Incident register, tags and evidence boundaries
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
This expansion covers 14 operational anomaly families plus multi-event correlation: 15 navigation tags, 30 incident-to-topic mappings and 17 distinct case/campaign records, reviewed on 2026-09-21. A campaign record may summarize multiple victims; this is not a count of individual breaches. A repeated case is not independent evidence.
Reading the labels: “Observed” means reported by the named investigator, not reproduced in this research. Each anomaly interpretation and ATT&CK association is an author-derived mapping. Suggested telemetry is a collection plan, not a claim that it was available to the original victim. No new precision, recall, threshold or successful-detection result is asserted.
Scope: Fourteen headings describe operational feature families; the fifteenth, multi-event correlation, is a composition pattern that combines them. The companion Atlas has a broader statistical taxonomy; its linked categories explain the statistical concept and do not imply one-to-one equivalence. The existing generic example bullets remain illustrative scenarios, not extra documented incidents.

Text equivalent and full-size diagram
Reported observations, author-inferred mappings and proposed telemetry have different evidence status. This register is not an anomaly type or a detector benchmark.
Scope snapshot: 14 operational anomaly families plus one correlation pattern; 15 navigation tags; 17 distinct case or campaign records; 30 incident-to-topic mappings. Reviewed 2026-09-21.
Reported: a named investigator reports an observation; the article has not independently reproduced it. Inferred: the author maps behavior to an analytical view; a topic tag is not attribution or detector validation.
Proposed: suggested telemetry requires validation; a collection plan does not prove that the original victim had that visibility.
Keep each case identifier, investigator and source attached to every mapping. A repeated case is not independent evidence, and a campaign can include several victims. Neither counts nor topic tags establish precision, recall or successful detection.
| Case / campaign record | Attribution boundary | Crosslinked analytical views |
|---|---|---|
| UNC5537 and Snowflake customer data theft (2024) | UNC5537, as tracked by Mandiant; customer-account compromise, not a demonstrated compromise of Snowflake itself | Volumetric · Geographic / ASN · Data Movement |
| HTTP/2 Rapid Reset DDoS campaign (August 2023) | Operators not named in the cited report | Volumetric · Frequency / Rate |
| Midnight Blizzard compromise of Microsoft (Reported January 2024) | Midnight Blizzard, as attributed by Microsoft | Frequency / Rate · Graph / Relationship · Geographic / ASN |
| SUNBURST in the SolarWinds supply-chain compromise (2020) | UNC2452 in contemporaneous Mandiant reporting; a malware observation is not by itself group attribution | Temporal · Protocol / Application Usage |
| Industroyer2 attempted disruption of a Ukrainian energy provider (8 April 2022) | Sandworm, as assessed by ESET and CERT-UA | Temporal |
| Twitter insider access for a foreign official (Conduct addressed in the 2022 Abouammo conviction) | Ahmad Abouammo, named in the conviction report; indictment allegations about other people are not treated as convictions | Peer-Group |
| Storm-1283 OAuth-enabled cryptomining (Reported December 2023) | Storm-1283, as tracked by Microsoft | Peer-Group · Graph / Relationship · State-Change |
| UNC3944 help-desk compromise and SaaS data theft (2023–2024 investigations reported June 2024) | UNC3944, as tracked by Mandiant; overlapping public names are not assumed to be exact aliases | Sequence · Identity / Access · Data Movement · Multi-Event Correlation |
| BazarCall to Conti intrusion (2021 case reported on 1 August) | Conti ransomware operators in this investigation; tools alone do not establish actor identity | Sequence · Rare Process / Service · Multi-Event Correlation |
| Storm-0558 forged-token mailbox access (2023) | Storm-0558, as attributed by Microsoft | Identity / Access |
| MESSAGETAP on telecommunications SMS servers (2019) | APT41, as attributed by Mandiant | Rare Process / Service |
| Lemon Duck exploitation of Exchange servers (March 2021 reporting) | Lemon Duck activity in Microsoft's report; not reassigned to HAFNIUM | Parent-Child Execution |
| DoejoCrypt activity after Exchange exploitation (March 2021 reporting) | DoejoCrypt activity in Microsoft's report; malware label, not a proven identity of the operator | Parent-Child Execution |
| OilRig-associated RDAT at a telecommunications organization (April 2020 activity) | OilRig association assessed by Unit 42; not an attribution inferred from DNS entropy | Protocol / Application Usage |
| SCARLETEEL cloud intrusion (2023 reporting) | SCARLETEEL is the operation label used by Sysdig, not an independently established actor identity | Negative Anomaly (Absence) |
| AuKill use before ransomware deployment (January–February 2023 incidents) | Ransomware incidents involving Medusa Locker or LockBit; no assertion that their operators are one group | Negative Anomaly (Absence) |
| LEMURLOOT in MOVEit data-theft intrusions (May–June 2023) | FIN11 in Mandiant's updated assessment (initially UNC4857); the separately reported CL0P data-leak claim is not an alias inferred from the account artifact | State-Change |
Topic tags
These topic links open the consolidated family pages. They describe analytical relevance, not validated detection coverage.
Cloud and SaaS
Volumetric · Peer-Group · Sequence · Graph / Relationship · Geographic / ASN · Identity / Access · Data Movement · Negative Anomaly (Absence) · State-Change · Multi-Event Correlation
Network telemetry
Volumetric · Frequency / Rate · Temporal · Geographic / ASN · Rare Process / Service · Protocol / Application Usage
Identity and access
Frequency / Rate · Peer-Group · Sequence · Graph / Relationship · Geographic / ASN · Identity / Access · Data Movement · State-Change · Multi-Event Correlation
Endpoint telemetry
Temporal · Sequence · Rare Process / Service · Parent-Child Execution · Protocol / Application Usage · Negative Anomaly (Absence) · Multi-Event Correlation
Insider risk
Operational technology
Telemetry health
Application audit
Reuse and validation
ATT&CK currency: Mappings were reviewed on 2026-09-21; the technical revision uses Enterprise ATT&CK v19.2. The former T1562.001 now points to T1685 — Disable or Modify Tools; The former T1562.008 now points to T1685.002 — Disable or Modify Tools: Disable or Modify Cloud Log. The JSON retains these identifier transitions. Vendor finding names remain their vendor-defined identifiers.
The companion machine-readable evidence register is available as JSON. It keeps source URLs and publication dates separate from incident periods, and records both the observed behavior and the inferred detection opportunity. Case identifiers support deduplication across anomaly types.
To evaluate a proposed detector, preserve the source event IDs, normalize entity identifiers and time zones, define the comparison population, and test against both attack and legitimate activity. Freeze thresholds before evaluation. Report missing telemetry, false alerts per entity-day, incident recall and alert precision separately. A high anomaly score is neither group attribution nor an automatic containment decision.
Implementation boundary: Incident evidence does not validate a detector. Section 8 now uses maintained query files and explicit telemetry contracts; its execution report distinguishes functional tests from public-recording replay. Section 9 labels synthetic statistical results separately. Neither establishes production precision, recall, connector compatibility or universal thresholds.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.