ServiceNow · SIR Range

Choose an operation. Deploy it to your PDI.

Each operation is a self-contained Security Incident Response experience you can run on your own ServiceNow Personal Developer Instance. Pick one below, download its update set, import it, and point it at the hosted challenge server.

01
Import ServiceNow Range
One Import from XML on your PDI — no SDK, no CLI. Installs the whole platform, with all four operations as records.
02
Pick an operation
A competitive CTF, or a guided implementation workshop. Choose one from ServiceNow Range → Operations.
03
Run it
Fill the operation's config and click Run. Challenges live on the hosted CTFd server; the workshop's are already visible.

Select an operation

Operation Quiet Harbor
SIR Capture the Flag

A competitive, self-paced CTF. Investigate realistic SIR incidents on your PDI and capture flags across the full attack lifecycle — phishing, malware, lateral movement, exfiltration, correlation, and triage.

  • Best forHands-on analysts practising investigation under a scoreboard
  • Format50 flag challenges · one answer key per cohort
  • Scopex_snc_range · Operation Quiet Harbor
  • SetupLight — fill 2 fields on the operation record, click Run (no OAuth)
Select this operation
Operation Deep Current
SIR Capture the Flag · Real-World Threats

A competitive CTF built from real-world threats. Triage a queue of five unrelated SIR incidents — a DPRK fake IT worker, ransomware living-off-the-land, a poisoned software supply chain, AI deepfake CFO fraud, and a home-network botnet — grounded in open-source threat intelligence.

  • Best forAnalysts triaging current, real-world attack scenarios under a scoreboard
  • Format31 flag challenges · one answer key per cohort
  • Scopex_snc_range · Operation Deep Current
  • SetupLight — fill 2 fields on the operation record, click Run (no OAuth)
Select this operation
Operation Undertow
SIR Capture the Flag · Expert / Salience Inversion

The expert cut. A breach discovered mid-stream — detection fired late, nothing is pre-verdicted, the tools disagree. Every flag is a salience inversion: the answer is the option your instincts steer you away from, overturned only by a bright-line record fact.

  • Best forSeasoned analysts who want their pattern-matching tested, not just their navigation
  • Format9 flag challenges · one answer key per cohort
  • Scopex_snc_range · Operation Undertow
  • SetupLight — fill 2 fields on the operation record, click Run (no OAuth)
Select this operation
Operation Watchtower
SIR Implementation Workshop

A guided, narrative incident-response loop. Press START and a SIR incident appears — auto-enriched, with a playbook. Solve the matching challenge, resolve the incident, and the next scenario reveals itself. Five in a row.

  • Best forEnablement & demos — showing how SIR implementation works end to end
  • Format5 scenarios · easy / medium / hard
  • Scopex_snc_range · Operation Watchtower
  • SetupLight — incidents generate on-platform; CTFd just reveals challenges
Select this operation

↑ Select an operation to get its update set and deploy steps.