Anomaly Detection Atlas: Behavior to Signals by Andrey PautovAnomaly Detection Atlas: Behavior to Signals by Andrey Pautov

Anomaly Detection Atlas: Behavior to Signals

Andrey Pautov

Andrey Pautov

Anomaly Detection Atlas: Behavior to Signals

I authored Anomaly Detection Atlas as one integrated research and reference project. It brings the foundations of my statistical-anomaly article into a maintained, cross-linked website that connects unusual behavior to measurable investigation hypotheses.

My contribution

My contribution combines statistical concepts, ATT&CK-aligned activity, security log sources, illustrated explanations and detection-rule references. Worked examples expose the hypothesis, normalized fields, query, fixture observations and interpretation limits. Third-party incident reporting and MITRE material remain credited to their original publishers.

Scope and limitations

The Atlas helps reviewers examine the reasoning and telemetry behind a detection approach. Anomaly labels and ATT&CK mappings do not prove maliciousness or validated coverage. Synthetic demonstrations do not establish production accuracy; operational use needs local collection checks, baselines, testing and analyst review.
Cover: research cover artwork; not measured telemetry.
Like this project

Posted Oct 1, 2026

Created a research reference connecting statistical anomaly concepts, ATT&CK activity, telemetry requirements and practical detection examples.