Skip to main content

Peer-Group

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

An entity differs from an explicitly defined comparison cohort.

Telemetry contract: Identity and asset inventory, role history, application use and access records.

Candidate method [unvalidated until tested]: Validate cohort membership, then compare distributions or fit a clustering model. TF-IDF can weight input features; it is not clustering itself.

Benign alternatives and limits: Role changes, small cohorts and incomplete personnel data can create misleading outliers.

Peer-group anomaly. Four synthetic employees have comparable finance roles. A–C access the finance application and CRM; D also accesses a code repository. That deviation depends on how the peer group was defined. Small cohorts and incomplete inventory can manufacture an outlier.
Figure 10. Peer-group anomaly. Four synthetic employees have comparable finance roles. A–C access the finance application and CRM; D also accesses a code repository. That deviation depends on how the peer group was defined.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Small cohorts and incomplete inventory can manufacture an outlier.

Employees A, B and C: finance application and CRM. Employee D: the same two resources plus a code repository.

Verify duties and cohort membership. A temporary project or legitimate role change may explain the difference.

Compare like with like and validate the cohort first.

Open original full-size asset

Evidence tags: Identity and access · Insider risk · Cloud and SaaS. Statistical forms: contextual.

Browse articles and guides: Peer-Group.

Reported incidents and detection interpretations

Twitter insider access for a foreign official​

Period: Conduct addressed in the 2022 Abouammo conviction. Evidence: incident reported by the cited source.

Observed [source-reported]: A jury convicted former Twitter media-partnerships manager Ahmad Abouammo over unlawful access and disclosure of user information. The indictment explains the job-duty boundary. US Department of Justice: Former Twitter Employee Found Guilty of Acting as an Agent of a Foreign Government and Unlawfully Sharing Twitter User Information; US Department of Justice: Superseding indictment, United States v. Abouammo et al., filed July 28, 2020.

Anomaly interpretation [inferred]: Compare sensitive-record access with employees having the same responsibilities, not with all staff who technically possess access.

Telemetry to validate: Internal user-data access logs, role assignments, case authorization and HR role history.

Boundary / competing explanation: Peer-group detection is an author-derived opportunity; the sources do not say a UEBA model discovered this case.

ATT&CK [author-mapped behavior, not actor attribution]: Not forced: the public role-misuse evidence does not justify a specific technique mapping here.

Storm-1283 OAuth-enabled cryptomining​

Period: Reported December 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: Microsoft reported that compromised access was used to create an OAuth application and deploy virtual machines for cryptomining. Microsoft: Threat actors misuse OAuth applications to automate financially driven attacks.

Anomaly interpretation [inferred]: Compare application activity with applications having the same business function. VM creation may be abnormal for one cohort and routine for deployment automation.

Telemetry to validate: Application inventory, workload-identity logs, Azure Activity and approved deployment records.

Boundary / competing explanation: The comparison cohort and expected activity are not supplied by the incident report and must be established locally.

ATT&CK [author-mapped behavior, not actor attribution]: T1496 — Resource Hijacking

Crosslinks: Identity / Access · Data Movement. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.

Illustrative scenarios (not additional incidents):

  • One finance employee accesses source code repositories and DevOps dashboards that no one else in the finance peer group normally uses.

  • A single server in the same Windows server class begins spawning developer tools and compression utilities, unlike its peer servers.

  • One sales user downloads 15 times more CRM records than others in the same department over the same week.

  • A service account in a group of low-privilege automation accounts suddenly begins calling privileged admin APIs that its peers never invoke.

  • One employee in a peer group of standard Microsoft 365 users starts creating mailbox forwarding rules and performing eDiscovery-like searches, unlike comparable users with the same role.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Process or account invokes elevation mechanism · Cloud resources or configurations enumerated · Privileged or long-running container workload deployed · Unauthorized computation or resource abuse · Cloud secrets, keys, or tokens retrieved.

Collection references: User Account Metadata · Asset Inventory · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.