top of page

USB Access List

When this option is enabled, access to removable devices (such as USB flash drives, external disks, SD cards, and MicroSD cards) can be detected across all machines on the network.

USB.png

Activation

A dedicated guide for enabling the recording of these events is available via the [i] button.

USB2.png

To enable logging of removable storage, the following steps are required:

1. Enable the “Audit Removable Storage” option in Group Policy under Advanced Configuration > Object Access.

USB_AccessoOggetti.png

2. Modify the registry key by enabling the HotplugSecureOpen option.

USB_Registry.png

Notifications

When the notification option is enabled, a notification is sent each time a user inserts a removable device.

USB1.png

ATTENTION:

Some virtualisation platforms may present their virtual drives as removable devices. In these cases, Windows interprets them incorrectly. Contact the platform vendor to configure the drive as a File System device rather than Removable Storage.

Enabling event 6416 logging

To enable logging of this event, the following security policy must be configured::​

Local Security Policies > Advanced Audit Policy Configuration > System Audit Policies > Detailed Tracking > Audit Plug and Play Activity

​​

Set the policy to "Success and Failure".

USB_PNP.png
  • Event 6416 logging

Support for Windows event 6416 is available and allows automatic logging of external device connections through the Plug and Play mechanism.

In particular, storage-capable USB devices are tracked, including:

  • USB flash drives

  • External hard disks

  • USB smart cards

  • Other removable storage devices

The event is recorded under the WINLOG source, Plug and Play Events category, and includes the device type and hardware description.

  • Alert functionality

Event 6416 can be configured as an alert, enabling automatic notifications based on specific criteria, including:

  • Device insertion by a specific user

  • Connection on a specific machine

  • Detected device type

  • SOC module integration

The SOC module uses these events to:

  • Report the insertion of USB devices on specific PCs

  • Generate targeted notifications or alerts based on user or workstation

With the USB plugin enabled, advanced details are also available, including information about the contents of connected devices.

Spiega il log selezionato

This function uses an AI-powered semantic analysis engine to automatically interpret the content of a single Syslog event.​

The system analyzes the message and provides a detailed explanation divided into sections:

  • What happened: describes the detected event in natural language, indicating the user, device, and technical context (e.g., accesses, errors, or modifications).

  • Why it matters: explains the relevance of the event, highlighting risks, vulnerabilities, or security implications.

  • Actions: suggests recommended checks or verifications for managing the event or resolving the issue.

When specific information is not available for a given event, the Wiki tab displays the technical details of the event ID, along with possible alternative actions or suggestions for further investigation.

SpiegaLog1.png
SpiegaLog2.png

The explanation can be printed or saved using the commands available at the bottom of the window.

AI Analysis

With a dedicated licence, the [AI Analysis] button is available in the log grids. Up to 100 events can be sent to the AI engine, which analyses them to automatically highlight critical or suspicious logs and provides a contextual evaluation that is easy to read, even for non-expert users.

The purpose is to offer advanced interpretative support, improve understanding of security logs, and speed up the identification of potentially risky actions.

If more than 100 events are selected, the system reports the excess and processes only the first 100.
The generated report can be printed and exported.

Log
Archives

bottom of page