Skip to main content

Negative Anomaly (Absence)

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

An expected observation is absent during a period where it should be observable.

Telemetry contract: Independent collector health, source heartbeat, delivery status, asset state and expected workload.

Candidate method [unvalidated until tested]: Model expected presence and detection delay separately from actual zero activity.

Benign alternatives and limits: Outage, retirement, filtering, permissions and retention are alternatives to deliberate impairment.

Negative / absence anomaly. Synthetic heartbeat schedule: reports at minutes 0, 5 and 10, then none observed at 15, 20 or 25. At minute 28, each missing report is beyond the illustrative two-minute delivery allowance. These assumed timings are not a universal alert threshold or proof of sensor tampering. An outage or parser failure can look like deliberate impairment.
Figure 19. Negative / absence anomaly. Synthetic heartbeat schedule: reports at minutes 0, 5 and 10, then none observed at 15, 20 or 25. At minute 28, each missing report is beyond the illustrative two-minute delivery allowance. These assumed timings are not a universal alert threshold or proof of sensor tampering.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

An outage or parser failure can look like deliberate impairment.

The example expects one heartbeat every five minutes. Reports were received at minutes 0, 5 and 10; reports expected at 15, 20 and 25 are not observed.

Assessment occurs at minute 28 with a two-minute delivery allowance, so the three example deadlines were 17, 22 and 27. An independent host monitor still reports the server online.

Check the expected-asset roster, source and collector health, delivery delays, filters and retention. Missing telemetry is unknown, not evidence of zero activity or automatically a benign state.

Open original full-size asset

Evidence tags: Cloud and SaaS · Endpoint telemetry · Telemetry health. Statistical forms: contextual, collective.

Browse articles and guides: Negative Anomaly (Absence).

Reported incidents and detection interpretations

SCARLETEEL cloud intrusion​

Period: 2023 reporting. Evidence: incident reported by the cited source.

Observed [source-reported]: Sysdig reported attackers disabling CloudTrail logging during SCARLETEEL and described StopLogging-based detection. Sysdig: How to Detect SCARLETEEL with Sysdig Secure.

Anomaly interpretation [inferred]: Combine an explicit logging change with loss of an otherwise expected event stream. Monitor the collection path independently of the source being disabled.

Telemetry to validate: CloudTrail control-plane changes, trail configuration, delivery health and downstream ingestion counters.

Boundary / competing explanation: StopLogging is a positive state-change event; missing logs are a separate inferred signal. Outages and configuration changes are competing explanations.

ATT&CK [author-mapped behavior, not actor attribution]: T1685.002 — Disable or Modify Tools: Disable or Modify Cloud Log

AuKill use before ransomware deployment​

Period: January–February 2023 incidents. Evidence: incident series reported by the cited source.

Observed [source-reported]: Sophos investigated ransomware incidents where AuKill abused a Process Explorer driver to disable EDR processes before payload deployment. Sophos: AuKill EDR killer malware abuses Process Explorer driver.

Anomaly interpretation [inferred]: Correlate unexpected security-service loss with driver installation and other independent host activity. A running host with a silent agent deserves investigation.

Telemetry to validate: EDR health, service state, driver-load events and independent management/network heartbeats.

Boundary / competing explanation: The source documents defense impairment, not a demonstrated heartbeat detector. Agent maintenance and host shutdown must be distinguished.

ATT&CK [author-mapped behavior, not actor attribution]: T1685 — Disable or Modify Tools

Crosslinks: State-Change · Temporal. Statistical foundation in the Anomaly Detection Atlas. Related research: Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry.

Illustrative scenarios (not additional incidents):

  • An EDR agent on a critical server that normally checks in every few minutes stops reporting immediately before suspicious outbound activity begins.

  • A domain controller that consistently produces Windows security events suddenly goes silent, with no expected authentication logs during business hours.

  • A Linux host that normally sends steady auditd records stops emitting process and file-access telemetry after a privileged session starts.

  • A firewall or proxy log source with a stable event stream abruptly drops to near zero, even though the protected segment remains active.

  • A backup service process that is normally always present on a server is no longer running, followed by unexpected file encryption or deletion activity.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Security tool, sensor, or logging disabled · File timestamps, metadata, logs, or indicators modified · Backup, snapshot, or recovery capability impaired.

Collection references: Host Status · Cloud Service Disable · Cloud Service Modification. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.