Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.
Incident Detail · SIR-2043
Commodity loader detected on finance workstation
malware affecting syn-wks-2291 (tier3, production) in business service "Corporate Workstations".
Simulated AI triage summary
Advisory only. Never used to take an action on its own.
Simulated triage: an office document spawned an encoded interpreter command that attempted an outbound connection. Behaviour matches a commodity loader family in the synthetic signature set.
Suggested actions (require analyst review)
- · Isolate the endpoint from the network
- · Collect process tree and persistence artifacts
- · Submit the sample hash to the simulated sandbox
No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.
Priority scoring trace
Deterministic score 60 → P3.
| Severity | high | +38 |
| Detection confidence | 92% aggregate across 1 signal(s) | +14 |
| Asset criticality | syn-wks-2291 (tier3, production) | +2 |
| Business service | Corporate Workstations (criticality 3) | +4 |
| Identity risk | p.novak (standard) | +2 |
| SLA age pressure | 40 min elapsed vs resolve budget | +0 |
Routing decision
Assigned to SOC Tier 1 Triage. First matching rule wins.
No elevated condition matched; standard triage queue applies.
- no matchP1 or critical severity -> Incident Response
- no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
- no matchCloud misconfiguration -> Cloud Security Engineering
- no matchVulnerable asset -> Vulnerability Management
- no matchP2, or tier0/tier1 production asset -> SOC Tier 2
- matchedDefault -> SOC Tier 1
Detection signals
Fabricated sources, normalized at intake.
Automation eligibility
Simulated playbook pre-flight.
- · Category, severity and confidence (92%) all satisfy playbook preconditions.
- · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.
Auto-executable (low impact, simulated)
- · Collect process tree and persistence artifacts
- · Submit sample hash to sandbox
Human approval required
- · Network-isolate the endpoint (high impact · SIM-EDR)
Response tasks
- completeCollect process tree and persistence artifactsSOC Tier 2 Analysisautomateddue 0m
- openApprove endpoint network isolationSOC Tier 2 Analysisapprovaldue 15m
Evidence
Synthetic artifacts with simulated integrity digests.
sha256:0000000000000000000000000000000000000000000000000000000000000043
automation:pb-endpoint · 2026-08-14T04:57:00Z · digest sha256:aa10…4f52 (synthetic)
Audit trail
Append-only in the demo; in-memory only.
- automationBlocked auto-isolation2026-08-14T04:55:00Z
pb-endpoint — High-impact action on high-severity incident requires human approval
SLA posture
Escalation
- · No escalation trigger matched.
Closure control
Auto-close is prohibited for high and critical severity incidents.