Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:25:41 UTC

Unauthorised USB Device

Informational False Positive
ALR-00163 · 2026-04-11T11:17:43Z

Description

Unauthorised USB mass storage device connected to WS-LAP-011 by user 'd.walker'. Device blocked by DecoyPulse endpoint policy.

Alert Metadata

Alert ID
ALR-00163
Timestamp
2026-04-11T11:17:43Z
Severity
Informational
Status
False Positive
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-011
User Account
d.walker
Source IP
103.46.216.178
Destination IP
10.2.184.196
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1091
Reference
attack.mitre.org/techniques/T1091

Investigation Timeline

11:17:43 Event ingested by SOC365 Engine
11:17:45 EmilyAI triage started — correlation enrichment
11:17:52 EmilyAI confidence: 79% — escalated to human analyst
11:18:10 Alert assigned to analyst: EmilyAI (auto)
11:18:47 Investigation started — querying SIEM and threat intelligence
11:26:52 Containment action taken — endpoint isolated
11:28:08 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00046 1h ago Anomalous DNS Query Medium Investigating WS-LAP-011
ALR-00315 2h ago Suspicious Scheduled Task Low Resolved WS-LAP-011
ALR-00243 6h ago Port Scan Detected Medium Resolved WS-LAP-011
ALR-00493 10h ago Unauthorised USB Device Medium Investigating WS-PC-004
ALR-00305 22h ago DLP Policy Violation Informational False Positive WS-LAP-011