Unauthorised USB Device
Low
False Positive
ALR-00437 · 2026-05-23T04:41:06Z
Description
Unauthorised USB mass storage device connected to SRV-SQL-01 by user 'a.wilson'. Device blocked by Firewall endpoint policy.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:41:06
Event ingested by SOC365 Engine
04:41:11
EmilyAI triage started — correlation enrichment
04:41:16
EmilyAI confidence: 88% — escalated to human analyst
04:41:36
Alert assigned to analyst: EmilyAI (auto)
04:42:07
Investigation started — querying SIEM and threat intelligence
04:47:06
Containment action taken — endpoint isolated
04:52:27
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00293 | 2h ago | Unauthorised USB Device | Informational | Escalated | FW-EDGE-01 |
| ALR-00321 | 3h ago | Unauthorised USB Device | Low | Open | WS-PC-004 |
| ALR-00105 | 14h ago | Failed MFA Challenge | Informational | False Positive | SRV-SQL-01 |
| ALR-00438 | 18h ago | Data Exfiltration Attempt | Medium | Resolved | SRV-SQL-01 |
| ALR-00313 | 1d ago | Phishing Email Blocked | Low | False Positive | SRV-SQL-01 |