Main Article Content
Abstract
Cloud infrastructure security represents a critical challenge in addressing cybersecurity threats, particularly for internet-facing services such as Remote Desktop Protocol (RDP) and SQL Server. This research investigates cloud infrastructure security based on Windows Server 2019 through the development of a proactive and responsive attack detection and analysis framework using the Wazuh platform as Security Information and Event Management (SIEM) integrated with the MITRE ATT&CK framework. The research method employs an experimental approach with continuous monitoring for 30 days of two Windows Server 2019 units running RDP and SQL Server services. Attack simulations were conducted using eight different scenarios including RDP brute force, SQL Server authentication brute force, port scanning, privilege escalation, lateral movement, data exfiltration, persistence mechanisms, and defense evasion. Monitoring results revealed 110,492 total security events, dominated by 109,057 authentication failures (98.7%) and only 171 successful authentications, with the remainder consisting of other activities such as port scanning and process execution. The Wazuh-based detection system with MITRE ATT&CK integration successfully mapped 15 attack techniques, 10 of which were actively observed during the 30-day monitoring period, with a detection rate of 93.2%, false positive rate of 6.8%, and average response time of 2.4 seconds. Compliance analysis showed 87% compliance with PCI DSS, 91% with NIST 800-53, 85% with HIPAA, and 89% with GDPR. The research concludes that the integration of Wazuh SIEM with the MITRE ATT&CK framework is effective in detecting and analyzing cyber attacks on Windows Server 2019, with practical contributions in the form of implementation guidelines for rule-based detection and correlation rules for multi-stage attack detection.
Keywords
Article Details
Copyright (c) 2026 Ikhwan Alfath Nurul Fathony, Affix Mareta, Olivia Wardhani, Hakkan Azrul Suseno, Galang Ahmad Ghifari

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
References
- National Institute of Standards and Technology, "Security and Privacy Controls for Information Systems and Organizations," NIST Special Publication 800-53 Rev. 5, Sep. 2020, doi: 10.6028/NIST.SP.800-53r5. DOI: https://doi.org/10.6028/NIST.SP.800-53r5
- Center for Internet Security, "CIS Microsoft Windows Server 2019 Benchmark v2.0.0," CIS Benchmarks, Dec. 2023. [Online]. Available: https://www.cisecurity.org/benchmark/windows_server
- MITRE Corporation, "MITRE ATT&CK Framework v18," MITRE ATT&CK, Oct. 2025. [Online]. Available: https://attack.mitre.org/
- International Organization for Standardization, "Information Security, Cybersecurity and Privacy Protection - Information Security Management Systems," ISO/IEC 27001:2022, Oct. 2022. [Online]. Available: https://www.iso.org/standard/27001
- PCI Security Standards Council, "Payment Card Industry Data Security Standard v4.0," PCI DSS Requirements and Testing Procedures, Mar. 2024. [Online]. Available: https://www.pcisecuritystandards.org/
- European Commission, "General Data Protection Regulation (GDPR)," Regulation (EU) 2016/679, May 2018. [Online]. Available: https://gdpr-info.eu/
- U.S. Department of Health and Human Services, "Health Insurance Portability and Accountability Act Security Rule," 45 CFR Parts 160, 162, and 164, Feb. 2023. [Online]. Available: https://www.hhs.gov/hipaa
- Wazuh Inc., "Wazuh 4.10 Documentation: The Open Source Security Platform," Wazuh Technical Documentation, 2025. [Online]. Available: https://documentation.wazuh.com/
- Microsoft Corporation, "Windows Server 2019 Security Baseline," Microsoft Security Compliance Toolkit, Nov. 2024. [Online]. Available: https://www.microsoft.com/security/
- OWASP Foundation, "OWASP Top 10:2021 - The Ten Most Critical Web Application Security Risks," OWASP Standards, 2021. [Online]. Available: https://owasp.org/Top10/
- C. Kurniawan and A. Triayudi, "Reconstruction and Detection of Gambling Web Defacement Attack Using Wazuh and Velociraptor," in 2024 International Conference on Information Technology Research and Innovation (ICITRI), Sep. 2024, pp. 257–262, doi: 10.1109/ICITRI62858.2024.10699215. DOI: https://doi.org/10.1109/ICITRI62858.2024.10699215
- S. Moiz, A. Majid, A. Basit, M. Ebrahim, A. A. Abro, and M. Naeem, "Security and Threat Detection through Cloud-Based Wazuh Deployment," in 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), Tandojam, Pakistan, 2024, pp. 1–5. DOI: https://doi.org/10.1109/KHI-HTC60760.2024.10482206
- S. Roy, E. Panaousis, C. Noakes, A. Laszka, S. Panda, and G. Loukas, "SoK: The MITRE ATT&CK Framework in Research and Practice," arXiv preprint arXiv:2304.07411, 2023.
- G. González-Granadillo, S. González-Zarzosa, and R. Diaz, "Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures," Sensors, vol. 21, no. 14, Art. no. 4759, Jul. 2021, doi: 10.3390/s21144759. DOI: https://doi.org/10.3390/s21144759
- J. Manzoor, A. Waleed, A. F. Jamali, and A. Masood, "Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs," PLOS ONE, vol. 19, no. 3, Mar. 2024, doi: 10.1371/journal.pone.0301183. DOI: https://doi.org/10.1371/journal.pone.0301183
- F. I. F. Farrel, M. K. I. Mardianto, and A. S. Qamar, "Implementation of Security Information & Event Management (SIEM) Wazuh with Active Response and Telegram Notification for Mitigating Brute Force Attacks on The GT-I2TI USAKTI Information System," Intelmatics, vol. 4, no. 1, pp. 1–7, Feb. 2024, doi: 10.25105/itm.v4i1.18529. DOI: https://doi.org/10.25105/itm.v4i1.18529
- P. Stöckle, B. Grobauer, and A. Pretschner, "Automated Implementation of Windows-related Security-Configuration Guides," in Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering (ASE '20), Sep. 2020, pp. 598–610, doi: 10.1145/3324884.3416540. DOI: https://doi.org/10.1145/3324884.3416540
- A. L. Robertson, "ATT&CK v18: The Detection Overhaul You've Been Waiting For," MITRE ATT&CK Blog, Oct. 28, 2025. [Online]. Available: https://medium.com/mitre-attack/att-ck-v18-detection-strategies-more-adversary-insights-8f82d839ee9e
- S. Benabderrahmane, G. Berrada, J. Cheney, and P. Valtchev, "A Rule Mining-Based Advanced Persistent Threats Detection System," arXiv preprint arXiv:2105.10053, 2021. DOI: https://doi.org/10.24963/ijcai.2021/494
- Z. S. Younus and M. Alanezi, "Detect and Mitigate Cyberattacks Using SIEM," in 2023 16th International Conference on Developments in eSystems Engineering (DeSE), Dec. 2023, pp. 510–515, doi: 10.1109/DeSE60595.2023.10469387. DOI: https://doi.org/10.1109/DeSE60595.2023.10469387
References
National Institute of Standards and Technology, "Security and Privacy Controls for Information Systems and Organizations," NIST Special Publication 800-53 Rev. 5, Sep. 2020, doi: 10.6028/NIST.SP.800-53r5. DOI: https://doi.org/10.6028/NIST.SP.800-53r5
Center for Internet Security, "CIS Microsoft Windows Server 2019 Benchmark v2.0.0," CIS Benchmarks, Dec. 2023. [Online]. Available: https://www.cisecurity.org/benchmark/windows_server
MITRE Corporation, "MITRE ATT&CK Framework v18," MITRE ATT&CK, Oct. 2025. [Online]. Available: https://attack.mitre.org/
International Organization for Standardization, "Information Security, Cybersecurity and Privacy Protection - Information Security Management Systems," ISO/IEC 27001:2022, Oct. 2022. [Online]. Available: https://www.iso.org/standard/27001
PCI Security Standards Council, "Payment Card Industry Data Security Standard v4.0," PCI DSS Requirements and Testing Procedures, Mar. 2024. [Online]. Available: https://www.pcisecuritystandards.org/
European Commission, "General Data Protection Regulation (GDPR)," Regulation (EU) 2016/679, May 2018. [Online]. Available: https://gdpr-info.eu/
U.S. Department of Health and Human Services, "Health Insurance Portability and Accountability Act Security Rule," 45 CFR Parts 160, 162, and 164, Feb. 2023. [Online]. Available: https://www.hhs.gov/hipaa
Wazuh Inc., "Wazuh 4.10 Documentation: The Open Source Security Platform," Wazuh Technical Documentation, 2025. [Online]. Available: https://documentation.wazuh.com/
Microsoft Corporation, "Windows Server 2019 Security Baseline," Microsoft Security Compliance Toolkit, Nov. 2024. [Online]. Available: https://www.microsoft.com/security/
OWASP Foundation, "OWASP Top 10:2021 - The Ten Most Critical Web Application Security Risks," OWASP Standards, 2021. [Online]. Available: https://owasp.org/Top10/
C. Kurniawan and A. Triayudi, "Reconstruction and Detection of Gambling Web Defacement Attack Using Wazuh and Velociraptor," in 2024 International Conference on Information Technology Research and Innovation (ICITRI), Sep. 2024, pp. 257–262, doi: 10.1109/ICITRI62858.2024.10699215. DOI: https://doi.org/10.1109/ICITRI62858.2024.10699215
S. Moiz, A. Majid, A. Basit, M. Ebrahim, A. A. Abro, and M. Naeem, "Security and Threat Detection through Cloud-Based Wazuh Deployment," in 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), Tandojam, Pakistan, 2024, pp. 1–5. DOI: https://doi.org/10.1109/KHI-HTC60760.2024.10482206
S. Roy, E. Panaousis, C. Noakes, A. Laszka, S. Panda, and G. Loukas, "SoK: The MITRE ATT&CK Framework in Research and Practice," arXiv preprint arXiv:2304.07411, 2023.
G. González-Granadillo, S. González-Zarzosa, and R. Diaz, "Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures," Sensors, vol. 21, no. 14, Art. no. 4759, Jul. 2021, doi: 10.3390/s21144759. DOI: https://doi.org/10.3390/s21144759
J. Manzoor, A. Waleed, A. F. Jamali, and A. Masood, "Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs," PLOS ONE, vol. 19, no. 3, Mar. 2024, doi: 10.1371/journal.pone.0301183. DOI: https://doi.org/10.1371/journal.pone.0301183
F. I. F. Farrel, M. K. I. Mardianto, and A. S. Qamar, "Implementation of Security Information & Event Management (SIEM) Wazuh with Active Response and Telegram Notification for Mitigating Brute Force Attacks on The GT-I2TI USAKTI Information System," Intelmatics, vol. 4, no. 1, pp. 1–7, Feb. 2024, doi: 10.25105/itm.v4i1.18529. DOI: https://doi.org/10.25105/itm.v4i1.18529
P. Stöckle, B. Grobauer, and A. Pretschner, "Automated Implementation of Windows-related Security-Configuration Guides," in Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering (ASE '20), Sep. 2020, pp. 598–610, doi: 10.1145/3324884.3416540. DOI: https://doi.org/10.1145/3324884.3416540
A. L. Robertson, "ATT&CK v18: The Detection Overhaul You've Been Waiting For," MITRE ATT&CK Blog, Oct. 28, 2025. [Online]. Available: https://medium.com/mitre-attack/att-ck-v18-detection-strategies-more-adversary-insights-8f82d839ee9e
S. Benabderrahmane, G. Berrada, J. Cheney, and P. Valtchev, "A Rule Mining-Based Advanced Persistent Threats Detection System," arXiv preprint arXiv:2105.10053, 2021. DOI: https://doi.org/10.24963/ijcai.2021/494
Z. S. Younus and M. Alanezi, "Detect and Mitigate Cyberattacks Using SIEM," in 2023 16th International Conference on Developments in eSystems Engineering (DeSE), Dec. 2023, pp. 510–515, doi: 10.1109/DeSE60595.2023.10469387. DOI: https://doi.org/10.1109/DeSE60595.2023.10469387