ServiceNow← Back to start

SIR Field Guide — new to ServiceNow Security Incident Response?

This guide gets a brand-new analyst oriented in the Security Incident Response (SIR) Workspace so you can work any of the range's operations the way a real IR team does. It applies to all three CTF operations (Quiet Harbor, Deep Current, Undertow); where a mechanic is specific to one operation, it says so. Veterans can skip to Where the evidence lives.

The incident, top to bottom

Open a Security Incident from the queue. The header shows Number, Category, Priority, Risk score, State. Below it is a row of tabs — each is a different view of the same incident:

Tab What's there
Overview The summary dashboard: description, timeline, business-impact + threat-intel donuts.
Details The full form — State, Category/Subcategory, Contact type, Affected user, MITRE technique/tactic, IOC fields, and the Activity / Work notes stream on the right.
Investigation The analyst's working set: Associated Observables (IOCs with a Finding verdict), Configuration Items, Affected Users, Associated Phish Emails, Email Search.
Response Tasks Sub-tasks (SIT…) assigned to teams — investigation, containment, eradication steps. In Quiet Harbor, closing a gated task can reveal evidence; Deep Current and Undertow have no gated tasks — every flag is readable directly from the records.
Related Records Everything linked to the incident, grouped: Business Impact (CIs, Affected Services), Threat Intel, Phishing (headers), Endpoint Detection and Response (EDR)Running Processes + Network Statistics.
Relationship Graph A visual map of the incident and its linked records.
MITRE Attack and Defend ATT&CK technique mapping (needs the ATT&CK repo imported on your PDI).

Triage flow (how a responder actually works it)

  1. Read the incident — description + the most recent work notes tell you what was detected and how.
  2. Confirm scope — Affected CI(s) on the Investigation/Related Records tabs; who owns the host (the CI's Assigned to), and what business service it supports (Affected Services).
  3. Work the indicators — the Observables list carries the IOCs and their verdict (Malicious / Suspicious / Clean). Pivot on them across incidents.
  4. Dig into evidence — the summary notes point you at the raw evidence; the answers to the harder questions are in the evidence, not the notes.
  5. Correlate — several incidents are one campaign. A shared indicator ties them together; look it up in the Threat Intelligence portal to attribute the adversary.
  6. Contain & record — work the Response Tasks. In Quiet Harbor, some reveal a receipt when closed (Deep Current and Undertow have no gated reveals — read the flag straight from the record).

Where the evidence lives (the hunt map)

Submitting flags

Each CTFd challenge asks for one value you read off the incident (a name, a domain, a hash, a count, a registry key…). Submit exactly what's asked. Every player's values are unique, so answers can't be shared — find yours in your incidents.

Training range — all data is synthetic. Adversary names in the TI portal are real documented groups; their attribution to your generated indicators is for the exercise.