Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2042

Credential-harvesting phishing wave targeting support staff

phishing affecting syn-wks-1043 (tier3, production) in business service "Corporate Workstations".

P3HIGHanalysis

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: nine near-identical messages from a lookalike sender domain reached support mailboxes; two recipients opened the link. No credential submission observed in synthetic telemetry.

Suggested actions (require analyst review)

  • · Quarantine matching messages across mailboxes
  • · Block the sender domain at the gateway
  • · Force password reset for the two click-through users

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 59 → P3.

Severityhigh+38
Detection confidence86% aggregate across 2 signal(s)+13
Asset criticalitysyn-wks-1043 (tier3, production)+2
Business serviceCorporate Workstations (criticality 3)+4
Identity riskd.reyes (standard)+2
SLA age pressure115 min elapsed vs resolve budget+0

Routing decision

Assigned to SOC Tier 1 Triage. First matching rule wins.

No elevated condition matched; standard triage queue applies.

  • no matchP1 or critical severity -> Incident Response
  • no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
  • no matchCloud misconfiguration -> Cloud Security Engineering
  • no matchVulnerable asset -> Vulnerability Management
  • no matchP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-MailGateway (synthetic)Lookalike domain with credential form81% conf.
MITRE: T1566.002 — Spearphishing LinkObserved: 2026-08-14T03:38:00Zdedupe: mail:lookalike:corpNormalized ✓
SIM-UserReport (synthetic)Employee-reported suspicious message60% conf.
MITRE: T1566 — PhishingObserved: 2026-08-14T03:52:00Zdedupe: report:corp:1043Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

Phishing Containmentrequires approval
  • · Category, severity and confidence (86%) all satisfy playbook preconditions.
  • · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.

Auto-executable (low impact, simulated)

  • · Search mailboxes for matching messages

Human approval required

  • · Quarantine matched messages (medium impact · SIM-MailGateway)
  • · Block sender domain at gateway (medium impact · SIM-MailGateway)
  • · Force password reset for click-through users (high impact · SIM-IdentityProvider)

Response tasks

  • completeQuarantine matched phishing messagesSOC Tier 2 Analysisautomateddue 0m
  • openForce password reset for click-through usersIdentity & Access Teamautomatedapprovaldue 45m

Evidence

Synthetic artifacts with simulated integrity digests.

analyst noteClick-through scope

2 of 9 recipients opened the link; no credential POST observed

analyst:d.reyes · 2026-08-14T04:05:00Z · digest sha256:0c73…be19 (synthetic)

Audit trail

Append-only in the demo; in-memory only.

  1. automationRouted to SOC Tier 2 Analysis2026-08-14T03:41:00Z

    routing-engineRule: P2, or tier0/tier1 production asset -> SOC Tier 2

  2. automationQuarantined messages2026-08-14T03:58:00Z

    pb-phish9 messages matched dedupe key mail:lookalike:corp

SLA posture

Acknowledge1h 25m over
115m / 30m budgetBreached
Contain5m left
115m / 120m budgetAt risk
Resolve6h 5m left
115m / 480m budgetOn track

Escalation

tier2
  • · Containment SLA at risk (96% consumed).

Notify (simulated)

  • · SOC Tier 2 Analysis
  • · SOC Shift Lead

Closure control

Auto-close is prohibited for high and critical severity incidents.

Context

Opened2026-08-14T03:40:00Z
Age1h 55m
Assetsyn-wks-1043 (tier3)
Environmentproduction
Business serviceCorporate Workstations · C3
Service ownerJ. Byrne (synthetic)
Identityd.reyes
Identity riskstandard
DepartmentSupport
Aggregate confidence86%
Containment approvedNo
← Back to queue