Mapping Anomalies to ATT&CK Tactics
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
ATT&CK organizes adversary objectives and behavior; it is not a required chronological lifecycle. An intrusion may repeat, skip or combine tactics. A statistical feature is not an ATT&CK technique, and neither establishes actor attribution.
Version boundary: this revision uses Enterprise ATT&CK v19.2. The April 2026 v19 release split the former Defense Evasion grouping into Stealth and Defense Impairment. The original article predates that release. Historical vendor strings such as DefenseEvasion:IAMUser/AnomalousBehavior remain vendor identifiers; they must not be silently renamed to match ATT&CK. MITRE release notes.
The following are author-proposed analytical opportunities, not measured coverage rankings. Original section anchors are retained for existing links.
| Tactic | Candidate observation | Context needed / important blind spot |
|---|---|---|
| Reconnaissance | Request rate, target spread, unusual URI access | Target-side requests can expose active reconnaissance; external/passive activity may require third-party visibility. Background scanning is common. |
| Resource Development | New lookalike domains or infrastructure relationships | Often outside enterprise logs; external monitoring can still support anomaly analysis. Acquisition alone does not prove malicious intent. |
| Initial Access | Authentication failures, new identity/device relationships | Distributed sources and valid credentials weaken per-IP rules. Tenant-local correlation may still help. |
| Execution | Unexpected process ancestry or application behavior | In-process execution may not create a child process; application maintenance can create unusual children. |
| Persistence | New credentials, application permissions, scheduled tasks | Check actual persistence semantics. VM creation or an MFA reset alone is not proof of persistence. |
| Privilege Escalation | Unexpected role assignment or privilege transition | Review actor, approved change and effective permissions. Kerberoasting itself belongs under Credential Access. |
| Stealth | Unusual execution location, masquerading or concealed relationships | This anchor preserves the old grouping's URL; it does not imply that the old grouping and Stealth are identical. |
| Defense Impairment | Audit-policy changes, security-service interruption, log clearing | Independent collector health distinguishes disabled collection from an ordinary outage. |
| Credential Access | Unusual service-ticket requests, replication access, LSASS access | Validate audit coverage, encryption types and approved replication sources. |
| Discovery | New enumeration tools, directory-query shape | Administrative inventory and troubleshooting can look similar. |
| Lateral Movement | New identity/source/destination edges | Requires asset roles, remote logon context and approved administration paths. |
| Collection | New data sources, object-access breadth | A newly assigned project can legitimately expand access. |
| Command and Control | Destination novelty, periodicity, DNS structure | Legitimate agents beacon; jitter, encrypted resolvers and sensor placement limit visibility. |
| Exfiltration | Unusual exports, downloads or outbound destinations | Distinguish bytes, records, unique objects and audit-event counts. Provider-side transfers may bypass endpoint sensors. |
| Impact | File-change bursts, availability loss, destructive commands | Backups, migration and recovery operations can resemble components of the pattern. |
Map the observed behavior first, then identify the possible statistic. Do not infer a group from an anomaly tag or infer detector success from a valid technique ID. The case register records those boundaries separately.
Text equivalent and full-size diagram
These are analytical relationships, not a guaranteed attack progression.
- Observed behavior. Keep the source and its limits.
- ATT&CK mapping. Explain why the behavior fits.
- Candidate feature. Name fields, units and context.
- ATT&CK v19.2 context. The v19 split created Stealth and Defense Impairment. Tactics are not a required time sequence.
- Do not infer. An anomaly tag is neither a technique verdict, a group identity nor measured detection coverage.