Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.
Incident Detail · SIR-2045
Large outbound transfer from analytics warehouse node
data exfiltration affecting syn-dw-node-11 (tier1, production) in business service "Analytics Warehouse".
Simulated AI triage summary
Advisory only. Never used to take an action on its own.
Simulated triage: bulk archive creation immediately preceded a sustained outbound transfer well above baseline. Cannot distinguish a scheduled export from exfiltration without analyst review of the change calendar.
Suggested actions (require analyst review)
- · Throttle egress from the affected node
- · Correlate against the scheduled export calendar
- · Preserve netflow and archive metadata
No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.
Priority scoring trace
Deterministic score 88 → P1.
| Severity | critical | +50 |
| Detection confidence | 84% aggregate across 2 signal(s) | +13 |
| Asset criticality | syn-dw-node-11 (tier1, production) | +11 |
| Business service | Analytics Warehouse (criticality 2) | +8 |
| Identity risk | k.ansari (elevated) | +6 |
| SLA age pressure | 30 min elapsed vs resolve budget | +0 |
Routing decision
Assigned to Incident Response (IR). First matching rule wins.
Highest-priority incidents go directly to the IR team.
- matchedP1 or critical severity -> Incident Response
- no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
- no matchCloud misconfiguration -> Cloud Security Engineering
- no matchVulnerable asset -> Vulnerability Management
- matchedP2, or tier0/tier1 production asset -> SOC Tier 2
- matchedDefault -> SOC Tier 1
Detection signals
Fabricated sources, normalized at intake.
Automation eligibility
Simulated playbook pre-flight.
- · Category, severity and confidence (84%) all satisfy playbook preconditions.
- · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.
Auto-executable (low impact, simulated)
- · Preserve netflow and archive metadata
- · Correlate against scheduled export calendar
Human approval required
- · Throttle egress from affected node (high impact · SIM-NetworkControl)
Response tasks
- completePreserve netflow and archive metadataIncident Response (IR)automateddue 0m
- openApprove egress throttle on warehouse nodeIncident Response (IR)approvaldue 25m
Evidence
Synthetic artifacts with simulated integrity digests.
05:03Z 1.9 GB in 4 min vs 48 MB/hr trailing baseline
automation:pb-exfil · 2026-08-14T05:07:00Z · digest sha256:7e46…c9d1 (synthetic)
Audit trail
Append-only in the demo; in-memory only.
- automationPreserved evidence2026-08-14T05:06:00Z
pb-exfil — Netflow and archive metadata captured before any containment
SLA posture
Escalation
- · P1 priority requires an incident commander.
Notify (simulated)
- · SOC Shift Lead
- · Incident Commander on-call
- · Incident Response (IR)
Closure control
Auto-close is prohibited for high and critical severity incidents.