Unauthorised USB Device
Medium
Investigating
ALR-00218 · 2026-05-21T22:53:22Z
Description
Unauthorised USB mass storage device connected to WS-LAP-012 by user 'j.smith'. Device blocked by SOC365 Engine endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:53:22
Event ingested by SOC365 Engine
22:53:27
EmilyAI triage started — correlation enrichment
22:53:30
EmilyAI confidence: 80% — escalated to human analyst
22:54:00
Alert assigned to analyst: Anika Patel
22:55:20
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00287 | 2h ago | Anomalous DNS Query | Medium | Investigating | WS-LAP-012 |
| ALR-00224 | 4h ago | Failed MFA Challenge | Low | Investigating | WS-LAP-012 |
| ALR-00273 | 9h ago | Unauthorised USB Device | Medium | False Positive | SRV-FILE-01 |
| ALR-00244 | 9h ago | Anomalous DNS Query | Low | False Positive | WS-LAP-012 |
| ALR-00187 | 19h ago | Certificate Anomaly | Low | Open | WS-LAP-012 |