Skip to main content

Provenance, review scope, and publication history

The unified Atlas combines the author's revised Malicious Activity as a Statistical Signal research with the existing activity-to-anomaly catalog. Consolidated on 27 September 2026. The incident research and figure review date remains 21 September 2026; consolidation is not a new incident investigation or a new detector test.

What was combined​

  • The complete current technical research is organized into foundations, fifteen operational views, an incident register, ATT&CK mapping, campaign analysis, telemetry, credential-access analysis, visibility limits, queries, validation, and references.
  • All 55 active figures occur once in the research path, with preserved evidence labels, original full-size assets, text equivalents, and nearby explanations. The cover is separate.
  • The 54 catalog rows retain their original anchors. This total includes rows with historical ATT&CK identifiers; it is not a count of active techniques or successful detectors.
  • Fourteen operational families and one correlation pattern are connected to the broader 118-concept statistical taxonomy and 175-category source taxonomy. Those taxonomies overlap and are not interchangeable.
  • Exact technique links lead to existing detection, simulation, tool, and collection references. Curated model-to-family relationships are editorial navigation, not assertions that an incident was detected by that model.

Source ownership and reproducibility​

The imported publication is pinned to archive commit a947508. Its full source, visual metadata, and incident register are hash-recorded in the integration manifest. The Atlas generator produces the research chapters from the imported source; generated chapters must not be edited independently.

The original article remains a publication snapshot so historical citations and anchors keep working. Its 44 superseded historical images are not promoted into current Atlas guidance. The new family pages and research path are the integrated reference.

Visual binaries are served from their existing publication URLs. This avoids duplicating large assets and preserves original hashes. The Atlas owns their placement and accessible presentation, not a modified raster copy.

Evidence review boundary​

This pass checked source preservation, scope counts, taxonomy separation, exact link identities, contextual navigation, and deployment behavior. The prior fact audit, incident register, and validation bundle remain available.

Historical incident claims and every source-to-row association in the older catalog were not independently re-audited in this consolidation. The older catalog's report links remain contextual associations, not newly certified evidence. No actor membership is inferred from a tool, statistical feature, or navigation link. Actor-profile links provide research context while retaining each source's attribution limits.

The reported functional tests, public-recording replay, and synthetic study are preserved results from the research revision. They were not rerun here, and they do not establish production precision, recall, connector compatibility, or safe automatic containment. Read the validation chapter before operational use.

Version and terminology checks​

NIST SP 800-94 is a February 2007 publication; its proposed revision did not become final. It supplies historical definitions, not a claim of a new standard. MITRE's April 2026 release notes document the Defense Evasion split into Stealth and Defense Impairment. Retained old catalog IDs are not silently migrated or counted as current-ID coverage.

Continue​

Research path · Family index · Model catalog · Visual index · Source repository