Automation / Security Operations Engineering

Create realistic security incidents on demand

Built a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.

UK Water UtilitySelf-service test workflow development2 min read

The ServiceNow team needed repeatable Microsoft Sentinel incidents to develop and test SecOps mappings. I programmed curated incident content so the tests could exercise known entities, ATT&CK context, labels and other Sentinel fields without asking a SOC analyst to reconstruct the data for every run.

I built a Teams-triggered workflow using Copilot Studio and Power Automate. It enabled a near-real-time Sentinel analytic rule, generated a fresh incident and disabled the rule after the testing window. The original fixture included three identities and three devices, with programmed tactics, techniques and labels for the mapping checks.

I added concurrency controls to reject overlapping runs and communicate when the rule was active or ready for another test. I also corrected alert grouping so a subsequent run created a fresh incident rather than adding activity to a previous test.

I documented the process and handed it to the ServiceNow team for on-demand use. It gave developers a repeatable source of test incidents within the Sentinel, ServiceNow and XSOAR programme, while the mappings and lifecycle behaviour remained the subjects of their integration tests.

Closer to the work

Curated entities and incident fields

I programmed the incident’s entities and available Sentinel values to support ServiceNow SecOps mapping tests. The fixture brought identities, devices, ATT&CK tactics and techniques, and labels into the same controlled incident so developers could inspect how each type of context arrived in ServiceNow.

Open this detail ↗
Repeatable test data

The original fixture contained three identities and three devices. Keeping the input content known and repeatable made it possible to compare mapping behaviour across runs. The fixture defined a useful test scope; additional entity types and behaviours could require their own scenarios.

Open this detail ↗
Guardrails and rule reset

The Copilot Studio and Power Automate flow enabled the NRT analytic rule, rejected a second run while it was active, communicated its state and disabled it after the testing window. Completion messaging showed when another test could begin.

Open this detail ↗
Fresh incidents and handover

I debugged the rule’s grouping behaviour so new activity produced a fresh incident, then documented the invocation and handed it to the ServiceNow team. The automation supplied the test data; developers still inspected whether the resulting entity, field and lifecycle mappings matched their requirements.

Open this detail ↗

Skills established through this work

This work connects to

Response automationSOC engineering

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.