Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2046

Internet-facing staging host missing critical patch

vulnerable asset affecting syn-portal-web-09 (tier1, staging) in business service "Customer Portal".

P3MEDIUMnew

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: a staging portal host is two patch cycles behind and exposes a service associated with a synthetic remote-code-execution advisory. No exploitation attempts observed.

Suggested actions (require analyst review)

  • · Open a remediation task with the platform owner
  • · Confirm the host is not reachable from the public internet

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 60 → P3.

Severitymedium+22
Detection confidence70% aggregate across 1 signal(s)+11
Asset criticalitysyn-portal-web-09 (tier1, staging)+11
Business serviceCustomer Portal (criticality 1)+12
Identity risksvc_ci_deploy (service)+4
SLA age pressure315 min elapsed vs resolve budget+0

Routing decision

Assigned to Vulnerability Management. First matching rule wins.

Exposure findings are tracked through the vulnerability program.

  • no matchP1 or critical severity -> Incident Response
  • no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
  • no matchCloud misconfiguration -> Cloud Security Engineering
  • matchedVulnerable asset -> Vulnerability Management
  • no matchP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-VulnScanner (synthetic)Unpatched remote-code-execution advisory (synthetic CVE-0000-0001)70% conf.
MITRE: T1190 — Exploit Public-Facing ApplicationObserved: 2026-08-14T00:18:00Zdedupe: vuln:rce:as-07Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

No playbook covers this incident category.

Response tasks

  • openSchedule patch window with platform ownerVulnerability Managementdue 24h

Evidence

Synthetic artifacts with simulated integrity digests.

No evidence recorded.

Audit trail

Append-only in the demo; in-memory only.

    SLA posture

    Acknowledge3h 15m over
    315m / 120m budgetBreached
    Contain2h 45m left
    315m / 480m budgetOn track
    Resolve18h 45m left
    315m / 1440m budgetOn track

    Escalation

    none
    • · No escalation trigger matched.

    Closure control

    Containment has not been validated by a human analyst.

    Context

    Opened2026-08-14T00:20:00Z
    Age5h 15m
    Assetsyn-portal-web-09 (tier1)
    Environmentstaging
    Business serviceCustomer Portal · C1
    Service ownerL. Marsh (synthetic)
    Identitysvc_ci_deploy
    Identity riskservice
    DepartmentPlatform
    Aggregate confidence70%
    Containment approvedNo
    ← Back to queue