Skip to main content

State-Change

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

A change to configuration, trust, permissions or exposure that warrants contextual review.

Telemetry contract: Before/after state, actor, control-plane audit, object identity and approved change records.

Candidate method [unvalidated until tested]: Scope the object and policy; first occurrence is a feature, not a maliciousness verdict.

Benign alternatives and limits: Administrative changes can be legitimate, including changes to sensitive objects.

State-change anomaly. Synthetic change on Repo-07 by Admin-12 at 10:04 UTC: internal-only access changes to allowing external sharing. No approval has yet been matched. Verify effective access separately; enabling sharing does not establish public exposure, data access or an unauthorized change. A first-seen configuration change can be legitimate administration.
Figure 20. State-change anomaly. Synthetic change on Repo-07 by Admin-12 at 10:04 UTC: internal-only access changes to allowing external sharing. No approval has yet been matched. Verify effective access separately; enabling sharing does not establish public exposure, data access or an unauthorized change.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

A first-seen configuration change can be legitimate administration.

The same repository object, Repo-07, changes from internal users only to external sharing enabled. The diagram names a synthetic actor Admin-12 and event time 10:04 UTC.

Approval has not yet been matched. This is not proof that the change lacked authorization.

Retain old and new values, object identity, actor and time. Check effective exposure and the approved change record; legitimate administration can create the same setting change.

Open original full-size asset

Evidence tags: Identity and access · Cloud and SaaS · Application audit. Statistical forms: point, contextual.

Browse articles and guides: State-Change.

Reported incidents and detection interpretations

Storm-1283 OAuth-enabled cryptomining​

Period: Reported December 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: The actor added credentials and permissions to OAuth applications and used application access for resource deployment. Microsoft: Threat actors misuse OAuth applications to automate financially driven attacks.

Anomaly interpretation [inferred]: Track changes to authentication material and authorization separately from subsequent consumption. Connect the changed application to its first unusual resource operations.

Telemetry to validate: Application credential additions, consent/role changes and Azure resource activity.

Boundary / competing explanation: Secret rotation and application provisioning are ordinary operations; ownership, approvals and deployment scope determine risk.

ATT&CK [author-mapped behavior, not actor attribution]: T1098 — Account Manipulation; T1496 — Resource Hijacking

LEMURLOOT in MOVEit data-theft intrusions​

Period: May–June 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: Mandiant described LEMURLOOT creating a MOVEit application account with Health Check Service names through database operations. Mandiant: Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft.

Anomaly interpretation [inferred]: Investigate unauthorized application-account creation and session insertion, correlating database changes with webshell access.

Telemetry to validate: MOVEit application/database evidence, web requests and web-root file changes.

Boundary / competing explanation: This is not inherently a Windows account. Windows Event 4720 is not the correct expected artifact for this application-database operation.

ATT&CK [author-mapped behavior, not actor attribution]: T1505.003 — Server Software Component: Web Shell

Crosslinks: Graph / Relationship · Negative Anomaly (Absence). Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.

Illustrative scenarios (not additional incidents):

  • A new trust policy is added to an IAM role, allowing a previously unrelated principal to assume it for the first time.

  • An Active Directory group policy or group membership change creates a new path to privileged access for a sensitive server tier.

  • A SaaS administrator changes a tenant setting to allow external sharing on a repository that was previously restricted to internal users.

  • An IdP admin modifies conditional access or MFA policy for a privileged group, reducing authentication requirements for high-risk accounts.

  • A cloud storage bucket that was private is suddenly changed to public or cross-account accessible, materially increasing exposure.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Startup or logon configuration changed to launch code · New or modified system service · Firewall policy disabled or weakened · New local, domain, cloud, or service account · Credential, group, role, or account-property modification · Email forwarding rule created · Compromised software or update installation · Files, records, or resources deleted or destroyed.

Collection references: Active Directory Object Modification · User Account Modification · Cloud Service Modification · Windows Registry Key Modification. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.