Alert Center
Triage, assign, and investigate alerts across identity, endpoint, email, and cloud.
| Alert | Severity | Status | MITRE | Source | User | Device | Analyst | Time | |
|---|---|---|---|---|---|---|---|---|---|
Impossible travel activity detected ALT-24817 · IdentityProtection.ImpossibleTravel | high | in progress | T1078 — Valid Accounts | Entra ID | kate.morgan@contoso.com | LT-KMORGAN-01 | Elena Rossi | 2m ago | |
Suspicious PowerShell encoded command ALT-24816 · EDR.Behavior.Powershell.EncodedCmd | critical | new | T1059.001 — PowerShell | Endpoint EDR | svc-backup | SRV-DB-07 | — | 6m ago | |
Password spray against tenant ALT-24815 · IdentityProtection.PasswordSpray | high | escalated | T1110.003 — Password Spraying | Entra ID | multiple | — | Marcus Chen | 14m ago | |
Malicious attachment quarantined ALT-24814 · Email.Attachment.Malware | medium | resolved | T1566.001 — Spearphishing Attachment | Email Gateway | invoice-inbox@contoso.com | — | Amelia Ward | 38m ago | |
Lateral movement via SMB admin share ALT-24813 · Network.LateralMovement.AdminShare | critical | in progress | T1021.002 — SMB/Windows Admin Shares | Endpoint EDR | d.holt | FIN-DESK-22 | Priya Nair | 1h ago | |
Legacy authentication protocol used ALT-24812 · IdentityProtection.LegacyAuth | low | closed | T1078.004 — Cloud Accounts | Entra ID | reports.svc | — | Amelia Ward | 2h ago | |
USB mass storage inserted (executive) ALT-24811 · Endpoint.Device.USBInserted | medium | open | T1091 — Replication Through Removable Media | Endpoint EDR | james.walker | LT-EXEC-JWALKER | Yusuf Demir | 3h ago | |
Suspicious OAuth consent grant ALT-24810 · M365.OAuth.SuspiciousConsent | high | new | T1528 — Steal Application Access Token | M365 Defender | sarah.chen@contoso.com | — | — | 3h ago |
Showing 8 of 248 alerts