Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:50:26 UTC

Unauthorised USB Device

Low Open
ALR-00268 · 2026-04-09T17:25:57Z

Description

Unauthorised USB mass storage device connected to WS-PC-002 by user 'k.brown'. Device blocked by Email Gateway endpoint policy.

Alert Metadata

Alert ID
ALR-00268
Timestamp
2026-04-09T17:25:57Z
Severity
Low
Status
Open
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
k.brown
Source IP
91.102.195.98
Destination IP
10.0.71.92
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1091
Reference
attack.mitre.org/techniques/T1091

Investigation Timeline

17:25:57 Event ingested by SOC365 Engine
17:25:58 EmilyAI triage started — correlation enrichment
17:26:06 EmilyAI confidence: 85% — escalated to human analyst
17:26:27 Alert assigned to analyst: EmilyAI (auto)
17:27:15 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00463 2h ago Phishing Email Blocked High Open WS-PC-002
ALR-00441 4h ago Unauthorised USB Device Informational False Positive SRV-MAIL-01
ALR-00464 6h ago Unauthorised USB Device Informational Escalated WS-PC-002
ALR-00021 6h ago Suspicious Scheduled Task Low Resolved WS-PC-002
ALR-00186 8h ago Unauthorised USB Device Medium Investigating WS-PC-004