Unauthorised USB Device
Informational
Open
ALR-00255 · 2026-05-25T07:51:00Z
Description
Unauthorised USB mass storage device connected to WS-PC-006 by user 'j.smith'. Device blocked by Email Gateway endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:51:00
Event ingested by SOC365 Engine
07:51:02
EmilyAI triage started — correlation enrichment
07:51:13
EmilyAI confidence: 93% — escalated to human analyst
07:51:45
Alert assigned to analyst: EmilyAI (auto)
07:52:40
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00153 | 34m ago | Unauthorised USB Device | Informational | Investigating | WS-PC-003 |
| ALR-00413 | 1h ago | Unauthorised USB Device | Medium | Resolved | WS-PC-001 |
| ALR-00191 | 1h ago | Anomalous DNS Query | Low | Investigating | WS-PC-006 |
| ALR-00474 | 3h ago | Unauthorised USB Device | Informational | Escalated | SRV-DC-01 |
| ALR-00240 | 3h ago | DecoyPulse Honeypot Triggered | Low | Open | WS-PC-006 |