Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Detection & Intake

Simulated detection pipeline

Signals arrive from fabricated sources, are normalized into a common shape, deduplicated by key, and aggregated into a single incident confidence used by priority and automation logic.

Signals ingested

11

Distinct sources

7

Normalized

11/11

Dedupe keys

11

Fabricated sources

None of these connect to a real product.

SIM-IdentityProvider (synthetic)SIM-SIEM (synthetic)SIM-EDR (synthetic)SIM-CloudTrail (synthetic)SIM-VulnScanner (synthetic)SIM-MailGateway (synthetic)SIM-UserReport (synthetic)

Intake stream

Aggregate confidence per incident is derived from its signals, never entered by hand.

SourceRuleMITREConf.Dedupe keyNorm.Incident
SIM-IdentityProvider (synthetic)Impossible travel for privileged sessionT1078.004 — Valid Accounts: Cloud Accounts88%idp:priv-token:as-01yesSIR-2041agg 93%
SIM-SIEM (synthetic)Burst of 4xx then 200 on admin endpointT1110.003 — Password Spraying74%siem:admin-burst:as-01yesSIR-2041agg 93%
SIM-SIEM (synthetic)Outbound volume 40x baseline to unrecognised ASNT1048 — Exfiltration Over Alternative Protocol79%siem:egress:as-04yesSIR-2045agg 84%
SIM-EDR (synthetic)Archive utility invoked against export directoryT1560.001 — Archive via Utility68%edr:archive:as-04yesSIR-2045agg 84%
SIM-SIEM (synthetic)Bulk document download outside working patternT1213 — Data from Information Repositories66%siem:bulkdl:id-03yesSIR-2047agg 66%
SIM-CloudTrail (synthetic)Bucket ACL changed to public-readT1580 — Cloud Infrastructure Discovery95%cloud:acl:as-04yesSIR-2044agg 95%
SIM-EDR (synthetic)Script interpreter spawning encoded child processT1059.001 — PowerShell92%edr:loader:as-05yesSIR-2043agg 92%
SIM-VulnScanner (synthetic)Unpatched remote-code-execution advisory (synthetic CVE-0000-0001)T1190 — Exploit Public-Facing Application70%vuln:rce:as-07yesSIR-2046agg 70%
SIM-MailGateway (synthetic)Lookalike domain with credential formT1566.002 — Spearphishing Link81%mail:lookalike:corpyesSIR-2042agg 86%
SIM-UserReport (synthetic)Employee-reported suspicious messageT1566 — Phishing60%report:corp:1043yesSIR-2042agg 86%
SIM-SIEM (synthetic)Request rate above edge threshold for 10 minutesT1498 — Network Denial of Service55%siem:flood:as-02yesSIR-2048agg 55%