Peer-Group
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
An entity differs from an explicitly defined comparison cohort.
Telemetry contract: Identity and asset inventory, role history, application use and access records.
Candidate method [unvalidated until tested]: Validate cohort membership, then compare distributions or fit a clustering model. TF-IDF can weight input features; it is not clustering itself.
Benign alternatives and limits: Role changes, small cohorts and incomplete personnel data can create misleading outliers.

Text equivalent and full-size diagram
Small cohorts and incomplete inventory can manufacture an outlier.
Employees A, B and C: finance application and CRM. Employee D: the same two resources plus a code repository.
Verify duties and cohort membership. A temporary project or legitimate role change may explain the difference.
Compare like with like and validate the cohort first.
Evidence tags: Identity and access · Insider risk · Cloud and SaaS. Statistical forms: contextual.
Browse articles and guides: Peer-Group.
Reported incidents and detection interpretations
Twitter insider access for a foreign official
Period: Conduct addressed in the 2022 Abouammo conviction. Evidence: incident reported by the cited source.
Observed [source-reported]: A jury convicted former Twitter media-partnerships manager Ahmad Abouammo over unlawful access and disclosure of user information. The indictment explains the job-duty boundary. US Department of Justice: Former Twitter Employee Found Guilty of Acting as an Agent of a Foreign Government and Unlawfully Sharing Twitter User Information; US Department of Justice: Superseding indictment, United States v. Abouammo et al., filed July 28, 2020.
Anomaly interpretation [inferred]: Compare sensitive-record access with employees having the same responsibilities, not with all staff who technically possess access.
Telemetry to validate: Internal user-data access logs, role assignments, case authorization and HR role history.
Boundary / competing explanation: Peer-group detection is an author-derived opportunity; the sources do not say a UEBA model discovered this case.
ATT&CK [author-mapped behavior, not actor attribution]: Not forced: the public role-misuse evidence does not justify a specific technique mapping here.
Storm-1283 OAuth-enabled cryptomining
Period: Reported December 2023. Evidence: campaign reported by the cited source.
Observed [source-reported]: Microsoft reported that compromised access was used to create an OAuth application and deploy virtual machines for cryptomining. Microsoft: Threat actors misuse OAuth applications to automate financially driven attacks.
Anomaly interpretation [inferred]: Compare application activity with applications having the same business function. VM creation may be abnormal for one cohort and routine for deployment automation.
Telemetry to validate: Application inventory, workload-identity logs, Azure Activity and approved deployment records.
Boundary / competing explanation: The comparison cohort and expected activity are not supplied by the incident report and must be established locally.
ATT&CK [author-mapped behavior, not actor attribution]: T1496 — Resource Hijacking
Crosslinks: Identity / Access · Data Movement. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.
Illustrative scenarios (not additional incidents):
-
One finance employee accesses source code repositories and DevOps dashboards that no one else in the finance peer group normally uses.
-
A single server in the same Windows server class begins spawning developer tools and compression utilities, unlike its peer servers.
-
One sales user downloads 15 times more CRM records than others in the same department over the same week.
-
A service account in a group of low-privilege automation accounts suddenly begins calling privileged admin APIs that its peers never invoke.
-
One employee in a peer group of standard Microsoft 365 users starts creating mailbox forwarding rules and performing eDiscovery-like searches, unlike comparable users with the same role.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Process or account invokes elevation mechanism · Cloud resources or configurations enumerated · Privileged or long-running container workload deployed · Unauthorized computation or resource abuse · Cloud secrets, keys, or tokens retrieved.
Collection references: User Account Metadata · Asset Inventory · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.