What is an anomaly alert?¶
An anomaly alert is generated when activity differs from a system’s expected or learned pattern.
The difference may involve time, location, device, volume, sequence, account behaviour or network activity.
Avoid the dangerous assumption¶
The dangerous assumption is that unusual activity is automatically malicious.
It is not.
An anomaly system may compare the event with the user’s previous behaviour, the behaviour of similar accounts or a statistical model. It may flag a first-time action, a sudden increase or a combination the system rarely sees.
That can identify activity traditional fixed rules would miss. But normal life is variable. Travel, new duties, software changes, incident response and unusual business demands can all produce legitimate anomalies.
The alert may contain a score, baseline, changed feature, account, device and time window. Investigators should establish what the system considered unusual and what data it used to learn normal behaviour.
A weak or incomplete baseline can produce misleading results. New accounts, seasonal activity and missing logs may all affect the model. The provider may also update the model over time.
Preserve the alert, underlying events, model or rule version where available and the explanation fields showing why it triggered. Compare the activity with known changes in the organisation or user’s circumstances.
Do not treat “anomalous” as a synonym for “malicious”. It means different from the model’s expectation.
Operational takeaway¶
An anomaly alert identifies activity that differed from an expected pattern, but investigators must understand the baseline, changed features and legitimate alternatives before treating it as evidence of compromise.