Unauthorised USB Device
Low
Open
ALR-00241 · 2026-04-06T22:32:13Z
Description
Unauthorised USB mass storage device connected to SRV-FILE-01 by user 's.jones'. Device blocked by Email Gateway endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:32:13
Event ingested by SOC365 Engine
22:32:14
EmilyAI triage started — correlation enrichment
22:32:27
EmilyAI confidence: 89% — escalated to human analyst
22:32:42
Alert assigned to analyst: EmilyAI (auto)
22:33:03
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00493 | 10h ago | Unauthorised USB Device | Medium | Investigating | WS-PC-004 |
| ALR-00102 | 13h ago | Tor Exit Node Connection | Low | Open | SRV-FILE-01 |
| ALR-00457 | 1d ago | Unauthorised USB Device | Low | False Positive | AP-WIFI-03 |
| ALR-00202 | 1d ago | Unauthorised USB Device | High | Escalated | SRV-FILE-01 |
| ALR-00163 | 1d ago | Unauthorised USB Device | Informational | False Positive | WS-LAP-011 |