References
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
Incident-source register (September 2026 expansion)
- Mandiant. UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion. Published 2024-06-10; reviewed 2026-09-21.
- Cloudflare. HTTP/2 Rapid Reset: deconstructing the record-breaking attack. Published 2023-10-10; reviewed 2026-09-21.
- Microsoft. Midnight Blizzard: Guidance for responders on nation-state attack. Published 2024-01-25; reviewed 2026-09-21.
- Mandiant. SUNBURST Additional Technical Details. Published 2020-12-24; reviewed 2026-09-21.
- ESET. Industroyer2: Industroyer reloaded. Published 2022-04-12; reviewed 2026-09-21.
- US Department of Justice. Former Twitter Employee Found Guilty of Acting as an Agent of a Foreign Government and Unlawfully Sharing Twitter User Information. Published 2022-08-10; reviewed 2026-09-21.
- US Department of Justice. Superseding indictment, United States v. Abouammo et al., filed July 28, 2020. Published 2020-07-28; reviewed 2026-09-21.
- Microsoft. Threat actors misuse OAuth applications to automate financially driven attacks. Published 2023-12-12; reviewed 2026-09-21.
- Mandiant. UNC3944 Targets SaaS Applications. Published 2024-06-13; reviewed 2026-09-21.
- The DFIR Report. BazarCall to Conti Ransomware via Trickbot and Cobalt Strike. Published 2021-08-01; reviewed 2026-09-21.
- Microsoft. Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email. Published 2023-07-11; reviewed 2026-09-21.
- Mandiant. MESSAGETAP: Who's Reading Your Text Messages?. Published 2019-10-31; reviewed 2026-09-21.
- Microsoft. Analyzing attacks taking advantage of the Exchange Server vulnerabilities. Published 2021-03-25; reviewed 2026-09-21.
- Palo Alto Networks Unit 42. OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Published 2020-07-22; reviewed 2026-09-21.
- Sysdig. How to Detect SCARLETEEL with Sysdig Secure. Published 2023-03-29; reviewed 2026-09-21.
- Sophos. AuKill EDR killer malware abuses Process Explorer driver. Published 2023-04-19; reviewed 2026-09-21.
- Mandiant. Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft. Published 2023-06-02; reviewed 2026-09-21.
Statistical and implementation references
- NIST. Guide to Intrusion Detection and Prevention Systems, SP 800–94, 2007.
- Chandola, Banerjee and Kumar. Anomaly Detection: A Survey, 2009; author technical-report version hosted by the University of Minnesota. The publisher endpoint restricted automated access during this revision; the university copy was accessible.
- MITRE. ATT&CK version history and April 2026 changes. Mapping edition: Enterprise v19.2.
- Microsoft. Sysmon reference, Security event 4662, Kusto time-window joins, and Kusto emulator limitations.
- Splunk. Attack Data repository. Exact recording paths, SHA-256 hashes and license are in the downloadable dataset manifest.
- LANL. Comprehensive, Multi-Source Cyber-Security Events. Proposed follow-up source; not used to generate this revision's results.
Additional incident and correction references
- CSRB. Review of the Summer 2023 Microsoft Exchange Online Intrusion, 2024.
- Microsoft. Volt Typhoon investigation, May 2023.
- Mandiant. APT41 Has Arisen From the DUST, July 2024.
- SentinelOne. SmoothOperator / 3CX investigation, March 2023.
- AWS. GuardDuty IAM findings and RDS IAM authentication limitations. The token-generation observability discrepancy remains unresolved.
Companion research
- Anomaly Detection Atlas — statistical definitions and detection design.
- Threat Matrix — behavior-oriented ATT&CK exploration.
- AdversaryGraph — evidence and investigation workflows. Enrichment and correlation support investigation; they do not validate attribution automatically.
Follow My Work
I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware-analysis projects, AI-security research, open-source tools, labs, and technical guides.