Jurnal Sains, Nalar, dan Aplikasi Teknologi Informasi
Vol. 5 No. 2 (2026)

Cloud Infrastructure Security: Detecting and Analyzing Attacks on Windows Server 2019

Fathony, Ikhwan Alfath Nurul (Unknown)
Mareta, Affix (Unknown)
Wardhani, Olivia (Unknown)
Suseno, Hakkan Azrul (Unknown)
Ghifari, Galang Ahmad (Unknown)



Article Info

Publish Date
13 Jul 2026

Abstract

Cloud infrastructure security represents a critical challenge in addressing cybersecurity threats, particularly for internet-facing services such as Remote Desktop Protocol (RDP) and SQL Server. This research investigates cloud infrastructure security based on Windows Server 2019 through the development of a proactive and responsive attack detection and analysis framework using the Wazuh platform as Security Information and Event Management (SIEM) integrated with the MITRE ATT&CK framework. The research method employs an experimental approach with continuous monitoring for 30 days of two Windows Server 2019 units running RDP and SQL Server services. Attack simulations were conducted using eight different scenarios including RDP brute force, SQL Server authentication brute force, port scanning, privilege escalation, lateral movement, data exfiltration, persistence mechanisms, and defense evasion. Monitoring results revealed 110,492 total security events, dominated by 109,057 authentication failures (98.7%) and only 171 successful authentications, with the remainder consisting of other activities such as port scanning and process execution. The Wazuh-based detection system with MITRE ATT&CK integration successfully mapped 15 attack techniques, 10 of which were actively observed during the 30-day monitoring period, with a detection rate of 93.2%, false positive rate of 6.8%, and average response time of 2.4 seconds. Compliance analysis showed 87% compliance with PCI DSS, 91% with NIST 800-53, 85% with HIPAA, and 89% with GDPR. The research concludes that the integration of Wazuh SIEM with the MITRE ATT&CK framework is effective in detecting and analyzing cyber attacks on Windows Server 2019, with practical contributions in the form of implementation guidelines for rule-based detection and correlation rules for multi-stage attack detection.

Copyrights © 2026






Journal Info

Abbrev

jurnalsnati

Publisher

Subject

Computer Science & IT

Description

Jurnal SNATi publishes original research articles on various topics related to computer science, information technology, systems engineering, and complementary ...