{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/system/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend","Elastic Agent","Kibana","Elastic Security","Auditd Manager","System","Windows","Fleet","Network Packet Capture"],"_cs_severities":["low"],"_cs_tags":["identity-and-access-audit","threat-detection","machine-learning","initial-access"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThis brief describes an Elastic Security machine learning rule designed to identify credential compromise and unauthorized access attempts by flagging user logons occurring at unusual times of day for a specific user. Developed by Elastic, this detection leverages data from Elastic Defend or the System integration, making it applicable across various endpoint and system environments. The rule calculates a baseline of normal logon hours for each user and then triggers an alert when a significant deviation is observed. This is crucial for defenders as it can expose attackers utilizing stolen credentials from different geographical locations or performing malicious activities outside typical business hours, potentially leading to unauthorized system access, data exfiltration, or further network penetration. The rule has a minimum stack version of 9.4.0 to use Entity Analytics fields for enhanced accuracy.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf an adversary successfully uses compromised credentials to log in at an unusual time, this can lead to unauthorized access to sensitive systems and data. This often precedes further malicious activities such as data exfiltration, lateral movement within the network, or the deployment of malware. While this rule detects anomalous behavior rather than a specific attack, the successful exploitation of valid accounts, as indicated by this anomaly, can result in significant reputational damage, regulatory fines, and operational disruption for affected organizations across any sector. The immediate impact is a breach of trust and unauthorized presence in the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInvestigate the user account flagged by the \u0026quot;Unusual Hour for a User to Logon\u0026quot; ML rule by contacting the account owner to verify the legitimacy of the logon activity.\u003c/li\u003e\n\u003cli\u003eEnable Elastic Defend or the System integration on all relevant endpoints and servers to ensure comprehensive log collection for logon events.\u003c/li\u003e\n\u003cli\u003eReview other alerts and user activity associated with the flagged user for the past 48 hours to identify broader suspicious behavior.\u003c/li\u003e\n\u003cli\u003eReset passwords for any confirmed compromised accounts and other potentially affected credentials as part of incident response.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T15:34:20Z","date_published":"2026-07-27T15:32:29Z","id":"https://feed.craftedsignal.io/briefs/2026-07-unusual-logon-hour/","summary":"An Elastic machine learning rule detects unusual user logon times, which can indicate credential compromise or unauthorized access, particularly when attackers operate from different time zones or during non-business hours, prompting investigation into the affected user account and related activities.","title":"Unusual Hour for a User to Logon","url":"https://feed.craftedsignal.io/briefs/2026-07-unusual-logon-hour/"}],"language":"en","title":"CraftedSignal Threat Feed - System","version":"https://jsonfeed.org/version/1.1"}