Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an anomaly?

An anomaly is activity that looks different from the baseline used by a product or analyst.

It is unusual, not automatically malicious.

That distinction matters because anomaly-based detections are very good at finding things worth checking — but they still need context.

The baseline defines what counts as unusual

A product might compare:

  • a user with their own history;
  • a device with its normal behaviour;
  • one employee with similar employees;
  • the organisation with a wider population.

An anomaly could be:

  • new country;
  • unusual working hour;
  • new device;
  • unfamiliar process;
  • unusual data volume;
  • first access to a sensitive resource.

Baselines can be incomplete

A new employee may have very little history.

A traveller may suddenly appear from another country.

An emergency administrator may work at 03:00.

A system migration may create activity never seen before.

Example anomaly alert
Account: jpatelObserved: login from AmsterdamBaseline: UK-only access over previous 30 daysOperational context: corporate VPN exits in AmsterdamAssessment: explained by normal VPN use

The anomaly was real. The malicious interpretation was not.

Ask what changed and why

Useful questions include:

  • what baseline was used;
  • how much history existed;
  • which feature was unusual;
  • whether the behaviour fits travel, role change or maintenance;
  • whether compromise or insider activity fits better;
  • what happened immediately afterwards.

The practical point is: use anomalies to focus the enquiry. Then decide whether the deviation reflects hostile activity, legitimate change or a poor baseline.

Reference: CIM-022Cyber Incidents & Offender Methods