TICKET: SOC-IR-0047 | Host: HR-WORKSTATION-04 | Priority: HIGH
The DLP system triggered an alert when a USB mass storage device was inserted into HR-WORKSTATION-04, a restricted endpoint in the HR department. USB storage is prohibited on HR workstations per policy. Your job is to examine Windows Event Viewer and the file access log to determine what — if anything — was copied to the device.
Windows Event ID 2003 — logged when a removable storage device connects. Contains device name, serial number, and the user account active at insertion.
Data Loss Prevention (DLP) — security controls that detect and prevent unauthorised data transfer. USB DLP policies restrict which devices can connect to which endpoints.
Insider threat indicators — large file copies to external storage, especially from HR or finance systems, are a key data exfiltration indicator regardless of whether the employee is malicious or negligent.
| Item | Detail |
|---|---|
| Hostname | HR-WORKSTATION-04 |
| User | m.chen (Margaret Chen, HR Coordinator) |
| OS | Windows 11 Pro |
| Classification | Restricted — HR data |
| USB policy | Prohibited — all removable storage |