Skip to main content

Temporal

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

Activity inconsistent with a defined time-of-day, shift or seasonal context.

Telemetry contract: Event-time identity, administration and workload logs plus time-zone and schedule context.

Candidate method [unvalidated until tested]: Compare like calendar periods; handle travel, daylight-saving changes and ingestion delay.

Benign alternatives and limits: On-call work, international teams and scheduled maintenance are legitimate alternatives.

Temporal anomaly. A synthetic weekday-only account acts at 03:00 on Sunday, outside its stated schedule. The heatmap is a schedule illustration, not measured event intensity or a real incident timeline. On-call work, travel and daylight-saving changes can explain timing.
Figure 9. Temporal anomaly. A synthetic weekday-only account acts at 03:00 on Sunday, outside its stated schedule. The heatmap is a schedule illustration, not measured event intensity or a real incident timeline.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

On-call work, travel and daylight-saving changes can explain timing.

The weekday work-context cells contrast with a highlighted Sunday 03:00 cell, in example local time.

Check time zone, shifts, on-call duties and approved changes. Event time and ingestion time are different.

Unusual timing is a question, not an explanation.

Open original full-size asset

Evidence tags: Network telemetry · Endpoint telemetry · Operational technology. Statistical forms: contextual, collective.

Browse articles and guides: Temporal.

Reported incidents and detection interpretations

SUNBURST in the SolarWinds supply-chain compromise​

Period: 2020. Evidence: campaign reported by the cited source.

Observed [source-reported]: SUNBURST delayed activation and subsequently used DNS coordination and command-and-control traffic. Mandiant: SUNBURST Additional Technical Details.

Anomaly interpretation [inferred]: Relate software installation, delayed first contact and later callbacks. The delay is an event-sequence feature, not an observable DNS anomaly while the implant is silent.

Telemetry to validate: Software deployment records, process-attributed network events and DNS timestamps.

Boundary / competing explanation: Dormancy without emitted telemetry cannot be scored from network traffic; normal update delays can look similar.

ATT&CK [author-mapped behavior, not actor attribution]: T1071.004 — Application Layer Protocol: DNS

Industroyer2 attempted disruption of a Ukrainian energy provider​

Period: 8 April 2022. Evidence: incident reported by the cited source.

Observed [source-reported]: ESET documented Industroyer2 execution scheduled for 8 April 2022 at 16:10 UTC in an attempted attack on a Ukrainian energy provider. ESET: Industroyer2: Industroyer reloaded.

Anomaly interpretation [inferred]: Correlate the task's creation and scheduled execution with approved OT work and operational commands. Clock time alone does not make an event anomalous.

Telemetry to validate: Scheduled-task records, engineering-host process logs, OT commands and maintenance approvals.

Boundary / competing explanation: The public report establishes the scheduled time, not the site's full maintenance baseline or a successful temporal detection.

ATT&CK [author-mapped behavior, not actor attribution]: T1053.005 — Scheduled Task/Job: Scheduled Task

Crosslinks: Sequence · Protocol / Application Usage. Statistical foundation in the Anomaly Detection Atlas. Related research: Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry.

Illustrative scenarios (not additional incidents):

  • An HR employee who normally logs in between 08:00–17:00 starts downloading sensitive employee records at 02:43 on a Sunday.

  • A SaaS admin account that is typically active only during local business hours performs privilege changes at 03:10.

  • A developer laptop that usually shows weekday activity suddenly initiates code repository access and cloud console actions during a national holiday.

  • A server management account that normally runs scheduled maintenance at 01:00–02:00 begins executing admin actions at an unusual afternoon hour outside its normal service window.

  • A user with a stable daytime pattern starts authenticating from the same device every night for several consecutive days, outside their historical baseline.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Scheduled job, service, or automation executes payload · Endpoint communicates periodically with external destination · External remote-service session · Transfers deliberately limited to evade controls.

Collection references: Scheduled Job Creation · Process Creation · Network Traffic Flow. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.