Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:55:02 UTC

Unauthorised USB Device

Informational False Positive
ALR-00078 · 2026-05-25T13:09:33Z

Description

Unauthorised USB mass storage device connected to WS-PC-002 by user 'system'. Device blocked by Email Gateway endpoint policy.

Alert Metadata

Alert ID
ALR-00078
Timestamp
2026-05-25T13:09:33Z
Severity
Informational
Status
False Positive
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
system
Source IP
185.213.220.12
Destination IP
10.1.66.237
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1091
Reference
attack.mitre.org/techniques/T1091

Investigation Timeline

13:09:33 Event ingested by SOC365 Engine
13:09:35 EmilyAI triage started — correlation enrichment
13:09:41 EmilyAI confidence: 86% — escalated to human analyst
13:09:58 Alert assigned to analyst: EmilyAI (auto)
13:11:43 Investigation started — querying SIEM and threat intelligence
13:15:09 Containment action taken — endpoint isolated
13:28:26 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00210 3h ago Suspicious PowerShell Execution Medium False Positive WS-PC-002
ALR-00197 6h ago Unauthorised USB Device Medium Resolved AP-WIFI-03
ALR-00143 7h ago Tor Exit Node Connection Informational Investigating WS-PC-002
ALR-00492 8h ago Phishing Email Blocked Low Escalated WS-PC-002
ALR-00337 9h ago Pass-the-Hash Detected Medium Escalated WS-PC-002