Skip to main content

Mapping Anomalies to ATT&CK Tactics

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

ATT&CK organizes adversary objectives and behavior; it is not a required chronological lifecycle. An intrusion may repeat, skip or combine tactics. A statistical feature is not an ATT&CK technique, and neither establishes actor attribution.

Version boundary: this revision uses Enterprise ATT&CK v19.2. The April 2026 v19 release split the former Defense Evasion grouping into Stealth and Defense Impairment. The original article predates that release. Historical vendor strings such as DefenseEvasion:IAMUser/AnomalousBehavior remain vendor identifiers; they must not be silently renamed to match ATT&CK. MITRE release notes.

The following are author-proposed analytical opportunities, not measured coverage rankings. Original section anchors are retained for existing links.

TacticCandidate observationContext needed / important blind spot
ReconnaissanceRequest rate, target spread, unusual URI accessTarget-side requests can expose active reconnaissance; external/passive activity may require third-party visibility. Background scanning is common.
Resource DevelopmentNew lookalike domains or infrastructure relationshipsOften outside enterprise logs; external monitoring can still support anomaly analysis. Acquisition alone does not prove malicious intent.
Initial AccessAuthentication failures, new identity/device relationshipsDistributed sources and valid credentials weaken per-IP rules. Tenant-local correlation may still help.
ExecutionUnexpected process ancestry or application behaviorIn-process execution may not create a child process; application maintenance can create unusual children.
PersistenceNew credentials, application permissions, scheduled tasksCheck actual persistence semantics. VM creation or an MFA reset alone is not proof of persistence.
Privilege EscalationUnexpected role assignment or privilege transitionReview actor, approved change and effective permissions. Kerberoasting itself belongs under Credential Access.
StealthUnusual execution location, masquerading or concealed relationshipsThis anchor preserves the old grouping's URL; it does not imply that the old grouping and Stealth are identical.
Defense ImpairmentAudit-policy changes, security-service interruption, log clearingIndependent collector health distinguishes disabled collection from an ordinary outage.
Credential AccessUnusual service-ticket requests, replication access, LSASS accessValidate audit coverage, encryption types and approved replication sources.
DiscoveryNew enumeration tools, directory-query shapeAdministrative inventory and troubleshooting can look similar.
Lateral MovementNew identity/source/destination edgesRequires asset roles, remote logon context and approved administration paths.
CollectionNew data sources, object-access breadthA newly assigned project can legitimately expand access.
Command and ControlDestination novelty, periodicity, DNS structureLegitimate agents beacon; jitter, encrypted resolvers and sensor placement limit visibility.
ExfiltrationUnusual exports, downloads or outbound destinationsDistinguish bytes, records, unique objects and audit-event counts. Provider-side transfers may bypass endpoint sensors.
ImpactFile-change bursts, availability loss, destructive commandsBackups, migration and recovery operations can resemble components of the pattern.

Map the observed behavior first, then identify the possible statistic. Do not infer a group from an anomaly tag or infer detector success from a valid technique ID. The case register records those boundaries separately.

Map behavior, then ask what is measurable. The article’s tactic matrix is a set of proposed observation opportunities. It is not a ranking of detector performance. These are analytical relationships, not a guaranteed attack progression.
Figure 23. Map behavior, then ask what is measurable. The article’s tactic matrix is a set of proposed observation opportunities. It is not a ranking of detector performance.CONCEPTUAL MODELSources: MITRE v19 release notes · MITRE v19.2 release notes.
Text equivalent and full-size diagram

These are analytical relationships, not a guaranteed attack progression.

  1. Observed behavior. Keep the source and its limits.
  2. ATT&CK mapping. Explain why the behavior fits.
  3. Candidate feature. Name fields, units and context.
  • ATT&CK v19.2 context. The v19 split created Stealth and Defense Impairment. Tactics are not a required time sequence.
  • Do not infer. An anomaly tag is neither a technique verdict, a group identity nor measured detection coverage.

Open original full-size asset · Open narrow-layout SVG