Skip to main content

Incident register, tags and evidence boundaries

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

This expansion covers 14 operational anomaly families plus multi-event correlation: 15 navigation tags, 30 incident-to-topic mappings and 17 distinct case/campaign records, reviewed on 2026-09-21. A campaign record may summarize multiple victims; this is not a count of individual breaches. A repeated case is not independent evidence.

Reading the labels: “Observed” means reported by the named investigator, not reproduced in this research. Each anomaly interpretation and ATT&CK association is an author-derived mapping. Suggested telemetry is a collection plan, not a claim that it was available to the original victim. No new precision, recall, threshold or successful-detection result is asserted.

Scope: Fourteen headings describe operational feature families; the fifteenth, multi-event correlation, is a composition pattern that combines them. The companion Atlas has a broader statistical taxonomy; its linked categories explain the statistical concept and do not imply one-to-one equivalence. The existing generic example bullets remain illustrative scenarios, not extra documented incidents.

Incident register: evidence boundaries. Article-register snapshot reviewed 2026-09-21: 14 operational families plus correlation, 15 navigation tags, 17 distinct case/campaign records and 30 incident-to-topic mappings. These counts match the maintained register; they are not individual breach counts, independent confirmations or detector-performance measurements. Reported observations, author-inferred mappings and proposed telemetry have different evidence status. This register is not an anomaly type or a detector benchmark.
Figure 22. Incident register: evidence boundaries. Article-register snapshot reviewed 2026-09-21: 14 operational families plus correlation, 15 navigation tags, 17 distinct case/campaign records and 30 incident-to-topic mappings. These counts match the maintained register; they are not individual breach counts, independent confirmations or detector-performance measurements.ARTICLE SCOPE SNAPSHOT · USER-SUPPLIEDSources: Maintained incident register and source citations.
Text equivalent and full-size diagram

Reported observations, author-inferred mappings and proposed telemetry have different evidence status. This register is not an anomaly type or a detector benchmark.

Scope snapshot: 14 operational anomaly families plus one correlation pattern; 15 navigation tags; 17 distinct case or campaign records; 30 incident-to-topic mappings. Reviewed 2026-09-21.

Reported: a named investigator reports an observation; the article has not independently reproduced it. Inferred: the author maps behavior to an analytical view; a topic tag is not attribution or detector validation.

Proposed: suggested telemetry requires validation; a collection plan does not prove that the original victim had that visibility.

Keep each case identifier, investigator and source attached to every mapping. A repeated case is not independent evidence, and a campaign can include several victims. Neither counts nor topic tags establish precision, recall or successful detection.

Open original full-size asset

Case / campaign recordAttribution boundaryCrosslinked analytical views
UNC5537 and Snowflake customer data theft (2024)UNC5537, as tracked by Mandiant; customer-account compromise, not a demonstrated compromise of Snowflake itselfVolumetric · Geographic / ASN · Data Movement
HTTP/2 Rapid Reset DDoS campaign (August 2023)Operators not named in the cited reportVolumetric · Frequency / Rate
Midnight Blizzard compromise of Microsoft (Reported January 2024)Midnight Blizzard, as attributed by MicrosoftFrequency / Rate · Graph / Relationship · Geographic / ASN
SUNBURST in the SolarWinds supply-chain compromise (2020)UNC2452 in contemporaneous Mandiant reporting; a malware observation is not by itself group attributionTemporal · Protocol / Application Usage
Industroyer2 attempted disruption of a Ukrainian energy provider (8 April 2022)Sandworm, as assessed by ESET and CERT-UATemporal
Twitter insider access for a foreign official (Conduct addressed in the 2022 Abouammo conviction)Ahmad Abouammo, named in the conviction report; indictment allegations about other people are not treated as convictionsPeer-Group
Storm-1283 OAuth-enabled cryptomining (Reported December 2023)Storm-1283, as tracked by MicrosoftPeer-Group · Graph / Relationship · State-Change
UNC3944 help-desk compromise and SaaS data theft (2023–2024 investigations reported June 2024)UNC3944, as tracked by Mandiant; overlapping public names are not assumed to be exact aliasesSequence · Identity / Access · Data Movement · Multi-Event Correlation
BazarCall to Conti intrusion (2021 case reported on 1 August)Conti ransomware operators in this investigation; tools alone do not establish actor identitySequence · Rare Process / Service · Multi-Event Correlation
Storm-0558 forged-token mailbox access (2023)Storm-0558, as attributed by MicrosoftIdentity / Access
MESSAGETAP on telecommunications SMS servers (2019)APT41, as attributed by MandiantRare Process / Service
Lemon Duck exploitation of Exchange servers (March 2021 reporting)Lemon Duck activity in Microsoft's report; not reassigned to HAFNIUMParent-Child Execution
DoejoCrypt activity after Exchange exploitation (March 2021 reporting)DoejoCrypt activity in Microsoft's report; malware label, not a proven identity of the operatorParent-Child Execution
OilRig-associated RDAT at a telecommunications organization (April 2020 activity)OilRig association assessed by Unit 42; not an attribution inferred from DNS entropyProtocol / Application Usage
SCARLETEEL cloud intrusion (2023 reporting)SCARLETEEL is the operation label used by Sysdig, not an independently established actor identityNegative Anomaly (Absence)
AuKill use before ransomware deployment (January–February 2023 incidents)Ransomware incidents involving Medusa Locker or LockBit; no assertion that their operators are one groupNegative Anomaly (Absence)
LEMURLOOT in MOVEit data-theft intrusions (May–June 2023)FIN11 in Mandiant's updated assessment (initially UNC4857); the separately reported CL0P data-leak claim is not an alias inferred from the account artifactState-Change

Topic tags​

These topic links open the consolidated family pages. They describe analytical relevance, not validated detection coverage.

Cloud and SaaS​

Volumetric · Peer-Group · Sequence · Graph / Relationship · Geographic / ASN · Identity / Access · Data Movement · Negative Anomaly (Absence) · State-Change · Multi-Event Correlation

Network telemetry​

Volumetric · Frequency / Rate · Temporal · Geographic / ASN · Rare Process / Service · Protocol / Application Usage

Identity and access​

Frequency / Rate · Peer-Group · Sequence · Graph / Relationship · Geographic / ASN · Identity / Access · Data Movement · State-Change · Multi-Event Correlation

Endpoint telemetry​

Temporal · Sequence · Rare Process / Service · Parent-Child Execution · Protocol / Application Usage · Negative Anomaly (Absence) · Multi-Event Correlation

Insider risk​

Peer-Group

Operational technology​

Temporal

Telemetry health​

Negative Anomaly (Absence)

Application audit​

State-Change

Reuse and validation​

ATT&CK currency: Mappings were reviewed on 2026-09-21; the technical revision uses Enterprise ATT&CK v19.2. The former T1562.001 now points to T1685 — Disable or Modify Tools; The former T1562.008 now points to T1685.002 — Disable or Modify Tools: Disable or Modify Cloud Log. The JSON retains these identifier transitions. Vendor finding names remain their vendor-defined identifiers.

The companion machine-readable evidence register is available as JSON. It keeps source URLs and publication dates separate from incident periods, and records both the observed behavior and the inferred detection opportunity. Case identifiers support deduplication across anomaly types.

To evaluate a proposed detector, preserve the source event IDs, normalize entity identifiers and time zones, define the comparison population, and test against both attack and legitimate activity. Freeze thresholds before evaluation. Report missing telemetry, false alerts per entity-day, incident recall and alert precision separately. A high anomaly score is neither group attribution nor an automatic containment decision.

Implementation boundary: Incident evidence does not validate a detector. Section 8 now uses maintained query files and explicit telemetry contracts; its execution report distinguishes functional tests from public-recording replay. Section 9 labels synthetic statistical results separately. Neither establishes production precision, recall, connector compatibility or universal thresholds.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.