Skip to main content

Sequence

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

An event sequence differs from an expected operational workflow.

Telemetry contract: Process ancestry, authentication, application actions, session identifiers and event time.

Candidate method [unvalidated until tested]: Use explicit sequence constraints or a validated sequence model; define allowed lateness and missing steps.

Benign alternatives and limits: Different legitimate workflows and timestamp disorder can produce the same apparent sequence.

Sequence anomaly. A synthetic session contains sign-in at 09:00, a permission grant at 09:03 and sensitive access at 09:05, without a matching approval yet observed. Missing approval telemetry is not proof that approval never occurred. This illustrative workflow can also be legitimate; timing alone is not causality.
Figure 11. Sequence anomaly. A synthetic session contains sign-in at 09:00, a permission grant at 09:03 and sensitive access at 09:05, without a matching approval yet observed. Missing approval telemetry is not proof that approval never occurred.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

This illustrative workflow can also be legitimate; timing alone is not causality.

Expected workflow: approved request, permission grant, sensitive access.

Illustrated session for one verified identity: sign-in 09:00, permission grant 09:03, sensitive access 09:05. Approval has not yet been observed.

Check identity, session, ordering, allowed gaps and record completeness before inferring an unauthorized sequence.

Open original full-size asset

Evidence tags: Identity and access · Endpoint telemetry · Cloud and SaaS. Statistical forms: collective, contextual.

Browse articles and guides: Sequence.

Reported incidents and detection interpretations

UNC3944 help-desk compromise and SaaS data theft​

Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.

Observed [source-reported]: Mandiant described help-desk impersonation, MFA changes and subsequent access to privileged accounts and SaaS applications across its investigations. Mandiant: UNC3944 Targets SaaS Applications.

Anomaly interpretation [inferred]: Correlate reset, new-device enrollment, sign-in and expanded access on the same identity. Preserve ordering rather than merely counting co-occurring alerts.

Telemetry to validate: Help-desk tickets, IdP factor events, session records and SaaS audit logs.

Boundary / competing explanation: The report synthesizes multiple engagements; do not invent one victim timeline containing every reported technique.

ATT&CK [author-mapped behavior, not actor attribution]: T1098.005 — Account Manipulation: Device Registration

BazarCall to Conti intrusion​

Period: 2021 case reported on 1 August. Evidence: incident reported by the cited source.

Observed [source-reported]: The DFIR Report traced a workbook-led intrusion through Trickbot, Cobalt Strike, discovery and lateral movement to later Conti deployment. The DFIR Report: BazarCall to Conti Ransomware via Trickbot and Cobalt Strike.

Anomaly interpretation [inferred]: Link execution, discovery and remote activity by host and identity. A multi-stage sequence can warrant investigation before ransomware appears.

Telemetry to validate: Process trees, authentication records, service creation and endpoint/network timestamps.

Boundary / competing explanation: A rigid sequence requiring every stage will miss partial telemetry and different attack paths; evaluate missing-stage tolerance.

ATT&CK [author-mapped behavior, not actor attribution]: T1087.002 — Account Discovery: Domain Account

Crosslinks: Identity / Access · Parent-Child Execution. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.

Illustrative scenarios (not additional incidents):

  • A user authenticates to a SaaS tenant, creates a new OAuth app, grants high-risk permissions, and then performs bulk data access in a sequence not seen in normal admin workflows.

  • On a server, powershell.exe spawns rundll32.exe, which then launches a network connection to an external host—an execution chain that deviates from the usual parent-child order.

  • A mailbox access session shows inbox rule creation before any normal interactive user activity, followed immediately by message forwarding and deletion operations.

  • A cloud workflow shows snapshot creation, privilege modification, and object export in an order that does not match standard backup or maintenance procedures.

  • A workstation process tree shows Office opening a script interpreter, then a credential access tool, then an archive utility — an event sequence inconsistent with normal user productivity flows.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Malicious attachment, link, or message delivery · User opens delivered content followed by execution · Data staged, compressed, or archived · Tool or payload transferred internally · Unexpected serverless or cloud-workload invocation · Container administration interface executes command.

Collection references: Process Creation · Logon Session Creation · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.