Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2044

Public object storage bucket exposing analytics extracts

cloud misconfiguration affecting syn-dw-node-11 (tier1, production) in business service "Analytics Warehouse".

P3MEDIUManalysis

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: a storage bucket holding synthetic analytics extracts was made publicly readable by an automation change. No external read requests appear in the synthetic access log.

Suggested actions (require analyst review)

  • · Revert the bucket ACL to private
  • · Review the change ticket that introduced the ACL update

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 61 → P3.

Severitymedium+22
Detection confidence95% aggregate across 1 signal(s)+14
Asset criticalitysyn-dw-node-11 (tier1, production)+11
Business serviceAnalytics Warehouse (criticality 2)+8
Identity riskk.ansari (elevated)+6
SLA age pressure527 min elapsed vs resolve budget+0

Routing decision

Assigned to Cloud Security Engineering. First matching rule wins.

Cloud control-plane findings are remediated by the cloud team.

  • no matchP1 or critical severity -> Incident Response
  • no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
  • matchedCloud misconfiguration -> Cloud Security Engineering
  • no matchVulnerable asset -> Vulnerability Management
  • matchedP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-CloudTrail (synthetic)Bucket ACL changed to public-read95% conf.
MITRE: T1580 — Cloud Infrastructure DiscoveryObserved: 2026-08-13T20:58:00Zdedupe: cloud:acl:as-04Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

Cloud Exposure Remediationrequires approval
  • · Category, severity and confidence (95%) all satisfy playbook preconditions.
  • · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.

Auto-executable (low impact, simulated)

  • · Snapshot current resource policy
  • · Query external access log

Human approval required

  • · Revert resource policy to private (high impact · SIM-CloudControlPlane)

Response tasks

  • in progressRevert bucket ACL to privateCloud Security Engineeringapprovaldue 2h

Evidence

Synthetic artifacts with simulated integrity digests.

screenshot referenceBucket policy before revert

artifact://synthetic/bucket-policy-2044.png

automation:pb-cloud · 2026-08-13T21:06:00Z · digest sha256:5d81…0b3a (synthetic)

Audit trail

Append-only in the demo; in-memory only.

  1. automationSnapshotted resource policy2026-08-13T21:06:00Z

    pb-cloudPre-mutation snapshot stored as EV-4005

SLA posture

Acknowledge6h 47m over
527m / 120m budgetBreached
Contain47m over
527m / 480m budgetBreached
Resolve15h 13m left
527m / 1440m budgetOn track

Escalation

incident commander
  • · Containment SLA breached (110% consumed).

Notify (simulated)

  • · SOC Shift Lead
  • · Incident Commander on-call
  • · Incident Response (IR)

Closure control

Incident must be in "review" state, currently "analysis".

Context

Opened2026-08-13T21:00:00Z
Age8h 47m
Assetsyn-dw-node-11 (tier1)
Environmentproduction
Business serviceAnalytics Warehouse · C2
Service ownerT. Nakamura (synthetic)
Identityk.ansari
Identity riskelevated
DepartmentData Engineering
Aggregate confidence95%
Containment approvedYes (human)
← Back to queue