Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF041
- Created: 28th July 2026
- Updated: 28th July 2026
- Contributor: The ITM Team
Cross-System Activity Fragmentation
A subject distributes related activity across multiple systems, applications, repositories, identities, devices, locations, or communication channels so that no individual source presents a complete account of the behavior. Each component may appear legitimate, low risk, or unrelated when reviewed independently, while correlation across sources reveals a coordinated sequence.
Cross-System Activity Fragmentation may involve identifying information in one system, retrieving it through another, staging it on a separate endpoint, and transferring it through a third service. The subject may alternate between corporate devices, virtual desktops, mobile applications, cloud platforms, collaboration tools, business applications, or administrative interfaces to prevent any single control from observing the full activity.
Investigators may encounter individually benign events, such as a file preview, a small export, a message attachment, or a cloud upload, that only become significant when placed into a shared timeline. Differences in timestamps, identity formats, logging standards, retention periods, and system ownership may further obstruct correlation.
This behavior should be distinguished from ordinary multi-system workflows. Classification requires evidence that fragmentation reduced visibility, attribution, or detection, or that the distribution of activity was inconsistent with the subject’s established business process.