OFF-HOURS ACCESS DETECTION

Off-hours access is a footnote until it is part of a pattern.

Plenty of legitimate work happens at 11pm. Plenty of incidents do too. The difference is what else is happening at the same time. Vedric reads off-hours activity as one axis of a behavioral storyline, not as a standalone alert.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

Threshold-based off-hours alerts are pure noise.

Every SOC has been trained to ignore the "user logged in after hours" alert. Sales runs late. Engineering pushes before launches. International teams overlap unusual windows. Off-hours alone is low signal. Correlation with first-time command shapes, authentication anomalies, or host-level network drift can make it worth review.

WHY CURRENT APPROACHES FALL SHORT

Why standalone off-hours alerts get suppressed.

STATIC TIME WINDOWS

A calendar window is the usual definition of "off-hours". The result is that anyone working a non-standard shift is constantly flagged, and the alert gets muted.

NO PEER CONTEXT

A 02:00 login by a global-on-call SRE is normal for that role. The same login by an HR coordinator is not. Without peer baselines the tool cannot tell which is which.

NO BEHAVIORAL CORRELATION

Even when off-hours is detected, most stacks fire it as its own alert and rely on humans to mentally correlate it with command activity in another tool. That correlation rarely happens in practice.

AUTH-ONLY SIGNAL

UEBA modules see the login. They cannot see what the user does once the session is open, which is where the real storyline lives.

HOW VEDRIC HELPS

Time, treated as one axis among many.

Vedric tracks observed activity windows and combines temporal deviation with command, privilege, authentication, and host-level network drift. A late login alone is context; a first-time privileged command plus corroborating metadata can become a storyline.

01 /PERSONAL WINDOWS

Hours baseline per primary identity

The platform learns when each user normally works, including weekend cadence, recurring late shifts, and timezone variability. Off-hours is measured against the user's own pattern, not a single global window.

02 /PEER COHORT

Off-hours that is normal for the role does not fire

Peer baselines mean that on-call rotations, international coverage, and shift work are recognized as cohort-typical. The signal is bigger when the user is off-baseline both personally and against their peer group.

03 /CORRELATED

Promoted only when other axes agree

Off-hours alone is context. Off-hours plus command drift, authentication anomalies, or host-level outbound-byte/new-destination-count drift can promote a storyline. Each signal stays labeled by what its collector actually observed.

EXAMPLE SCENARIO · TIMELINE

A weekend session that is half normal and half not.

A weekend login is not unusual for this user; they have done weekend work for two years. What is unusual is what the session does once it is open.

  1. T+01
    T+01 Saturday 22:00 - user logs in. Personal pattern allows late and weekend work. No alert.
  2. T+02
    T+02 22:15 - user runs a database query against a partner-data warehouse that is not in their personal six-month query set. Scope drift logged. No alert yet.
  3. T+03
    T+03 22:30 - same session runs an archive utility with a command shape not previously observed for this identity. Compression-tool deviation logged.
  4. T+04
    T+04 22:45 - multiple correlated deviations on the same identity: temporal context plus scope plus compression. Storyline materializes. One alert reaches the analyst.
  5. T+05
    T+05 - Vedric AI triage retrieves the tenant-scoped baseline, peer context, recent storylines, and the bounded process/command/network evidence. It has no file contents or per-file read history.
  6. T+06
    T+06 - analyst reviews. Pattern is consistent with pre-departure staging. Admin-gated response: limit user privileges, require manager review on Monday, audit trail exported.
OUTCOME

A standalone off-hours alert would have been muted by the SOC weeks ago. The detection landed because off-hours was treated as one axis of a multi-axis storyline, not as the standalone alert.

WHAT VEDRIC SURFACES

Time as context, not as alert.

VEDRIC SURFACES
  • Per-user working-window baselines that adapt to the actual user pattern
  • Peer-cohort context so on-call and shift work do not generate noise
  • Correlation between temporal deviation and command, scope, privilege, and egress drift
  • Promotion of multi-axis storylines
  • Tenant-isolated AI triage with full evidence chain
VEDRIC DOES NOT DO
  • Fire on every login outside a static business-hours calendar
  • Treat all weekend or evening activity as suspicious
  • Track productivity, idle time, or activity scoring
  • Capture content of off-hours sessions
  • Take action without admin approval and a stated reason
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Off-hours signal that is actually signal.

Early access is for teams who have given up on standalone time-of-day alerts and want temporal drift to mean something, only when it should.

Request Early AccessTalk to security teamResponse within one business day.