Skip to main content

Volumetric

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

Unusual amount of data or events over a defined observation window.

Telemetry contract: Directional flow counters, exports, object access or audit events; record whether units are bytes, objects, rows or events.

Candidate method [unvalidated until tested]: Compare aligned windows within a workload/role. Evaluate empirical quantiles or an appropriate location/scale model.

Benign alternatives and limits: Backups, reporting, synchronization and incident recovery can create large legitimate volumes.

Volumetric anomaly. Equal 30-minute windows for the same user and workload contain 90, 120, 110, 100, 130 and 650 download audit events. These are synthetic counts, not the Snowflake or DDoS incident measurements below. Backups, reporting and recovery can produce legitimate spikes.
Figure 7. Volumetric anomaly. Equal 30-minute windows for the same user and workload contain 90, 120, 110, 100, 130 and 650 download audit events. These are synthetic counts, not the Snowflake or DDoS incident measurements below.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Backups, reporting and recovery can produce legitimate spikes.

W1: 90; W2: 120; W3: 110; W4: 100; W5: 130; W6: 650 download audit events. Every window is 30 minutes.

Compare like units and workloads. Audit events are not necessarily unique files; backups and reporting can explain spikes.

Measure how much, then establish why.

Open original full-size asset

Evidence tags: Cloud and SaaS · Network telemetry. Statistical forms: point, collective.

Browse articles and guides: Volumetric.

Reported incidents and detection interpretations

UNC5537 and Snowflake customer data theft​

Period: 2024. Evidence: campaign reported by the cited source.

Observed [source-reported]: Mandiant investigated stolen customer credentials used to access Snowflake instances and exfiltrate database records. Mandiant: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion.

Anomaly interpretation [inferred]: Compare exported rows or bytes with that account's job and warehouse workload. A large legitimate reporting job remains a competing explanation.

Telemetry to validate: Snowflake query and access history; export destinations; identity and warehouse context.

Boundary / competing explanation: The report does not provide a universal per-account volume threshold or a measured anomaly-detector success rate.

ATT&CK [author-mapped behavior, not actor attribution]: T1078.004 — Valid Accounts: Cloud Accounts

HTTP/2 Rapid Reset DDoS campaign​

Period: August 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: Cloudflare reported HTTP/2 attacks reaching just above 201 million requests per second and automatic detection and mitigation. Cloudflare: HTTP/2 Rapid Reset: deconstructing the record-breaking attack.

Anomaly interpretation [inferred]: This is a documented extreme-load event. Separate total resource load from rate and compare it with service capacity and normal demand.

Telemetry to validate: Edge request counters, connection statistics, origin saturation and mitigation events.

Boundary / competing explanation: This is Cloudflare's measurement, not a generic enterprise threshold or independent validation of a particular model.

ATT&CK [author-mapped behavior, not actor attribution]: T1499 — Endpoint Denial of Service

Crosslinks: Frequency / Rate · Data Movement. Statistical foundation in the Anomaly Detection Atlas. Related research: AI Agent vs. Human with Wireshark: Six Malware PCAPs Put to the Test.

Illustrative scenarios (not additional incidents):

  • A finance user whose historical complete 40-minute windows contain 20–50 download events produces 8,000 download events in a comparable window. Audit-event counts are not necessarily unique documents.

  • A database server with stable nightly replication begins sending 12 GB of outbound traffic to an external IP at 03:12, far above its normal egress baseline.

  • A workstation that usually makes fewer than 200 DNS requests per hour suddenly generates 9,000 queries, including many high-entropy subdomains.

  • A cloud service account that typically reads a few dozen objects per day suddenly accesses 30,000 S3 objects in one session.

  • A file server that normally changes 1–2 GB of data daily suddenly shows mass file modifications and deletions consistent with ransomware impact.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Files, records, messages, or objects accessed in bulk · Large outbound transfer · Files encrypted for impact · Service or system availability disrupted.

Collection references: Network Traffic Flow · Cloud Storage Access · File Access. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.