Infrastructure Scenario Tests

We test Corax against real-world infrastructure failures across every vendor, platform, and scenario. Browse the results below.

276
Total Tests
100.0%
Pass Rate
276
Passed
0
Failed

PDU Circuit Breaker Trip in Server Rack

PASS

A power distribution unit circuit breaker trips in the primary server rack, cutting power to 6 servers including the domain controller, file server, and monitoring system. UPS did not engage because the PDU breaker is downstream.

InfrastructurePattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands35 correlated

Fiber Optic Cable Cut — Dark Fiber Link Down

PASS

A construction crew accidentally cuts the dark fiber connecting two office buildings, severing all network connectivity between the primary data center and the disaster recovery site, including storage replication.

InfrastructurePattern: NIC_ERRORSSeverity: CRITICALConfidence: 95%Remote Hands35 correlated

Datto RMM Script Execution Failure

PASS

The Datto RMM platform experiences a component monitor failure causing all automated remediation scripts to fail silently, leaving 200 endpoints without automated patching and maintenance for a week.

VendorPattern: BACKUP_FAILURESeverity: CRITICALConfidence: 85%Remote Hands24 correlated

Kaseya VSA Agent Heartbeat Loss

PASS

The Kaseya VSA server loses heartbeat connectivity from 150 managed endpoints simultaneously after a VSA server renewal breaks the agent communication channel.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands22 correlated

Datto BCDR Backup Appliance Failure

PASS

A Datto SIRIS 5 BCDR appliance experiences a storage controller failure, halting all local backups and breaking the chain for 15 protected servers. Cloud offsite replication also stops.

VendorPattern: BACKUP_FAILURESeverity: CRITICALConfidence: 95%Remote Hands22 correlated

Cisco Catalyst SD-WAN vEdge Offline

PASS

A Cisco Catalyst SD-WAN vEdge router at a critical branch office goes offline after a control connection failure to all vSmart controllers, isolating the branch from the SD-WAN fabric and dropping all overlay paths.

VendorPattern: CISCO_EVENTSeverity: CRITICALConfidence: 85%Remote Hands30 correlated

Cisco UCS Blade Server Failure

PASS

A Cisco UCS B200 M6 blade server in a UCS 5108 chassis experiences a memory DIMM failure that causes repeated reboots, affecting 20 VMs hosted on the blade and triggering VMware HA restarts.

VendorPattern: CISCO_EVENTSeverity: CRITICALConfidence: 95%Remote Hands18 correlated

Cisco Webex Calling Service Outage

PASS

Cisco Webex Calling cloud service experiences a regional outage affecting all cloud-connected phones and soft clients at the organization, with calls failing to connect and existing calls dropping.

VendorPattern: CISCO_EVENTSeverity: CRITICALConfidence: 95%Remote Hands28 correlated

Cisco DNA Center Assurance Alert — Network Health Critical

PASS

Cisco DNA Center detects a widespread network health issue across 50 managed switches and 200 APs, with AI-driven assurance identifying a misconfigured QoS policy as the root cause.

VendorPattern: CISCO_EVENTSeverity: CRITICALConfidence: 85%Remote Hands20 correlated

Cisco ISE RADIUS Authentication Failure

PASS

Both Cisco ISE Policy Service Nodes (PSNs) in an HA pair experience a Java heap exhaustion, causing all RADIUS authentications to fail and locking out 3000 users from wired and wireless networks.

VendorPattern: CISCO_EVENTSeverity: CRITICALConfidence: 92%Auto-Heal28 correlated

Ruckus Wireless Mesh Link Failure

PASS

A Ruckus outdoor mesh network loses its primary mesh backhaul link between two T750SE APs during a rainstorm, isolating 8 downstream mesh APs and 150 connected clients in an outdoor venue.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 90%Remote Hands18 correlated

Ruckus ICX Switch Stack Partition

PASS

A Ruckus ICX 7650 switch stack of 6 members partitions when a stacking module fails on the middle unit, splitting the stack into two independent 3-member segments with duplicate configurations.

VendorPattern: SWITCH_STACK_EVENTSeverity: CRITICALConfidence: 92%Remote Hands20 correlated

Ruckus SmartZone Controller Failure

PASS

The primary Ruckus SmartZone 300 wireless controller experiences a database corruption, causing all 200 managed APs to lose their management connection and fall back to standalone mode with limited functionality.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands29 correlated

WatchGuard FireCluster Sync Failure

PASS

A WatchGuard Firebox M690 FireCluster experiences a configuration sync failure between the active and standby units, leaving the standby with an outdated policy that would cause an outage if failover occurs.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 90%Remote Hands22 correlated

WatchGuard AuthPoint MFA Outage

PASS

The WatchGuard AuthPoint cloud MFA service becomes unreachable, preventing all multi-factor authentication for VPN, web applications, and network access across the organization.

VendorPattern: SERVER_ERRORSeverity: CRITICALConfidence: 85%Remote Hands21 correlated

WatchGuard Firebox BOVPN Tunnel Flap

PASS

A WatchGuard Firebox M590 experiences persistent BOVPN instability to 6 branch offices due to a phase 2 SA lifetime mismatch after a firmware upgrade, causing intermittent branch connectivity.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands27 correlated

Sophos Intercept X False Positive Blocking Business App

PASS

Sophos Intercept X behavioral analysis blocks a legitimate custom in-house application as ransomware due to its file encryption behavior (the app encrypts documents for secure transfer), preventing a critical business process.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands21 correlated

Sophos Central EDR Quarantine Storm

PASS

A Sophos Central Intercept X update causes the EDR engine to quarantine a critical Windows system DLL across all managed endpoints, rendering 300 workstations unable to run key business applications.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands20 correlated

Sophos XG WAF Rule Blocking Customer Portal

PASS

A Sophos XG 330 web application protection rule blocks legitimate customer portal traffic by flagging JSON API payloads as SQL injection attempts, preventing all customer-facing operations.

VendorPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands21 correlated

HPE SimpliVity HCI Node Rebuild Failure

PASS

An HPE SimpliVity 380 Gen10 node fails during a rebuild operation after a previous disk replacement, leaving the cluster in a reduced state with lower storage efficiency and no fault tolerance.

VendorPattern: VMWARE_EVENTSeverity: CRITICALConfidence: 92%Remote Hands21 correlated
PreviousPage 4 of 14Next

Every scenario is tested against Corax's Neural Engine in a production environment with AI-powered root cause analysis.

Tests run continuously as new infrastructure patterns are added.