Skip to main content

How Attackers Suppress Anomaly Visibility

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

Separate reported tradecraft from untested claims about defeating a specific detector.

MechanismEvidence or analytical implicationWhat this research does not establish
Distributed activityMidnight Blizzard's residential proxies motivate identity-level correlation alongside source-level counts.That all tenant-local analytics failed or that every source stayed below every threshold.
Valid accounts and native toolsVolt Typhoon motivates role, actor and change-context analysis.That native commands are indistinguishable in every available source, or command lines are the only evidence.
In-process behaviorA detector requiring a child process misses activity that does not create one.That Sysmon image-load or remote-thread events cover every injection mechanism.
Low-rate collectionSmall transfers can avoid a large-transfer rule; longer windows may expose accumulation.A measured recall advantage without replay and representative benign traffic.
Provider-side activitySome SaaS transfers bypass a customer's endpoint/perimeter sensors.That no identity, application, provider or destination evidence exists.
Baseline contaminationIncluding the scored event in training or accepting attacker activity as normal can mask deviations.That a specific historical actor poisoned a particular model unless a source documents it.
Collection interruptionMissing logs reduce observability and may distort statistical denominators.That a missing event proves deliberate evasion rather than outage, filtering, retention or parser failure.

The campaign-specific sources and boundaries are in Section 4. For an operational analytic, publish its expected blind spots next to the query—not only in a distant disclaimer.

A detector can miss at different layers. Different failure layers require different remedies. More complex scoring cannot recover events the pipeline never collected. This is a diagnostic map, not a sourced chronology for any particular actor.
Figure 50. A detector can miss at different layers. Different failure layers require different remedies. More complex scoring cannot recover events the pipeline never collected.CONCEPTUAL MODELSources: NIST SP 800-94.
Text equivalent and full-size diagram

This is a diagnostic map, not a sourced chronology for any particular actor.

  1. Behavior. Low-rate or in-process activity.
  2. Sensor. Wrong position or missing source.
  3. Data pipeline. Drops, filters, clock or parser errors.
  4. Model. Wrong cohort or contaminated baseline.
  • Investigate the layer. Record which assumption failed and test an alternative source or analytic.
  • Avoid circular reasoning. A missing alert does not prove intentional evasion or absence of compromise.

Open original full-size asset · Open narrow-layout SVG