Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2047

Departing employee bulk-downloading document repository

insider risk affecting syn-hr-app-02 (tier2, production) in business service "HR Self-Service".

P2HIGHreview

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: an account flagged in the synthetic HR offboarding feed downloaded 412 documents in one hour. Legitimate handover activity is a plausible explanation and requires manager confirmation.

Suggested actions (require analyst review)

  • · Request manager confirmation of handover activity
  • · Preserve the download manifest for HR review

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 68 → P2.

Severityhigh+38
Detection confidence66% aggregate across 1 signal(s)+10
Asset criticalitysyn-hr-app-02 (tier2, production)+6
Business serviceHR Self-Service (criticality 3)+4
Identity riskd.reyes (standard)+2
SLA age pressure665 min elapsed vs resolve budget+8

Routing decision

Assigned to Identity & Access Team. First matching rule wins.

Identity-centric incidents require account and entitlement review.

  • no matchP1 or critical severity -> Incident Response
  • matchedCredential abuse / insider risk, or privileged identity -> Identity & Access
  • no matchCloud misconfiguration -> Cloud Security Engineering
  • no matchVulnerable asset -> Vulnerability Management
  • matchedP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-SIEM (synthetic)Bulk document download outside working pattern66% conf.
MITRE: T1213 — Data from Information RepositoriesObserved: 2026-08-13T18:25:00Zdedupe: siem:bulkdl:id-03Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

Identity Compromise Responseblocked
  • · Aggregate confidence 66% is below the required 70%.

Response tasks

  • in progressObtain manager confirmation of handoverIdentity & Access Teamdue 4h

Evidence

Synthetic artifacts with simulated integrity digests.

analyst noteDownload manifest summary

412 documents, 3 repositories, all within prior access grants

analyst:d.reyes · 2026-08-13T19:40:00Z · digest sha256:b214…8e77 (synthetic)

Audit trail

Append-only in the demo; in-memory only.

  1. analystDeclined auto-closehuman approved2026-08-13T22:14:00Z

    d.reyesHigh-severity incident: closure requires human validation

SLA posture

Acknowledge10h 35m over
665m / 30m budgetBreached
Contain9h 5m over
665m / 120m budgetBreached
Resolve3h 5m over
665m / 480m budgetBreached

Escalation

incident commander
  • · Containment SLA breached (554% consumed).

Notify (simulated)

  • · SOC Shift Lead
  • · Incident Commander on-call
  • · Incident Response (IR)

Closure control

Auto-close is prohibited for high and critical severity incidents.

Context

Opened2026-08-13T18:30:00Z
Age11h 5m
Assetsyn-hr-app-02 (tier2)
Environmentproduction
Business serviceHR Self-Service · C3
Service ownerR. Delgado (synthetic)
Identityd.reyes
Identity riskstandard
DepartmentSupport
Aggregate confidence66%
Containment approvedYes (human)
← Back to queue