Unauthorised USB Device
Informational
False Positive
ALR-00163 · 2026-04-11T11:17:43Z
Description
Unauthorised USB mass storage device connected to WS-LAP-011 by user 'd.walker'. Device blocked by DecoyPulse endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:17:43
Event ingested by SOC365 Engine
11:17:45
EmilyAI triage started — correlation enrichment
11:17:52
EmilyAI confidence: 79% — escalated to human analyst
11:18:10
Alert assigned to analyst: EmilyAI (auto)
11:18:47
Investigation started — querying SIEM and threat intelligence
11:26:52
Containment action taken — endpoint isolated
11:28:08
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00046 | 1h ago | Anomalous DNS Query | Medium | Investigating | WS-LAP-011 |
| ALR-00315 | 2h ago | Suspicious Scheduled Task | Low | Resolved | WS-LAP-011 |
| ALR-00243 | 6h ago | Port Scan Detected | Medium | Resolved | WS-LAP-011 |
| ALR-00493 | 10h ago | Unauthorised USB Device | Medium | Investigating | WS-PC-004 |
| ALR-00305 | 22h ago | DLP Policy Violation | Informational | False Positive | WS-LAP-011 |