The ServiceNow team needed repeatable Microsoft Sentinel incidents to develop and test SecOps mappings. I programmed curated incident content so the tests could exercise known entities, ATT&CK context, labels and other Sentinel fields without asking a SOC analyst to reconstruct the data for every run.
I built a Teams-triggered workflow using Copilot Studio and Power Automate. It enabled a near-real-time Sentinel analytic rule, generated a fresh incident and disabled the rule after the testing window. The original fixture included three identities and three devices, with programmed tactics, techniques and labels for the mapping checks.
I added concurrency controls to reject overlapping runs and communicate when the rule was active or ready for another test. I also corrected alert grouping so a subsequent run created a fresh incident rather than adding activity to a previous test.
I documented the process and handed it to the ServiceNow team for on-demand use. It gave developers a repeatable source of test incidents within the Sentinel, ServiceNow and XSOAR programme, while the mappings and lifecycle behaviour remained the subjects of their integration tests.
Closer to the work
Curated entities and incident fields
I programmed the incident’s entities and available Sentinel values to support ServiceNow SecOps mapping tests. The fixture brought identities, devices, ATT&CK tactics and techniques, and labels into the same controlled incident so developers could inspect how each type of context arrived in ServiceNow.
Open this detail ↗Repeatable test data
The original fixture contained three identities and three devices. Keeping the input content known and repeatable made it possible to compare mapping behaviour across runs. The fixture defined a useful test scope; additional entity types and behaviours could require their own scenarios.
Open this detail ↗Guardrails and rule reset
The Copilot Studio and Power Automate flow enabled the NRT analytic rule, rejected a second run while it was active, communicated its state and disabled it after the testing window. Completion messaging showed when another test could begin.
Open this detail ↗Fresh incidents and handover
I debugged the rule’s grouping behaviour so new activity produced a fresh incident, then documented the invocation and handed it to the ServiceNow team. The automation supplied the test data; developers still inspected whether the resulting entity, field and lifecycle mappings matched their requirements.
Open this detail ↗Skills established through this work