Unauthorised USB Device
Low
Resolved
ALR-00008 · 2026-05-22T01:13:18Z
Description
Unauthorised USB mass storage device connected to WS-LAP-011 by user 'k.brown'. Device blocked by Dark Web Monitor endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:13:18
Event ingested by SOC365 Engine
01:13:21
EmilyAI triage started — correlation enrichment
01:13:31
EmilyAI confidence: 90% — escalated to human analyst
01:13:51
Alert assigned to analyst: EmilyAI (auto)
01:14:44
Investigation started — querying SIEM and threat intelligence
01:22:54
Containment action taken — endpoint isolated
01:31:17
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00264 | 43m ago | Phishing Email Blocked | Medium | False Positive | WS-LAP-011 |
| ALR-00399 | 6h ago | Unauthorised USB Device | High | Investigating | SRV-WEB-01 |
| ALR-00004 | 13h ago | Data Exfiltration Attempt | Medium | False Positive | WS-LAP-011 |
| ALR-00357 | 13h ago | Unauthorised USB Device | Critical | Investigating | SW-CORE-01 |
| ALR-00377 | 19h ago | Unauthorised USB Device | Medium | Investigating | WS-PC-006 |