Alert Center

Alert Center

Triage, assign, and investigate alerts across identity, endpoint, email, and cloud.

AlertSeverityStatusMITRESourceUserDeviceAnalystTime
Impossible travel activity detected
ALT-24817 · IdentityProtection.ImpossibleTravel
highin progressT1078 — Valid AccountsEntra IDkate.morgan@contoso.comLT-KMORGAN-01Elena Rossi2m ago
Suspicious PowerShell encoded command
ALT-24816 · EDR.Behavior.Powershell.EncodedCmd
criticalnewT1059.001 — PowerShellEndpoint EDRsvc-backupSRV-DB-076m ago
Password spray against tenant
ALT-24815 · IdentityProtection.PasswordSpray
highescalatedT1110.003 — Password SprayingEntra IDmultipleMarcus Chen14m ago
Malicious attachment quarantined
ALT-24814 · Email.Attachment.Malware
mediumresolvedT1566.001 — Spearphishing AttachmentEmail Gatewayinvoice-inbox@contoso.comAmelia Ward38m ago
Lateral movement via SMB admin share
ALT-24813 · Network.LateralMovement.AdminShare
criticalin progressT1021.002 — SMB/Windows Admin SharesEndpoint EDRd.holtFIN-DESK-22Priya Nair1h ago
Legacy authentication protocol used
ALT-24812 · IdentityProtection.LegacyAuth
lowclosedT1078.004 — Cloud AccountsEntra IDreports.svcAmelia Ward2h ago
USB mass storage inserted (executive)
ALT-24811 · Endpoint.Device.USBInserted
mediumopenT1091 — Replication Through Removable MediaEndpoint EDRjames.walkerLT-EXEC-JWALKERYusuf Demir3h ago
Suspicious OAuth consent grant
ALT-24810 · M365.OAuth.SuspiciousConsent
highnewT1528 — Steal Application Access TokenM365 Defendersarah.chen@contoso.com3h ago
Showing 8 of 248 alerts