Unauthorised USB Device
High
Escalated
ALR-00043 · 2026-05-26T21:24:01Z
Description
Unauthorised USB mass storage device connected to AP-WIFI-03 by user 'f.hall'. Device blocked by Endpoint Agent endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:24:01
Event ingested by SOC365 Engine
21:24:05
EmilyAI triage started — correlation enrichment
21:24:10
EmilyAI confidence: 89% — escalated to human analyst
21:24:30
Alert assigned to analyst: Marcus Webb
21:25:43
Investigation started — querying SIEM and threat intelligence
21:32:11
Containment action taken — endpoint isolated
21:36:08
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00319 | 16h ago | Phishing Email Blocked | Medium | Investigating | AP-WIFI-03 |
| ALR-00415 | 16h ago | Certificate Anomaly | Low | Resolved | AP-WIFI-03 |
| ALR-00386 | 17h ago | Unauthorised USB Device | Medium | Escalated | WS-LAP-010 |
| ALR-00040 | 18h ago | Pass-the-Hash Detected | Low | False Positive | AP-WIFI-03 |
| ALR-00257 | 1d ago | Unauthorised USB Device | Informational | False Positive | AP-WIFI-03 |