Managed SOC Services
Jul 31, 2026
Karan Patel

Attackers Are Working Around the Clock, So Are We: FoxRadar360

Attackers Are Working Around the Clock, So Are We: FoxRadar360

details hero

There is a specific hour when most organizations are least able to defend themselves, and adversaries have known it for years. It is not a secret, it is not sophisticated, and it does not require any particular skill to exploit. It simply requires patience and a calendar.

The uncomfortable part is that this is a solved problem in every other operational discipline. Hospitals staff overnight. Manufacturing runs shifts. Airlines fly at 3 a.m. with fully staffed operations centres. Security is one of the few functions where an organization will invest heavily in detection capability and then leave that capability unattended for roughly two thirds of every week.

This post walks through what actually happens during an off-hours intrusion, hour by hour, then covers what real continuous coverage requires and how to tell whether yours is genuine or nominal.

Anatomy of an Intrusion That Starts at 11 p.m. Friday

The timeline below is composite rather than a specific case, but every stage reflects patterns that recur consistently in ransomware and data theft incidents.

11:14 p.m. Friday: Initial Access

A credential purchased from a broker works against a remote access gateway. The password is valid, there is no second factor on that path, and the authentication succeeds cleanly.

Somewhere a log entry records a successful login from an unfamiliar autonomous system. The detection rule that would flag it exists and fires correctly. The alert arrives in a queue.

11:40 p.m.: Establishing Position

Commercial remote management software is installed, chosen specifically because it blends into normal administrative activity and does not resemble malware. Persistence is established without anything a signature would catch.

A second alert fires on unusual software installation. It joins the first.

1:20 a.m. Saturday: Discovery

Directory enumeration begins. File shares are mapped, backup infrastructure is located, and credential material is hunted across the systems the compromised account can reach.

This is the noisiest phase of the entire intrusion. Enumeration bursts, administrative share access, and credential access attempts generate several more alerts. The queue now holds five related events that, correlated, describe an attack in progress.

Nobody is reading the queue.

3:45 a.m.: Privilege Escalation

An attack path from the compromised standard account to domain administrative access is identified and followed, exploiting accumulated permissions and a service account with more rights than anyone remembers granting.

6:10 a.m.: Defense Evasion and Backup Destruction

Security tooling is stopped on key systems. Shadow copies are deleted. Backup repositories are accessed with the newly obtained credentials and destroyed.

Shadow copy deletion fires a high-severity alert. It is the clearest pre-encryption indicator in the entire sequence, and the window between it and deployment is typically under an hour.

8:30 a.m.: Exfiltration

Data is staged and transferred through a legitimate cloud storage service, blending into ordinary outbound traffic patterns.

11:00 p.m. Saturday: Deployment

Encryption is pushed across the estate through management tooling, timed so that it runs uninterrupted for the remainder of the weekend.

Monday, 8:15 a.m.

The first person to open the alert console finds thirty-two hours of clearly documented intrusion, correlated, severity-ranked, and entirely accurate. The detection worked flawlessly. The organization is still encrypted.

What Went Wrong, and What Did Not

The instructive part of that timeline is what functioned correctly.

The tooling detected. The rules fired. The correlation logic assembled the events. Every technical control performed as designed and produced an accurate record of an attack from the first hour.

What failed was the interval between an alert existing and a human acting on it. That interval is not a technology property. It is a staffing and authority property, and it is where the outcome was actually determined.

There were at least four points in that timeline where intervention would have changed everything. At 11:14 p.m., disabling the account and revoking sessions ends it before anything else happens. At 1:20 a.m., isolating the host during discovery prevents escalation. At 6:10 a.m., responding to shadow copy deletion still saves the backups. Even at 8:30 a.m., interrupting exfiltration limits the extortion leverage substantially.

Each of those interventions required someone awake with authority to act. None required a better platform.

Organizations wanting to establish honestly what would have happened in their own environment at each of those points can assess that with FoxRadar360, because the answer is usually different from what the tooling inventory suggests.

Why the Off-Hours Advantage Persists

Three structural factors keep this working for attackers.

Timing Is a Planning Input, Not Luck

Ransomware deployment clusters on Friday evenings and ahead of major holidays for a straightforward reason: encryption that begins at 11 p.m. Friday may run for sixty hours before anyone notices, while the same payload deployed on Tuesday morning generates help desk tickets within twenty minutes.

The same logic applies to data theft. Large outbound transfers that would prompt a bandwidth review during business hours blend into backup windows and batch jobs overnight.

Time Zones Do the Work for Them

If your team sits in one region and your adversary sits eight or ten hours away, their normal working day maps precisely onto your quiet hours. No special tradecraft is required. They simply work office hours in their own location.

For organizations with distributed infrastructure, this compounds. Some part of the estate is always outside the attention of whoever is currently awake.

Automation Removed the Slack

The window between initial access and meaningful impact has compressed to hours. Enumeration, privilege path analysis, and lateral movement are heavily scripted. A defensive model calibrated around next-business-day triage is calibrated to a threat that stopped existing several years ago.

What Genuine Continuous Coverage Requires

The phrase gets used loosely enough to be nearly meaningless. Here is what separates real from nominal.

Capacity, Not Just Availability

A single on-call analyst carrying a pager is coverage in the narrowest sense. Someone will eventually respond. That person cannot simultaneously triage a queue, investigate a suspected compromise, coordinate with an infrastructure team, preserve evidence, and make containment decisions while half awake at 3 a.m.

Real capacity means enough staffed analyst hours to handle a genuine incident at the worst possible time, plus escalation to senior responders when the situation exceeds first-line skill. Everything else is a hope with a rota attached.

Handoff Discipline

Incidents get lost between shifts far more often than they get lost in detection. A structured transfer of open investigations, working hypotheses, pending actions, and the reasoning behind them is what prevents an intrusion from being effectively restarted every eight hours.

Follow-the-sun models, where every shift is somebody's normal working day, generally produce better alertness at the cost of more handoffs. Rotating shifts keep context tighter but wear people down, and fatigued analysts miss things. Either works with disciplined handoff. Neither works without it.

Authority Delegated in Advance

Detection speed only matters if it converts into response speed. That requires deciding, in writing and before any incident, which containment actions can be taken immediately without further approval.

Low blast radius actions belong in that category at any hour: isolating a single endpoint, disabling a specific account, revoking active sessions and tokens, blocking a specific outbound destination, quarantining a mailbox. A false positive on any of these costs one person some inconvenience.

Broader actions still need a decision-maker, but that person should be named in advance along with a backup, with criteria documented rather than debated live at 4 a.m.

Session Revocation as Standard Practice

In identity-driven intrusions, disabling an account does nothing about tokens already issued. Containment that stops at account disablement leaves an attacker fully authenticated with a valid session while the responder believes the incident is closed.

Verify that your identity platform enforces revocation immediately rather than at the next token refresh. Test it before you need it.

Signals Prioritized for the Hours They Fire In

Certain events warrant immediate escalation regardless of the hour, because they have few benign explanations overnight and short windows before consequences.

Shadow copy deletion. Security service tampering. Backup repository access from unexpected accounts. Credential access attempts against the local security subsystem. Administrative group membership changes outside a change window. Service accounts authenticating interactively. Conditional access policy modifications. Mass installation of remote management tooling.

These belong in a category that wakes someone up, not in a queue for morning triage.

Where Automation Helps and Where It Stops

Automation is the reason continuous coverage is affordable, and misapplying it is the reason some programs get worse after adopting it.

What It Handles Well

Enrichment and context assembly, so an analyst starting at 3 a.m. begins with asset criticality, user history, related events, and threat intelligence already attached rather than spending the first ten minutes gathering facts.

Correlation and clustering, which reduces a queue of thirty events to one incident with a narrative.

Low blast radius containment on high-confidence detections, where the cost of a false positive is one workstation offline and the cost of a false negative is an encrypted estate.

Investigation summarization and handoff documentation, which directly supports the shift discipline described above.

What It Does Not Handle

Ambiguity, business context, and accountability for consequential decisions. A model produces fluent output regardless of whether the underlying reasoning is sound, and a confidently wrong verdict attached to a real intrusion is worse than no verdict.

The structural requirement is traceability. Every automated conclusion must be inspectable back to the specific evidence supporting it, because the analyst needs to extend that reasoning during the incident and the organization needs to defend it afterward.

Automation buys analysts time. It does not replace the judgment that determines whether an unusual pattern is a migration nobody mentioned or an intrusion in progress.

The Economics of Round-the-Clock Coverage

The obstacle for most organizations is arithmetic rather than conviction.

Genuine twenty-four hour coverage with meaningful capacity, including escalation depth and leave cover, requires roughly eight to twelve analysts. For organizations with security teams of three to six people responsible for everything, that is not a hiring plan. It is a different organization.

The alternatives are honest to name. Extending business hours partially reduces exposure without closing it, and attackers will simply operate in whatever window remains. An on-call rotation provides availability without capacity and burns out the people carrying it. Managed detection and response provides the staffing without building the team, which is why it exists as a category.

Whichever route makes sense, the decision should be made explicitly rather than defaulted into. Most organizations have not decided to leave nights and weekends uncovered; they have simply never costed the alternative. Working through what coverage would actually look like against your specific estate is a conversation worth having with FoxRadar360 before an incident forces the arithmetic.

Testing Whether Your Coverage Is Real

Assumptions about after-hours capability are rarely tested, and they are frequently wrong.

Run an exercise that starts at 11 p.m. on a Friday. Not a tabletop at 2 p.m. with everyone present. Use only the contact methods your plan actually documents, involving the people who would genuinely be on call. The findings are uncomfortable and always useful.

Verify your escalation contacts quarterly. People change roles and phone numbers change. Stale contact lists are discovered at the worst possible moment, and a list that lives only in the collaboration platform an attacker just compromised is not an escalation path.

Measure acknowledgment time by hour of day. If your overnight number is materially worse than your daytime number, your coverage is nominal.

Test containment mechanics, not just authority. Confirm that whoever is on call can actually isolate a host and revoke sessions with the credentials they hold at 3 a.m., rather than discovering the permissions sit with someone unreachable.

Sample closed alerts for what was missed. Particularly those closed on Monday mornings. Bulk closure of weekend backlogs is where genuine detections go to die.

Metrics That Hold the Program Accountable

Time to acknowledge, segmented by hour and day of week. The single clearest indicator of whether coverage is real.

Time to containment, reported as a distribution. Averages hide the long tail where damaging incidents live. The ninety-fifth percentile and an explanation of the outliers reveal more than a mean.

Overnight detection performance specifically. Detections that fired outside business hours and what happened next.

Escalation accuracy. How often incidents escalated warranted it, and how often something that should have escalated did not.

False negative sampling. Re-examine closed alerts independently, weighted toward off-hours closures.

Handoff continuity. Whether investigations open at shift change were correctly resumed, which is invisible until it fails.

Key Takeaways

The composite timeline at the start of this post is not a story about a security program with bad tooling. Every control worked. The rules fired, the correlation held, and the severity ranking was correct. What determined the outcome was that thirty-two hours passed between the first accurate alert and the first human to read it.

That gap is the actual product being bought when an organization invests in continuous coverage. Not better detection, though tuning helps. Not more telemetry, though gaps matter. The specific thing being purchased is the interval between an alert existing and someone with authority acting on it, at whatever hour the alert happens to fire.

Closing that interval requires four things together: staffed capacity rather than an on-call pager, disciplined handoff so investigations survive shift boundaries, containment authority agreed in writing before an incident rather than debated during one, and automation applied to enrichment and correlation so that human judgment is spent on judgment.

Attackers chose these hours deliberately, and they will keep choosing them for as long as the choice keeps working. The organizations that stop being reliably profitable targets are the ones where 3 a.m. on a Saturday looks operationally the same as 10 a.m. on a Tuesday.

To review what would actually happen in your environment at each stage of that timeline, and where the first intervention point realistically sits, start a conversation with the team at FoxRadar360.

Your Threat-Free Future Is One Click Away

Let FoxRadar360 transform your business into a secure, monitored, and threat-resilient operation. Schedule your SOC demo in seconds, simple and stress-free.  

title-icon
Cloud Monitoring
title-icon
Incident Response
title-icon
Compliance Support
title-icon
Threat Intelligence
title-icon
Intelligent TDIR + CTEM
title-icon
SIEM Integration
title-icon
Endpoint Detection and Response
title-icon
Proactive Cyber Risk Management