OFF-HOURS ACCESS DETECTION

Off-hours access is a footnote until it is part of a pattern.

Plenty of legitimate work happens at 11pm. Plenty of incidents do too. The difference is what else is happening at the same time. Vedric reads off-hours activity as one axis of a behavioral storyline, not as a standalone alert.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

Threshold-based off-hours alerts are pure noise.

Every SOC has been trained to ignore the "user logged in after hours" alert. Sales runs late. Engineering pushes before launches. International teams overlap weird windows. Off-hours alone is a low-signal primitive. The high-signal pattern is when off-hours combines with commands the user has never run, scope drift onto systems they do not normally touch, or destinations they have not used. Detection has to live at that intersection.

WHY CURRENT APPROACHES FALL SHORT

Why standalone off-hours alerts get suppressed.

STATIC TIME WINDOWS

Most tools define "off-hours" as a calendar window. The result is that anyone working a non-standard shift is constantly flagged, and the alert gets muted.

NO PEER CONTEXT

A 02:00 login by a global-on-call SRE is normal for that role. The same login by an HR coordinator is not. Without peer baselines the tool cannot tell which is which.

NO BEHAVIORAL CORRELATION

Even when off-hours is detected, most stacks fire it as its own alert and rely on humans to mentally correlate it with command activity in another tool. That correlation rarely happens in practice.

AUTH-ONLY SIGNAL

UEBA modules see the login. They cannot see what the user does once the session is open, which is where the real storyline lives.

HOW VEDRIC HELPS

Time, treated as one axis among many.

Vedric tracks each user own working window (not a calendar threshold) and combines temporal deviation with command, scope, privilege, and egress drift. A 22:00 login is logged. A 22:00 login plus a privileged query the user has not run in six months plus access to a system outside their scope is a storyline.

01 /PERSONAL WINDOWS

Hours baseline per primary identity

The platform learns when each user normally works, including weekend cadence, recurring late shifts, and timezone variability. Off-hours is measured against the user own pattern, not a single global window.

02 /PEER COHORT

Off-hours that is normal for the role does not fire

Peer baselines mean that on-call rotations, international coverage, and shift work are recognized as cohort-typical. The signal is bigger when the user is off-baseline both personally and against their peer group.

03 /CORRELATED

Promoted only when other axes agree

Off-hours alone gets logged silently. Off-hours plus command drift, scope drift, or egress to an unusual destination triggers the storyline. The analyst surface is the correlated case.

EXAMPLE SCENARIO · TIMELINE

A weekend session that is half normal and half not.

A weekend login is not unusual for this user; they have done weekend work for two years. What is unusual is what the session does once it is open.

  1. T+01
    T+01 Saturday 22:00 - user logs in. Personal pattern allows late and weekend work. No alert.
  2. T+02
    T+02 22:15 - user runs a database query against a partner-data warehouse that is not in their personal six-month query set. Scope drift logged. No alert yet.
  3. T+03
    T+03 22:30 - same session compresses files from a project they have not actively touched in months. Compression-utility deviation against personal baseline.
  4. T+04
    T+04 22:45 - multiple correlated deviations on the same identity: temporal context plus scope plus compression. Storyline materializes. One alert reaches the analyst.
  5. T+05
    T+05 - Vedric AI triage retrieves the user baseline, the peer cohort baseline, recent storylines on the same primary identity, and forensic context for the involved files. Verdict produced with full evidence chain.
  6. T+06
    T+06 - analyst reviews. Pattern is consistent with pre-departure staging. Admin-gated response: limit user privileges, require manager review on Monday, audit trail exported.
OUTCOME

A standalone off-hours alert would have been muted by the SOC weeks ago. The detection landed because off-hours was treated as one axis of a multi-axis storyline, not as the standalone alert.

WHAT VEDRIC SURFACES

Time as context, not as alert.

VEDRIC SURFACES
  • Per-user working-window baselines that adapt to the actual user pattern
  • Peer-cohort context so on-call and shift work do not generate noise
  • Correlation between temporal deviation and command, scope, privilege, and egress drift
  • Promotion of multi-axis storylines, not standalone time-of-day alerts
  • Tenant-isolated AI triage with full evidence chain
VEDRIC DOES NOT DO
  • Fire on every login outside a static business-hours calendar
  • Treat all weekend or evening activity as suspicious
  • Track productivity, idle time, or activity scoring
  • Capture content of off-hours sessions
  • Take action without admin approval and a stated reason
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Off-hours signal that is actually signal.

Early access is for teams who have given up on standalone time-of-day alerts and want temporal drift to mean something, only when it should.

Request Early AccessTalk to security teamResponse within one business day.