Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.
Detection & Intake
Simulated detection pipeline
Signals arrive from fabricated sources, are normalized into a common shape, deduplicated by key, and aggregated into a single incident confidence used by priority and automation logic.
Signals ingested
11
Distinct sources
7
Normalized
11/11
Dedupe keys
11
Fabricated sources
None of these connect to a real product.
SIM-IdentityProvider (synthetic)SIM-SIEM (synthetic)SIM-EDR (synthetic)SIM-CloudTrail (synthetic)SIM-VulnScanner (synthetic)SIM-MailGateway (synthetic)SIM-UserReport (synthetic)
Intake stream
Aggregate confidence per incident is derived from its signals, never entered by hand.
| Source | Rule | MITRE | Conf. | Dedupe key | Norm. | Incident |
|---|---|---|---|---|---|---|
| SIM-IdentityProvider (synthetic) | Impossible travel for privileged session | T1078.004 — Valid Accounts: Cloud Accounts | 88% | idp:priv-token:as-01 | yes | SIR-2041agg 93% |
| SIM-SIEM (synthetic) | Burst of 4xx then 200 on admin endpoint | T1110.003 — Password Spraying | 74% | siem:admin-burst:as-01 | yes | SIR-2041agg 93% |
| SIM-SIEM (synthetic) | Outbound volume 40x baseline to unrecognised ASN | T1048 — Exfiltration Over Alternative Protocol | 79% | siem:egress:as-04 | yes | SIR-2045agg 84% |
| SIM-EDR (synthetic) | Archive utility invoked against export directory | T1560.001 — Archive via Utility | 68% | edr:archive:as-04 | yes | SIR-2045agg 84% |
| SIM-SIEM (synthetic) | Bulk document download outside working pattern | T1213 — Data from Information Repositories | 66% | siem:bulkdl:id-03 | yes | SIR-2047agg 66% |
| SIM-CloudTrail (synthetic) | Bucket ACL changed to public-read | T1580 — Cloud Infrastructure Discovery | 95% | cloud:acl:as-04 | yes | SIR-2044agg 95% |
| SIM-EDR (synthetic) | Script interpreter spawning encoded child process | T1059.001 — PowerShell | 92% | edr:loader:as-05 | yes | SIR-2043agg 92% |
| SIM-VulnScanner (synthetic) | Unpatched remote-code-execution advisory (synthetic CVE-0000-0001) | T1190 — Exploit Public-Facing Application | 70% | vuln:rce:as-07 | yes | SIR-2046agg 70% |
| SIM-MailGateway (synthetic) | Lookalike domain with credential form | T1566.002 — Spearphishing Link | 81% | mail:lookalike:corp | yes | SIR-2042agg 86% |
| SIM-UserReport (synthetic) | Employee-reported suspicious message | T1566 — Phishing | 60% | report:corp:1043 | yes | SIR-2042agg 86% |
| SIM-SIEM (synthetic) | Request rate above edge threshold for 10 minutes | T1498 — Network Denial of Service | 55% | siem:flood:as-02 | yes | SIR-2048agg 55% |