Plenty of legitimate work happens at 11pm. Plenty of incidents do too. The difference is what else is happening at the same time. Vedric reads off-hours activity as one axis of a behavioral storyline, not as a standalone alert.
THE PROBLEM
Every SOC has been trained to ignore the "user logged in after hours" alert. Sales runs late. Engineering pushes before launches. International teams overlap unusual windows. Off-hours alone is low signal. Correlation with first-time command shapes, authentication anomalies, or host-level network drift can make it worth review.
A calendar window is the usual definition of "off-hours". The result is that anyone working a non-standard shift is constantly flagged, and the alert gets muted.
A 02:00 login by a global-on-call SRE is normal for that role. The same login by an HR coordinator is not. Without peer baselines the tool cannot tell which is which.
Even when off-hours is detected, most stacks fire it as its own alert and rely on humans to mentally correlate it with command activity in another tool. That correlation rarely happens in practice.
UEBA modules see the login. They cannot see what the user does once the session is open, which is where the real storyline lives.
Vedric tracks observed activity windows and combines temporal deviation with command, privilege, authentication, and host-level network drift. A late login alone is context; a first-time privileged command plus corroborating metadata can become a storyline.
The platform learns when each user normally works, including weekend cadence, recurring late shifts, and timezone variability. Off-hours is measured against the user's own pattern, not a single global window.
Peer baselines mean that on-call rotations, international coverage, and shift work are recognized as cohort-typical. The signal is bigger when the user is off-baseline both personally and against their peer group.
Off-hours alone is context. Off-hours plus command drift, authentication anomalies, or host-level outbound-byte/new-destination-count drift can promote a storyline. Each signal stays labeled by what its collector actually observed.
EXAMPLE SCENARIO · TIMELINE
A weekend login is not unusual for this user; they have done weekend work for two years. What is unusual is what the session does once it is open.
A standalone off-hours alert would have been muted by the SOC weeks ago. The detection landed because off-hours was treated as one axis of a multi-axis storyline, not as the standalone alert.
Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.
Read the full privacy stance →Early access is for teams who have given up on standalone time-of-day alerts and want temporal drift to mean something, only when it should.