Unauthorised USB Device
Low
Open
ALR-00216 · 2026-05-26T03:17:25Z
Description
Unauthorised USB mass storage device connected to FW-EDGE-01 by user 'p.thomas'. Device blocked by Network IDS endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
03:17:25
Event ingested by SOC365 Engine
03:17:26
EmilyAI triage started — correlation enrichment
03:17:36
EmilyAI confidence: 83% — escalated to human analyst
03:17:44
Alert assigned to analyst: EmilyAI (auto)
03:19:50
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00449 | 2h ago | Unauthorised USB Device | Medium | Open | SRV-DC-01 |
| ALR-00060 | 10h ago | Unauthorised USB Device | Informational | Escalated | WS-PC-006 |
| ALR-00354 | 18h ago | Unauthorised USB Device | Medium | Escalated | WS-PC-004 |
| ALR-00239 | 1d ago | Suspicious Scheduled Task | High | Escalated | FW-EDGE-01 |
| ALR-00441 | 1d ago | Unauthorised USB Device | Medium | False Positive | WS-PC-001 |