UC-L3-013
After Hours Sensitive File Access
Windows Security Event Log
Use case development / Detect Insider Threats / Detect Unusual Data Access
sigma
Detection rule
title: Sensitive File Access Outside Business Hours
status: experimental
description: Detects access to sensitive files outside normal working hours
logsource:
product: windows
service: security
detection:
selection:
EventID: 4663
ObjectName|contains:
- '\HR\'
- '\Finance\'
- '\Legal\'
filter:
TimeOfDay|between: '08:00'..'18:00'
condition: selection and not filter
falsepositives:
- After hours work
- International teams
level: medium
tags:
- attack.collection
- attack.t1005Test cases
- Access HR folder after 6 PM
False positive guidance
Exclude known after-hours workers and adjust for timezones.