Access Anomaly Detector

Scan a file-access log for anomalies — off-hours access, sudden bursts of activity, and users touching an unusual number of files in a short window.

Drop a CSV with user, file, and timestamp columns

How to use the Access Anomaly Detector

  1. Prepare a CSV whose first row contains a user column (user or username), a file column (file, filename, or resource), and a timestamp column (timestamp, date, or time). Include one access event per row and use timestamps your browser can parse.
  2. Drop the CSV into the upload area. The page confirms how many valid events it loaded. If the file is not ready, choose Load Sample to try the detector.
  3. Set business-hours start and end using 24-hour values from 0 to 23. The start hour is included and the end hour is excluded; access times are evaluated in the browser's local time zone. Set the burst threshold to the number of event rows for one user within any five-minute window that should trigger a flag.
  4. Choose Scan for Anomalies. Review each flagged user's name, file, timestamp, and reason. A flag is a prompt to investigate, not proof of misuse. Choose Export Flagged Events to download the findings as CSV.

Finding the handful of events that actually matter

A busy file-access log can have thousands of routine entries hiding the few that are genuinely worth a second look — someone touching dozens of files in minutes, or activity logged well outside normal working hours. Manually scanning for that is impractical past a few hundred rows; automated flagging against rules you set isn't.

Why burst detection uses a sliding time window

Counting "how many files did this user touch within any 5-minute window" (rather than just a daily total) catches rapid, concentrated activity — the pattern most associated with bulk downloads or scripted access — without false-flagging someone who steadily works through files over a normal day.

What counts as "off-hours"?

Whatever business-hours window you configure — anything outside that start and end hour is flagged, so adjust it to match your actual working hours or time zone.

Does a flagged event mean something bad happened?

Not necessarily — flags highlight patterns worth reviewing, not confirmed incidents. Context (was this a scheduled backup job, a legitimate after-hours deadline) still matters.

Just want normal usage stats, not anomalies?

Use the Access Pattern Analyzer instead for most-accessed files and per-user totals without anomaly flagging.

User Reviews

5.0
1 review
  • 5★1
  • 4★0
  • 3★0
  • 2★0
  • 1★0
Write a review
Your rating *

Your email is never published. Reviews are moderated, and links aren't allowed.

What users are saying

Khan G

Nice tool

Works perfectly, It perfectly Scans a file-access log for anomalies..