Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.
Incident Detail · SIR-2042
Credential-harvesting phishing wave targeting support staff
phishing affecting syn-wks-1043 (tier3, production) in business service "Corporate Workstations".
Simulated AI triage summary
Advisory only. Never used to take an action on its own.
Simulated triage: nine near-identical messages from a lookalike sender domain reached support mailboxes; two recipients opened the link. No credential submission observed in synthetic telemetry.
Suggested actions (require analyst review)
- · Quarantine matching messages across mailboxes
- · Block the sender domain at the gateway
- · Force password reset for the two click-through users
No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.
Priority scoring trace
Deterministic score 59 → P3.
| Severity | high | +38 |
| Detection confidence | 86% aggregate across 2 signal(s) | +13 |
| Asset criticality | syn-wks-1043 (tier3, production) | +2 |
| Business service | Corporate Workstations (criticality 3) | +4 |
| Identity risk | d.reyes (standard) | +2 |
| SLA age pressure | 115 min elapsed vs resolve budget | +0 |
Routing decision
Assigned to SOC Tier 1 Triage. First matching rule wins.
No elevated condition matched; standard triage queue applies.
- no matchP1 or critical severity -> Incident Response
- no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
- no matchCloud misconfiguration -> Cloud Security Engineering
- no matchVulnerable asset -> Vulnerability Management
- no matchP2, or tier0/tier1 production asset -> SOC Tier 2
- matchedDefault -> SOC Tier 1
Detection signals
Fabricated sources, normalized at intake.
Automation eligibility
Simulated playbook pre-flight.
- · Category, severity and confidence (86%) all satisfy playbook preconditions.
- · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.
Auto-executable (low impact, simulated)
- · Search mailboxes for matching messages
Human approval required
- · Quarantine matched messages (medium impact · SIM-MailGateway)
- · Block sender domain at gateway (medium impact · SIM-MailGateway)
- · Force password reset for click-through users (high impact · SIM-IdentityProvider)
Response tasks
- completeQuarantine matched phishing messagesSOC Tier 2 Analysisautomateddue 0m
- openForce password reset for click-through usersIdentity & Access Teamautomatedapprovaldue 45m
Evidence
Synthetic artifacts with simulated integrity digests.
2 of 9 recipients opened the link; no credential POST observed
analyst:d.reyes · 2026-08-14T04:05:00Z · digest sha256:0c73…be19 (synthetic)
Audit trail
Append-only in the demo; in-memory only.
- automationRouted to SOC Tier 2 Analysis2026-08-14T03:41:00Z
routing-engine — Rule: P2, or tier0/tier1 production asset -> SOC Tier 2
- automationQuarantined messages2026-08-14T03:58:00Z
pb-phish — 9 messages matched dedupe key mail:lookalike:corp
SLA posture
Escalation
- · Containment SLA at risk (96% consumed).
Notify (simulated)
- · SOC Tier 2 Analysis
- · SOC Shift Lead
Closure control
Auto-close is prohibited for high and critical severity incidents.