Synthetic data & simulated integrations. Every incident, host, identity, indicator and detection source on this page is fabricated for portfolio demonstration. There is no live ServiceNow instance, SIEM, EDR or identity provider connected, and this project is not affiliated with or endorsed by ServiceNow.

Incident Detail · SIR-2048

Sustained request flood against customer portal edge

denial of service affecting syn-portal-web-04 (tier1, production) in business service "Customer Portal".

P3LOWrecovery

Simulated AI triage summary

Advisory only. Never used to take an action on its own.

Simulated AI assist — advisory only

Simulated triage: edge rate limiting absorbed a short traffic spike from a small address range. No origin saturation or error-rate change in synthetic telemetry.

Suggested actions (require analyst review)

  • · Confirm rate-limit rules held
  • · Close after 24h of stable traffic

No suggestion here is executed automatically. An analyst must approve each consequential action and the decision is recorded in the audit trail.

Priority scoring trace

Deterministic score 45 → P3.

Severitylow+10
Detection confidence55% aggregate across 1 signal(s)+8
Asset criticalitysyn-portal-web-04 (tier1, production)+11
Business serviceCustomer Portal (criticality 1)+12
Identity risksvc_payments_batch (service)+4
SLA age pressure260 min elapsed vs resolve budget+0

Routing decision

Assigned to SOC Tier 2 Analysis. First matching rule wins.

Elevated impact requires deeper analysis before containment.

  • no matchP1 or critical severity -> Incident Response
  • no matchCredential abuse / insider risk, or privileged identity -> Identity & Access
  • no matchCloud misconfiguration -> Cloud Security Engineering
  • no matchVulnerable asset -> Vulnerability Management
  • matchedP2, or tier0/tier1 production asset -> SOC Tier 2
  • matchedDefault -> SOC Tier 1

Detection signals

Fabricated sources, normalized at intake.

SIM-SIEM (synthetic)Request rate above edge threshold for 10 minutes55% conf.
MITRE: T1498 — Network Denial of ServiceObserved: 2026-08-14T01:13:00Zdedupe: siem:flood:as-02Normalized ✓

Automation eligibility

Simulated playbook pre-flight.

No playbook covers this incident category.

Response tasks

  • openConfirm 24h of stable edge trafficSOC Tier 1 Triagedue 10h

Evidence

Synthetic artifacts with simulated integrity digests.

No evidence recorded.

Audit trail

Append-only in the demo; in-memory only.

  1. analystValidated containmenthuman approved2026-08-14T02:00:00Z

    d.reyesEdge rate limiting confirmed effective

SLA posture

Acknowledge3h 40m left
260m / 480m budgetOn track
Contain19h 40m left
260m / 1440m budgetOn track
Resolve67h 40m left
260m / 4320m budgetOn track

Escalation

none
  • · No escalation trigger matched.

Closure control

Incident must be in "review" state, currently "recovery".

Context

Opened2026-08-14T01:15:00Z
Age4h 20m
Assetsyn-portal-web-04 (tier1)
Environmentproduction
Business serviceCustomer Portal · C1
Service ownerL. Marsh (synthetic)
Identitysvc_payments_batch
Identity riskservice
DepartmentPlatform
Aggregate confidence55%
Containment approvedYes (human)
← Back to queue