JELAJAH SOC
YO

Operations

Alert Center

Every detection raised by the SIEM lands here. Work the queue top-down and set a verdict on each alert.

AlertSeverityConf.Host / UserMITRESourceAssigneeStatusTime
ALT-2405Ransomware canary file modified on file serverDET-0311 Canary File Tampercritical60%SRV-SQL-01m.tanakaT1486Windows Event LogUnassignedInvestigating1970-01-01 08:37:00Z
ALT-2412Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Commandcritical98%SRV-SQL-01r.wijayaT1566.001, T1059.001SysmonYouClosed1970-01-01 08:27:00Z
ALT-2426LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Accesscritical84%LNX-BUILD-07svc_backupT1003.001EDRS. HartonoNew1970-01-01 08:16:00Z
ALT-2411Scheduled task created for persistenceDET-0165 Suspicious Scheduled Taskmedium68%WS-FIN-014d.kusumaT1053.005SysmonA. PratamaInvestigating1970-01-01 07:44:00Z
ALT-2425Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Bursthigh74%WS-ENG-231adm.helpdeskT1110.003Entra IDS. HartonoClosed1970-01-01 07:16:00Z
ALT-2416Impossible travel sign-inDET-0044 Geo-velocity Anomalymedium61%WS-FIN-014adm.helpdeskT1078Entra IDUnassignedFalse Positive1970-01-01 06:35:00Z
ALT-2423Scheduled task created for persistenceDET-0165 Suspicious Scheduled Taskmedium66%SRV-FILE-03adm.helpdeskT1053.005SysmonS. HartonoNew1970-01-01 06:27:00Z
ALT-2401Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Bursthigh90%WS-ENG-231r.wijayaT1110.003Entra IDUnassignedInvestigating1970-01-01 05:54:00Z
ALT-2419SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Createhigh90%WS-FIN-014m.tanakaT1021.002Windows Event LogR. WijayaNew1970-01-01 05:04:00Z
ALT-2421Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristiclow58%WS-FIN-014s.hartonoT1568.002DNSS. HartonoInvestigating1970-01-01 04:11:00Z
ALT-2428Impossible travel sign-inDET-0044 Geo-velocity Anomalymedium97%WS-HR-002l.ferreiraT1078Entra IDR. WijayaNew1970-01-01 04:07:00Z
ALT-2435Scheduled task created for persistenceDET-0165 Suspicious Scheduled Taskmedium58%SRV-WEB-02m.tanakaT1053.005SysmonS. HartonoNew1970-01-01 03:58:00Z
ALT-2409Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristiclow65%SRV-FILE-03a.pratamaT1568.002DNSUnassignedClosed1970-01-01 03:11:00Z
ALT-2402LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Accesscritical83%WS-FIN-014a.pratamaT1003.001EDRA. PratamaClosed1970-01-01 03:02:00Z
ALT-2429Ransomware canary file modified on file serverDET-0311 Canary File Tampercritical82%SRV-WEB-02a.pratamaT1486Windows Event LogYouEscalated1970-01-01 02:42:00Z
ALT-2407SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Createhigh61%WS-FIN-014a.pratamaT1021.002Windows Event LogD. KusumaFalse Positive1970-01-01 02:36:00Z
ALT-2414LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Accesscritical97%SRV-DC-01a.pratamaT1003.001EDRA. PratamaFalse Positive1970-01-01 01:57:00Z
ALT-2404Impossible travel sign-inDET-0044 Geo-velocity Anomalymedium62%WS-HR-002a.pratamaT1078Entra IDR. WijayaEscalated1970-01-01 01:43:00Z
ALT-2400Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Commandcritical61%WS-FIN-014a.pratamaT1566.001, T1059.001SysmonUnassignedEscalated1970-01-01 01:33:00Z
ALT-2424Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Commandcritical62%SRV-WEB-02adm.helpdeskT1566.001, T1059.001SysmonR. WijayaClosed1970-01-01 01:30:00Z
ALT-2410Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usagelow68%WS-FIN-014m.tanakaT1078Entra IDD. KusumaFalse Positive1970-01-01 00:59:00Z
ALT-2417Ransomware canary file modified on file serverDET-0311 Canary File Tampercritical67%WS-HR-002adm.helpdeskT1486Windows Event LogR. WijayaInvestigating1970-01-01 00:52:00Z
ALT-2413Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Bursthigh95%SRV-DC-01r.wijayaT1110.003Entra IDUnassignedNew1970-01-01 00:09:00Z
ALT-2420Web shell uploaded to public web serverDET-0221 Web Directory Script Writehigh91%WS-HR-002s.hartonoT1505.003Web ServerA. PratamaClosed1969-12-31 23:27:00Z
ALT-2422Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usagelow61%SRV-WEB-02a.pratamaT1078Entra IDR. WijayaNew1969-12-31 23:17:00Z
ALT-2418Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rulemedium61%SRV-WEB-02a.pratamaT1114.003Microsoft 365S. HartonoNew1969-12-31 22:51:00Z
ALT-2433Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristiclow68%SRV-FILE-03r.wijayaT1568.002DNSS. HartonoEscalated1969-12-31 22:17:00Z
ALT-2431SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Createhigh86%SRV-SQL-01l.ferreiraT1021.002Windows Event LogD. KusumaInvestigating1969-12-31 20:09:00Z
ALT-2434Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usagelow67%WS-ENG-231a.pratamaT1078Entra IDR. WijayaClosed1969-12-31 19:32:00Z
ALT-2415Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beaconhigh74%WS-HR-002svc_backupT1071.004DNSA. PratamaEscalated1969-12-31 19:18:00Z
ALT-2408Web shell uploaded to public web serverDET-0221 Web Directory Script Writehigh84%SRV-WEB-02r.wijayaT1505.003Web ServerA. PratamaNew1969-12-31 18:58:00Z
ALT-2430Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rulemedium96%SRV-WEB-02l.ferreiraT1114.003Microsoft 365YouNew1969-12-31 18:54:00Z
ALT-2403Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beaconhigh83%SRV-DC-01r.wijayaT1071.004DNSUnassignedNew1969-12-31 18:52:00Z
ALT-2427Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beaconhigh95%LNX-BUILD-07adm.helpdeskT1071.004DNSS. HartonoInvestigating1969-12-31 18:34:00Z
ALT-2432Web shell uploaded to public web serverDET-0221 Web Directory Script Writehigh67%WS-FIN-014s.hartonoT1505.003Web ServerR. WijayaInvestigating1969-12-31 18:29:00Z
ALT-2406Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rulemedium79%SRV-WEB-02r.wijayaT1114.003Microsoft 365UnassignedNew1969-12-31 18:19:00Z