Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2045

Large outbound transfer from analytics warehouse node

data exfiltration affecting syn-dw-node-11 (tier1, production) in business service "Analytics Warehouse".

P1CRITICALtriage

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: bulk archive creation immediately preceded a sustained outbound transfer well above baseline. Cannot distinguish a scheduled export from exfiltration without analyst review of the change calendar.

Suggested actions (require analyst review)

  • · Throttle egress from the affected node
  • · Correlate against the scheduled export calendar
  • · Preserve netflow and archive metadata

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 88 → P1.

Severitycritical+50
Detection confidence84% aggregate across 2 signal(s)+13
Asset criticalitysyn-dw-node-11 (tier1, production)+11
Business serviceAnalytics Warehouse (criticality 2)+8
Identity riskk.ansari (elevated)+6
SLA age pressure30 min elapsed vs resolve budget+0

Routing decision

Assigned to Incident Response (IR). First matching rule wins.

Highest-priority incidents go directly to the IR team.

  • matchedP1 or critical severity -> Incident Response
  • no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
  • no matchCloud misconfiguration -> Cloud Security Engineering
  • no matchVulnerable asset -> Vulnerability Management
  • matchedP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-SIEM (synthetic)Outbound volume 40x baseline to unrecognised ASN79% conf.
MITRE: T1048 — Exfiltration Over Alternative ProtocolObserved: 2026-08-14T05:03:00Zdedupe: siem:egress:as-04Normalized ✓
SIM-EDR (synthetic)Archive utility invoked against export directory68% conf.
MITRE: T1560.001 — Archive via UtilityObserved: 2026-08-14T05:04:00Zdedupe: edr:archive:as-04Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

Exfiltration Throttle & Preserverequires approval
  • · Category, severity and confidence (84%) all satisfy playbook preconditions.
  • · High-severity incident or tier0/tier1 production asset: all non-trivial actions require documented human approval.

Auto-executable (low impact, simulated)

  • · Preserve netflow and archive metadata
  • · Correlate against scheduled export calendar

Human approval required

  • · Throttle egress from affected node (high impact · SIM-NetworkControl)

Response tasks

  • completePreserve netflow and archive metadataIncident Response (IR)automateddue 0m
  • openApprove egress throttle on warehouse nodeIncident Response (IR)approvaldue 25m

Evidence

Synthetic artifacts with simulated integrity digests.

log excerptEgress volume baseline delta

05:03Z 1.9 GB in 4 min vs 48 MB/hr trailing baseline

automation:pb-exfil · 2026-08-14T05:07:00Z · digest sha256:7e46…c9d1 (synthetic)

Audit trail

Append-only in the demo; in-memory only.

  1. automationPreserved evidence2026-08-14T05:06:00Z

    pb-exfilNetflow and archive metadata captured before any containment

SLA posture

Acknowledge15m over
30m / 15m budgetBreached
Contain30m left
30m / 60m budgetOn track
Resolve3h 30m left
30m / 240m budgetOn track

Escalation

incident commander
  • · P1 priority requires an incident commander.

Notify (simulated)

  • · SOC Shift Lead
  • · Incident Commander on-call
  • · Incident Response (IR)

Closure control

Auto-close is prohibited for high and critical severity incidents.

Context

Opened2026-08-14T05:05:00Z
Age30m
Assetsyn-dw-node-11 (tier1)
Environmentproduction
Business serviceAnalytics Warehouse · C2
Service ownerT. Nakamura (synthetic)
Identityk.ansari
Identity riskelevated
DepartmentData Engineering
Aggregate confidence84%
Containment approvedNo
← Back to queue