Sequence
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
An event sequence differs from an expected operational workflow.
Telemetry contract: Process ancestry, authentication, application actions, session identifiers and event time.
Candidate method [unvalidated until tested]: Use explicit sequence constraints or a validated sequence model; define allowed lateness and missing steps.
Benign alternatives and limits: Different legitimate workflows and timestamp disorder can produce the same apparent sequence.

Text equivalent and full-size diagram
This illustrative workflow can also be legitimate; timing alone is not causality.
Expected workflow: approved request, permission grant, sensitive access.
Illustrated session for one verified identity: sign-in 09:00, permission grant 09:03, sensitive access 09:05. Approval has not yet been observed.
Check identity, session, ordering, allowed gaps and record completeness before inferring an unauthorized sequence.
Evidence tags: Identity and access · Endpoint telemetry · Cloud and SaaS. Statistical forms: collective, contextual.
Browse articles and guides: Sequence.
Reported incidents and detection interpretations
UNC3944 help-desk compromise and SaaS data theft
Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.
Observed [source-reported]: Mandiant described help-desk impersonation, MFA changes and subsequent access to privileged accounts and SaaS applications across its investigations. Mandiant: UNC3944 Targets SaaS Applications.
Anomaly interpretation [inferred]: Correlate reset, new-device enrollment, sign-in and expanded access on the same identity. Preserve ordering rather than merely counting co-occurring alerts.
Telemetry to validate: Help-desk tickets, IdP factor events, session records and SaaS audit logs.
Boundary / competing explanation: The report synthesizes multiple engagements; do not invent one victim timeline containing every reported technique.
ATT&CK [author-mapped behavior, not actor attribution]: T1098.005 — Account Manipulation: Device Registration
BazarCall to Conti intrusion
Period: 2021 case reported on 1 August. Evidence: incident reported by the cited source.
Observed [source-reported]: The DFIR Report traced a workbook-led intrusion through Trickbot, Cobalt Strike, discovery and lateral movement to later Conti deployment. The DFIR Report: BazarCall to Conti Ransomware via Trickbot and Cobalt Strike.
Anomaly interpretation [inferred]: Link execution, discovery and remote activity by host and identity. A multi-stage sequence can warrant investigation before ransomware appears.
Telemetry to validate: Process trees, authentication records, service creation and endpoint/network timestamps.
Boundary / competing explanation: A rigid sequence requiring every stage will miss partial telemetry and different attack paths; evaluate missing-stage tolerance.
ATT&CK [author-mapped behavior, not actor attribution]: T1087.002 — Account Discovery: Domain Account
Crosslinks: Identity / Access · Parent-Child Execution. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.
Illustrative scenarios (not additional incidents):
-
A user authenticates to a SaaS tenant, creates a new OAuth app, grants high-risk permissions, and then performs bulk data access in a sequence not seen in normal admin workflows.
-
On a server,
powershell.exespawnsrundll32.exe, which then launches a network connection to an external host—an execution chain that deviates from the usual parent-child order. -
A mailbox access session shows inbox rule creation before any normal interactive user activity, followed immediately by message forwarding and deletion operations.
-
A cloud workflow shows snapshot creation, privilege modification, and object export in an order that does not match standard backup or maintenance procedures.
-
A workstation process tree shows Office opening a script interpreter, then a credential access tool, then an archive utility — an event sequence inconsistent with normal user productivity flows.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Malicious attachment, link, or message delivery · User opens delivered content followed by execution · Data staged, compressed, or archived · Tool or payload transferred internally · Unexpected serverless or cloud-workload invocation · Container administration interface executes command.
Collection references: Process Creation · Logon Session Creation · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.