Temporal
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
Activity inconsistent with a defined time-of-day, shift or seasonal context.
Telemetry contract: Event-time identity, administration and workload logs plus time-zone and schedule context.
Candidate method [unvalidated until tested]: Compare like calendar periods; handle travel, daylight-saving changes and ingestion delay.
Benign alternatives and limits: On-call work, international teams and scheduled maintenance are legitimate alternatives.

Text equivalent and full-size diagram
On-call work, travel and daylight-saving changes can explain timing.
The weekday work-context cells contrast with a highlighted Sunday 03:00 cell, in example local time.
Check time zone, shifts, on-call duties and approved changes. Event time and ingestion time are different.
Unusual timing is a question, not an explanation.
Evidence tags: Network telemetry · Endpoint telemetry · Operational technology. Statistical forms: contextual, collective.
Browse articles and guides: Temporal.
Reported incidents and detection interpretations
SUNBURST in the SolarWinds supply-chain compromise
Period: 2020. Evidence: campaign reported by the cited source.
Observed [source-reported]: SUNBURST delayed activation and subsequently used DNS coordination and command-and-control traffic. Mandiant: SUNBURST Additional Technical Details.
Anomaly interpretation [inferred]: Relate software installation, delayed first contact and later callbacks. The delay is an event-sequence feature, not an observable DNS anomaly while the implant is silent.
Telemetry to validate: Software deployment records, process-attributed network events and DNS timestamps.
Boundary / competing explanation: Dormancy without emitted telemetry cannot be scored from network traffic; normal update delays can look similar.
ATT&CK [author-mapped behavior, not actor attribution]: T1071.004 — Application Layer Protocol: DNS
Industroyer2 attempted disruption of a Ukrainian energy provider
Period: 8 April 2022. Evidence: incident reported by the cited source.
Observed [source-reported]: ESET documented Industroyer2 execution scheduled for 8 April 2022 at 16:10 UTC in an attempted attack on a Ukrainian energy provider. ESET: Industroyer2: Industroyer reloaded.
Anomaly interpretation [inferred]: Correlate the task's creation and scheduled execution with approved OT work and operational commands. Clock time alone does not make an event anomalous.
Telemetry to validate: Scheduled-task records, engineering-host process logs, OT commands and maintenance approvals.
Boundary / competing explanation: The public report establishes the scheduled time, not the site's full maintenance baseline or a successful temporal detection.
ATT&CK [author-mapped behavior, not actor attribution]: T1053.005 — Scheduled Task/Job: Scheduled Task
Crosslinks: Sequence · Protocol / Application Usage. Statistical foundation in the Anomaly Detection Atlas. Related research: Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry.
Illustrative scenarios (not additional incidents):
-
An HR employee who normally logs in between 08:00–17:00 starts downloading sensitive employee records at 02:43 on a Sunday.
-
A SaaS admin account that is typically active only during local business hours performs privilege changes at 03:10.
-
A developer laptop that usually shows weekday activity suddenly initiates code repository access and cloud console actions during a national holiday.
-
A server management account that normally runs scheduled maintenance at 01:00–02:00 begins executing admin actions at an unusual afternoon hour outside its normal service window.
-
A user with a stable daytime pattern starts authenticating from the same device every night for several consecutive days, outside their historical baseline.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Scheduled job, service, or automation executes payload · Endpoint communicates periodically with external destination · External remote-service session · Transfers deliberately limited to evade controls.
Collection references: Scheduled Job Creation · Process Creation · Network Traffic Flow. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.