What is an anomaly?¶
An anomaly is activity that looks different from the baseline used by a product or analyst.
It is unusual, not automatically malicious.
That distinction matters because anomaly-based detections are very good at finding things worth checking — but they still need context.
The baseline defines what counts as unusual¶
A product might compare:
- a user with their own history;
- a device with its normal behaviour;
- one employee with similar employees;
- the organisation with a wider population.
An anomaly could be:
- new country;
- unusual working hour;
- new device;
- unfamiliar process;
- unusual data volume;
- first access to a sensitive resource.
Baselines can be incomplete¶
A new employee may have very little history.
A traveller may suddenly appear from another country.
An emergency administrator may work at 03:00.
A system migration may create activity never seen before.
The anomaly was real. The malicious interpretation was not.
Ask what changed and why¶
Useful questions include:
- what baseline was used;
- how much history existed;
- which feature was unusual;
- whether the behaviour fits travel, role change or maintenance;
- whether compromise or insider activity fits better;
- what happened immediately afterwards.
The practical point is: use anomalies to focus the enquiry. Then decide whether the deviation reflects hostile activity, legitimate change or a poor baseline.