Unauthorised USB Device
Low
Investigating
ALR-00127 · 2026-05-22T04:42:46Z
Description
Unauthorised USB mass storage device connected to SRV-SQL-01 by user 'r.davies'. Device blocked by Endpoint Agent endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:42:46
Event ingested by SOC365 Engine
04:42:47
EmilyAI triage started — correlation enrichment
04:42:54
EmilyAI confidence: 84% — escalated to human analyst
04:43:06
Alert assigned to analyst: EmilyAI (auto)
04:44:24
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00394 | 6h ago | Brute Force SSH | High | Investigating | SRV-SQL-01 |
| ALR-00401 | 6h ago | Rogue DHCP Server | Low | False Positive | SRV-SQL-01 |
| ALR-00198 | 7h ago | Unauthorised USB Device | Low | Open | WS-MAC-005 |
| ALR-00114 | 20h ago | Unauthorised USB Device | Low | Open | SRV-APP-01 |
| ALR-00267 | 1d ago | C2 Beacon Activity | Medium | Investigating | SRV-SQL-01 |