I created a policy for Endpoint Server with a keyword match of "encrypt" on all areas (envelope, subject etc) and the Protocol is Removable Storage. The response rule of the policy Endpoint FlexResponse (EERPlugin_flexresponse).
I am triggering the policy by creating a text file with the word "encrypt" in it and moving the said file to a USB connected to the machine.
I am primarily looking at Endpoint Reports but at the same time, I took a look at other reports (Network/Discover) and do not find the incident there.