Unauthorised USB Device
Medium
Open
ALR-00063 · 2026-04-07T16:06:28Z
Description
Unauthorised USB mass storage device connected to SRV-FILE-01 by user 'k.brown'. Device blocked by Email Gateway endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:06:28
Event ingested by SOC365 Engine
16:06:29
EmilyAI triage started — correlation enrichment
16:06:39
EmilyAI confidence: 78% — escalated to human analyst
16:07:10
Alert assigned to analyst: Emma Richardson
16:07:27
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00429 | 9h ago | Ransomware Behaviour Detected | Medium | Resolved | SRV-FILE-01 |
| ALR-00398 | 14h ago | DecoyPulse Honeypot Triggered | Informational | Resolved | SRV-FILE-01 |
| ALR-00237 | 18h ago | Unauthorised USB Device | Medium | Open | WS-PC-003 |
| ALR-00197 | 1d ago | Unauthorised USB Device | Medium | False Positive | WS-PC-001 |
| ALR-00335 | 1d ago | Shadow IT Discovery | Low | Open | SRV-FILE-01 |