Terminology Index

Glossary

2953 terms

Open concept maps
O
17

Outlier Detection

A hunting and analysis technique that finds data points deviating markedly from the norm, unusual hosts, accounts, or behaviors, on the principle that statistical outliers often warrant investigation as possible threats.

Outlier detection surfaces items that stand apart from the bulk of the data: a host with far more connections than its peers, an account behaving unlike similar ones, a process seen almost nowhere else. By baselining normal and flagging deviations, it helps hunters and analysts focus on the unusual, where threats often hide. It is a core data-driven hunting technique, related to frequency and long-tail analysis, and to anomaly detection more broadly.

Introduced in: Threat Hunting Fundamentals

Examples

  • Flagging a host with far more outbound connections than its peers.
  • Surfacing an account behaving unlike others in its role.
  • Investigating a process seen on almost no other systems.
P
15