https://www.sans.org/reading-room/whitepapers/forensics/incident-identification-outlier-analysis-36740