Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.
Incident Detail · SIR-2047
Departing employee bulk-downloading document repository
insider risk affecting syn-hr-app-02 (tier2, production) in business service "HR Self-Service".
Simulated AI triage summary
Advisory only. Never used to take an action on its own.
Simulated triage: an account flagged in the synthetic HR offboarding feed downloaded 412 documents in one hour. Legitimate handover activity is a plausible explanation and requires manager confirmation.
Suggested actions (require analyst review)
- · Request manager confirmation of handover activity
- · Preserve the download manifest for HR review
No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.
Priority scoring trace
Deterministic score 68 → P2.
| Severity | high | +38 |
| Detection confidence | 66% aggregate across 1 signal(s) | +10 |
| Asset criticality | syn-hr-app-02 (tier2, production) | +6 |
| Business service | HR Self-Service (criticality 3) | +4 |
| Identity risk | d.reyes (standard) | +2 |
| SLA age pressure | 665 min elapsed vs resolve budget | +8 |
Routing decision
Assigned to Identity & Access Team. First matching rule wins.
Identity-centric incidents require account and entitlement review.
- no matchP1 or critical severity -> Incident Response
- matchedCredential abuse / insider risk, or privileged identity -> Identity & Access
- no matchCloud misconfiguration -> Cloud Security Engineering
- no matchVulnerable asset -> Vulnerability Management
- matchedP2, or tier0/tier1 production asset -> SOC Tier 2
- matchedDefault -> SOC Tier 1
Detection signals
Fabricated sources, normalized at intake.
Automation eligibility
Simulated playbook pre-flight.
- · Aggregate confidence 66% is below the required 70%.
Response tasks
- in progressObtain manager confirmation of handoverIdentity & Access Teamdue 4h
Evidence
Synthetic artifacts with simulated integrity digests.
412 documents, 3 repositories, all within prior access grants
analyst:d.reyes · 2026-08-13T19:40:00Z · digest sha256:b214…8e77 (synthetic)
Audit trail
Append-only in the demo; in-memory only.
- analystDeclined auto-closehuman approved2026-08-13T22:14:00Z
d.reyes — High-severity incident: closure requires human validation
SLA posture
Escalation
- · Containment SLA breached (554% consumed).
Notify (simulated)
- · SOC Shift Lead
- · Incident Commander on-call
- · Incident Response (IR)
Closure control
Auto-close is prohibited for high and critical severity incidents.