Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:58:58 UTC

Unauthorised USB Device

Medium Investigating
ALR-00483 · 2026-04-06T05:12:19Z

Description

Unauthorised USB mass storage device connected to FW-EDGE-01 by user 'system'. Device blocked by DLP Module endpoint policy.

Alert Metadata

Alert ID
ALR-00483
Timestamp
2026-04-06T05:12:19Z
Severity
Medium
Status
Investigating
Detection Source
DLP Module
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
FW-EDGE-01
User Account
system
Source IP
194.207.62.5
Destination IP
10.1.79.237
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1091
Reference
attack.mitre.org/techniques/T1091

Investigation Timeline

05:12:19 Event ingested by SOC365 Engine
05:12:20 EmilyAI triage started — correlation enrichment
05:12:30 EmilyAI confidence: 88% — escalated to human analyst
05:12:56 Alert assigned to analyst: Anika Patel
05:13:26 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00420 1h ago Unauthorised USB Device Low Escalated AP-WIFI-03
ALR-00103 4h ago Suspicious Scheduled Task Low Investigating FW-EDGE-01
ALR-00059 11h ago Rogue DHCP Server High Investigating FW-EDGE-01
ALR-00030 12h ago Unusual Outbound Traffic Low Open FW-EDGE-01
ALR-00430 14h ago Unusual Outbound Traffic Medium Resolved FW-EDGE-01