-reported]: Sophos investigated ransomware incidents where AuKill abused a Process Explorer driver to disable EDR processes before payload deployment. Sophos: AuKill EDR killer malware abuses Process Explorer driver.
Anomaly interpretation [inferred]: Correlate unexpected security-service loss with driver installation and other independent host activity. A running host with a silent agent deserves investigation.
Telemetry to validate: EDR health, service state, driver-load events and independent management/network heartbeats.
Boundary / competing explanation: The source documents defense impairment, not a demonstrated heartbeat detector. Agent maintenance and host shutdown must be distinguished.
ATT&CK [author-mapped behavior, not actor attribution]: T1685 — Disable or Modify Tools
Crosslinks: State-Change · Temporal. Statistical foundation in the Anomaly Detection Atlas. Related research: Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry.
Illustrative scenarios (not additional incidents):
-
An EDR agent on a critical server that normally checks in every few minutes stops reporting immediately before suspicious outbound activity begins.
-
A domain controller that consistently produces Windows security events suddenly goes silent, with no expected authentication logs during business hours.
-
A Linux host that normally sends steady
auditdrecords stops emitting process and file-access telemetry after a privileged session starts. -
A firewall or proxy log source with a stable event stream abruptly drops to near zero, even though the protected segment remains active.
-
A backup service process that is normally always present on a server is no longer running, followed by unexpected file encryption or deletion activity.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Security tool, sensor, or logging disabled · File timestamps, metadata, logs, or indicators modified · Backup, snapshot, or recovery capability impaired.
Collection references: Host Status · Cloud Service Disable · Cloud Service Modification. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.