| ALT-2405Ransomware canary file modified on file serverDET-0311 Canary File Tamper | critical | 60% | SRV-SQL-01m.tanaka | T1486 | Windows Event Log | Unassigned | Investigating | 1970-01-01 08:37:00Z |
| ALT-2412Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Command | critical | 98% | SRV-SQL-01r.wijaya | T1566.001, T1059.001 | Sysmon | You | Closed | 1970-01-01 08:27:00Z |
| ALT-2426LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Access | critical | 84% | LNX-BUILD-07svc_backup | T1003.001 | EDR | S. Hartono | New | 1970-01-01 08:16:00Z |
| ALT-2411Scheduled task created for persistenceDET-0165 Suspicious Scheduled Task | medium | 68% | WS-FIN-014d.kusuma | T1053.005 | Sysmon | A. Pratama | Investigating | 1970-01-01 07:44:00Z |
| ALT-2425Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Burst | high | 74% | WS-ENG-231adm.helpdesk | T1110.003 | Entra ID | S. Hartono | Closed | 1970-01-01 07:16:00Z |
| ALT-2416Impossible travel sign-inDET-0044 Geo-velocity Anomaly | medium | 61% | WS-FIN-014adm.helpdesk | T1078 | Entra ID | Unassigned | False Positive | 1970-01-01 06:35:00Z |
| ALT-2423Scheduled task created for persistenceDET-0165 Suspicious Scheduled Task | medium | 66% | SRV-FILE-03adm.helpdesk | T1053.005 | Sysmon | S. Hartono | New | 1970-01-01 06:27:00Z |
| ALT-2401Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Burst | high | 90% | WS-ENG-231r.wijaya | T1110.003 | Entra ID | Unassigned | Investigating | 1970-01-01 05:54:00Z |
| ALT-2419SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Create | high | 90% | WS-FIN-014m.tanaka | T1021.002 | Windows Event Log | R. Wijaya | New | 1970-01-01 05:04:00Z |
| ALT-2421Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristic | low | 58% | WS-FIN-014s.hartono | T1568.002 | DNS | S. Hartono | Investigating | 1970-01-01 04:11:00Z |
| ALT-2428Impossible travel sign-inDET-0044 Geo-velocity Anomaly | medium | 97% | WS-HR-002l.ferreira | T1078 | Entra ID | R. Wijaya | New | 1970-01-01 04:07:00Z |
| ALT-2435Scheduled task created for persistenceDET-0165 Suspicious Scheduled Task | medium | 58% | SRV-WEB-02m.tanaka | T1053.005 | Sysmon | S. Hartono | New | 1970-01-01 03:58:00Z |
| ALT-2409Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristic | low | 65% | SRV-FILE-03a.pratama | T1568.002 | DNS | Unassigned | Closed | 1970-01-01 03:11:00Z |
| ALT-2402LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Access | critical | 83% | WS-FIN-014a.pratama | T1003.001 | EDR | A. Pratama | Closed | 1970-01-01 03:02:00Z |
| ALT-2429Ransomware canary file modified on file serverDET-0311 Canary File Tamper | critical | 82% | SRV-WEB-02a.pratama | T1486 | Windows Event Log | You | Escalated | 1970-01-01 02:42:00Z |
| ALT-2407SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Create | high | 61% | WS-FIN-014a.pratama | T1021.002 | Windows Event Log | D. Kusuma | False Positive | 1970-01-01 02:36:00Z |
| ALT-2414LSASS memory access by unsigned binaryDET-0203 Credential Dumping via Process Access | critical | 97% | SRV-DC-01a.pratama | T1003.001 | EDR | A. Pratama | False Positive | 1970-01-01 01:57:00Z |
| ALT-2404Impossible travel sign-inDET-0044 Geo-velocity Anomaly | medium | 62% | WS-HR-002a.pratama | T1078 | Entra ID | R. Wijaya | Escalated | 1970-01-01 01:43:00Z |
| ALT-2400Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Command | critical | 61% | WS-FIN-014a.pratama | T1566.001, T1059.001 | Sysmon | Unassigned | Escalated | 1970-01-01 01:33:00Z |
| ALT-2424Encoded PowerShell spawned by Microsoft WordDET-0142 Office Child Process — Encoded Command | critical | 62% | SRV-WEB-02adm.helpdesk | T1566.001, T1059.001 | Sysmon | R. Wijaya | Closed | 1970-01-01 01:30:00Z |
| ALT-2410Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usage | low | 68% | WS-FIN-014m.tanaka | T1078 | Entra ID | D. Kusuma | False Positive | 1970-01-01 00:59:00Z |
| ALT-2417Ransomware canary file modified on file serverDET-0311 Canary File Tamper | critical | 67% | WS-HR-002adm.helpdesk | T1486 | Windows Event Log | R. Wijaya | Investigating | 1970-01-01 00:52:00Z |
| ALT-2413Password spray against Entra ID tenantDET-0087 Distributed Authentication Failure Burst | high | 95% | SRV-DC-01r.wijaya | T1110.003 | Entra ID | Unassigned | New | 1970-01-01 00:09:00Z |
| ALT-2420Web shell uploaded to public web serverDET-0221 Web Directory Script Write | high | 91% | WS-HR-002s.hartono | T1505.003 | Web Server | A. Pratama | Closed | 1969-12-31 23:27:00Z |
| ALT-2422Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usage | low | 61% | SRV-WEB-02a.pratama | T1078 | Entra ID | R. Wijaya | New | 1969-12-31 23:17:00Z |
| ALT-2418Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rule | medium | 61% | SRV-WEB-02a.pratama | T1114.003 | Microsoft 365 | S. Hartono | New | 1969-12-31 22:51:00Z |
| ALT-2433Excessive DNS NXDOMAIN from single hostDET-0033 DGA Heuristic | low | 68% | SRV-FILE-03r.wijaya | T1568.002 | DNS | S. Hartono | Escalated | 1969-12-31 22:17:00Z |
| ALT-2431SMB lateral movement from finance workstationDET-0158 Admin Share Write + Service Create | high | 86% | SRV-SQL-01l.ferreira | T1021.002 | Windows Event Log | D. Kusuma | Investigating | 1969-12-31 20:09:00Z |
| ALT-2434Legacy authentication protocol usage spikeDET-0091 Legacy Auth Usage | low | 67% | WS-ENG-231a.pratama | T1078 | Entra ID | R. Wijaya | Closed | 1969-12-31 19:32:00Z |
| ALT-2415Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beacon | high | 74% | WS-HR-002svc_backup | T1071.004 | DNS | A. Pratama | Escalated | 1969-12-31 19:18:00Z |
| ALT-2408Web shell uploaded to public web serverDET-0221 Web Directory Script Write | high | 84% | SRV-WEB-02r.wijaya | T1505.003 | Web Server | A. Pratama | New | 1969-12-31 18:58:00Z |
| ALT-2430Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rule | medium | 96% | SRV-WEB-02l.ferreira | T1114.003 | Microsoft 365 | You | New | 1969-12-31 18:54:00Z |
| ALT-2403Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beacon | high | 83% | SRV-DC-01r.wijaya | T1071.004 | DNS | Unassigned | New | 1969-12-31 18:52:00Z |
| ALT-2427Beaconing DNS pattern to newly registered domainDET-0119 Periodic DNS Beacon | high | 95% | LNX-BUILD-07adm.helpdesk | T1071.004 | DNS | S. Hartono | Investigating | 1969-12-31 18:34:00Z |
| ALT-2432Web shell uploaded to public web serverDET-0221 Web Directory Script Write | high | 67% | WS-FIN-014s.hartono | T1505.003 | Web Server | R. Wijaya | Investigating | 1969-12-31 18:29:00Z |
| ALT-2406Suspicious inbox rule created to delete security mailDET-0076 Malicious Inbox Rule | medium | 79% | SRV-WEB-02r.wijaya | T1114.003 | Microsoft 365 | Unassigned | New | 1969-12-31 18:19:00Z |