Unauthorised USB Device
Medium
Escalated
ALR-00399 · 2026-05-25T16:02:53Z
Description
Unauthorised USB mass storage device connected to WS-PC-006 by user 'r.davies'. Device blocked by Email Gateway endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:02:53
Event ingested by SOC365 Engine
16:02:54
EmilyAI triage started — correlation enrichment
16:03:05
EmilyAI confidence: 98% — escalated to human analyst
16:03:23
Alert assigned to analyst: Sarah Chen
16:03:48
Investigation started — querying SIEM and threat intelligence
16:06:58
Containment action taken — endpoint isolated
16:14:52
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00070 | 3h ago | Unauthorised USB Device | Informational | Escalated | WS-LAP-012 |
| ALR-00311 | 5h ago | Credential Stuffing Attempt | Low | False Positive | WS-PC-006 |
| ALR-00310 | 9h ago | Unauthorised USB Device | Medium | Investigating | SRV-DC-01 |
| ALR-00265 | 10h ago | Unauthorised USB Device | High | Escalated | FW-EDGE-01 |
| ALR-00302 | 16h ago | Lateral Movement Detected | Low | False Positive | WS-PC-006 |