1200KM / tag
Peer-Group Anomaly — anomaly tag
11 related reference pages for anomaly: Peer-Group Anomaly.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation. Statistical concepts are hypotheses until implemented and evaluated on suitable telemetry.
Related pages
- T1078 Valid Accounts detections · detection
- T1087 Account Discovery detections · detection
- T1136 Create Account detections · detection
- T1543 Create or Modify System Process detections · detection
- T1548 Abuse Elevation Control Mechanism detections · detection
- T1552 Unsecured Credentials detections · detection
- T1567 Exfiltration Over Web Service detections · detection
- T1573 Encrypted Channel detections · detection
- T1580 Cloud Infrastructure Discovery detections · detection
- T1609 Container Administration Command detections · detection
- T1610 Deploy Container detections · detection
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.