StealthTalk - After hours work

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies systematic off-hours activity for a single StealthTalk user - repeated authentications outside the user's configured working hours OR on weekends, observed across at least two distinct calendar days within a 48-hour window. The pattern is a common indicator of credential misuse, insider threat, or compromise of the account by an attacker operating in a different timezone. An "off-hours event" is one where IsWeekend=true OR DeviationMinutes >= 180 (i.e. >= 3 hours after the configured

Attribute Value
Type Analytic Rule
Solution StealthTalk
ID e3a8b2f1-5c7d-4d89-9b6e-0f1a2c3d4e5f
Severity Low
Status Available
Kind Scheduled
Tactics InitialAccess, DefenseEvasion, Persistence
Techniques T1078
Required Connectors StealthTalkAnomalousAuth
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StealthTalkAnomalousAuth_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to StealthTalk