Unauthorised USB Device
Informational
Resolved
ALR-00344 · 2026-04-06T04:55:33Z
Description
Unauthorised USB mass storage device connected to WS-LAP-012 by user 'a.wilson'. Device blocked by Firewall endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:55:33
Event ingested by SOC365 Engine
04:55:37
EmilyAI triage started — correlation enrichment
04:55:38
EmilyAI confidence: 87% — escalated to human analyst
04:56:14
Alert assigned to analyst: EmilyAI (auto)
04:57:12
Investigation started — querying SIEM and threat intelligence
05:03:51
Containment action taken — endpoint isolated
05:09:33
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00243 | 38m ago | Unauthorised USB Device | Medium | Resolved | SRV-WEB-01 |
| ALR-00141 | 3h ago | Pass-the-Hash Detected | Low | False Positive | WS-LAP-012 |
| ALR-00184 | 9h ago | Rogue DHCP Server | Low | Escalated | WS-LAP-012 |
| ALR-00387 | 16h ago | Ransomware Behaviour Detected | High | Escalated | WS-LAP-012 |
| ALR-00223 | 22h ago | DecoyPulse Honeypot Triggered | Informational | Resolved | WS-LAP-012 |