6,000x the normal median, off-hours, by a near-ghost user.
Two telnet sessions transferred 100+ MB each to a legacy on-premises device. 6,000x the normal median. Off-hours, by a near-ghost user with only 2 total logons ever.
The volume alone would be enough to flag. But it showed up off-hours, both times on a Tuesday, on a device with no process or file event monitoring. The user behind it had logged on twice, ever. And the device itself was a dark spot in the network: legacy, on-prem, no Azure presence, nothing but telnet.
No endpoint agent covered this device, no Azure telemetry existed for it, and nothing was logging its processes. Traditional security tools had no way to see it. Only network-level anomaly detection on raw traffic metadata could have caught this, and only because a baseline for normal behavior already existed to compare against.