Alert delivery
6 mock destinations. Routing is severity-floor + escalation chain.
- Slack#sec-darkweb-criticalliveFloorcriticalTarget
slack://workspace/example-corp/#sec-darkweb-criticalEscalationManny -> SOC L1 (immediate) -> SecOps Lead (15m)
- Slack#sec-darkweb-feedliveFloorlowTarget
slack://workspace/example-corp/#sec-darkweb-feedEscalationFeed-only; no escalation.
- Emailsoc-distro@example.comliveFloorhighTarget
mailto:soc-distro@example.comEscalationDistribution list; auto-ticket if unread > 30m.
- ServiceNowServiceNow — SOC queueliveFloorhighTarget
https://example-corp.service-now.com/api/incidentEscalationAuto-INC at high+; assign group SOC-L2.
- MS TeamsTeams — Exec briefingsliveFloorcriticalTarget
https://example.webhook.office.com/REDACTEDEscalationExec channel; criticals only; CFO/CEO tagged.
- PagerDutyPagerDuty — DarkWeb on-callpausedFloorcriticalTarget
https://events.pagerduty.com/REDACTEDEscalationP1 page on critical; rotates SOC primary -> secondary at 15m.