Infrastructure Scenario Tests

We test Corax against real-world infrastructure failures across every vendor, platform, and scenario. Browse the results below.

276
Total Tests
100.0%
Pass Rate
276
Passed
0
Failed

NOC Shift Handoff — Critical Alert Missed

PASS

During a NOC shift handoff, a critical alert for a client's ransomware detection is missed. The outgoing shift marked it as acknowledged but did not brief the incoming shift. The ransomware spreads for 4 additional hours before discovery.

InfrastructurePattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands17 correlated

Ticketing Auto-Escalation Loop

PASS

The PSA ticketing system enters an auto-escalation loop where a ticket is escalated, triggers a workflow that reassigns it, which triggers another escalation, creating an infinite loop. The ticket generates 500+ email notifications and consumes the email sending quota.

InfrastructurePattern: HIGH_CPUSeverity: CRITICALConfidence: 95%Auto-Heal7 correlated

Documentation System Down During Outage

PASS

The IT documentation platform (IT Glue/Hudu) becomes unreachable during a major client outage. Technicians cannot access network diagrams, credential vaults, or runbook procedures needed to resolve the issue. The documentation system is hosted on the same infrastructure experiencing the outage.

InfrastructurePattern: CONNECTION_REFUSEDSeverity: CRITICALConfidence: 85%Remote Hands9 correlated

Client Site ISP Failover Not Working

PASS

A managed client's secondary ISP failover fails to activate when the primary circuit goes down. The SD-WAN appliance detects the primary failure but the secondary circuit is disconnected due to an unpaid bill. The site is completely offline.

NetworkPattern: TIMEOUTSeverity: CRITICALConfidence: 95%Remote Hands16 correlated

Remote Monitoring False Alarm Storm

PASS

The RMM platform generates a false alarm storm after a monitoring agent update pushes incorrect threshold values. 2,000+ alerts fire simultaneously across all managed clients, overwhelming the NOC and masking real issues.

InfrastructurePattern: SNMP_TRAP_ERRORSeverity: CRITICALConfidence: 85%Auto-Heal16 correlated

Network TAP/SPAN Port Oversubscription

PASS

The network TAP aggregating traffic for the IDS/IPS and packet capture system becomes oversubscribed. The 10G TAP is receiving 14Gbps of traffic, causing 28% packet loss on the monitoring feed. The IDS misses attack signatures and the packet capture has gaps.

NetworkPattern: PERFORMANCE_DEGRADATIONSeverity: CRITICALConfidence: 85%Remote Hands6 correlated

QoS Misconfiguration — Voice Traffic Not Prioritized

PASS

A switch firmware upgrade resets QoS policies on 12 access switches, removing DSCP marking and priority queuing for voice traffic. VoIP call quality degrades severely during business hours when data traffic competes with voice.

NetworkPattern: VOIP_QUALITYSeverity: CRITICALConfidence: 85%Remote Hands13 correlated

802.1X MAB Failure — IoT Devices Locked Out

PASS

A RADIUS policy change breaks MAC Authentication Bypass (MAB) for IoT devices. Security cameras, badge readers, and building management sensors are all locked out of the network as they cannot perform 802.1X EAP authentication.

NetworkPattern: ACTIVE_DIRECTORYSeverity: CRITICALConfidence: 92%Remote Hands13 correlated

IPAM Exhaustion — No Addresses to Allocate

PASS

The IP Address Management system shows all subnets in the production VLAN are fully allocated. DHCP scopes have no available leases, and new devices cannot obtain IP addresses. Server provisioning and workstation deployment are both blocked.

NetworkPattern: DHCP_EXHAUSTIONSeverity: CRITICALConfidence: 90%Auto-Heal4 correlated

NTP Stratum Drift — Multiple Servers Affected

PASS

The primary NTP server loses its upstream time source and begins drifting. As a stratum 1 source for the internal network, all downstream servers inherit the drift. Kerberos authentication begins failing when clock skew exceeds 5 minutes.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands6 correlated

TFTP Server Unreachable — Switch Config Backup Failing

PASS

The TFTP server used for automated network device configuration backups becomes unreachable after a server migration. Nightly configuration backups for 80 network devices have not run for 7 days, leaving no recent configuration recovery point.

NetworkPattern: CONNECTION_REFUSEDSeverity: CRITICALConfidence: 85%Auto-Heal4 correlated

Syslog UDP Overflow — Log Data Loss

PASS

The centralized syslog server cannot keep up with the volume of incoming UDP syslog messages during a network event. UDP packets are dropped at the kernel level, causing critical security and audit log data to be permanently lost.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Auto-Heal6 correlated

RADIUS Accounting Failure — Billing Data Loss

PASS

The RADIUS accounting server becomes unresponsive, causing all network access devices to fail sending accounting records. ISP billing data is lost for 8 hours, and compliance logging for network access events stops.

NetworkPattern: SNMP_TRAP_ERRORSeverity: CRITICALConfidence: 85%Auto-Heal8 correlated

SPF/DKIM/DMARC Misconfiguration — Emails Rejected

PASS

After a DNS migration, SPF, DKIM, and DMARC records are not properly recreated. Outbound emails are rejected by major providers (Gmail, Microsoft) due to authentication failures, and the company's email reputation score drops rapidly.

InfrastructurePattern: SERVER_ERRORSeverity: CRITICALConfidence: 92%Remote Hands4 correlated

Journaling Mailbox Full — Compliance Risk

PASS

The Exchange journaling mailbox reaches its storage quota, causing journal reports to be NDR'd back to the sender. Email journaling stops functioning, creating a compliance gap for regulatory requirements (HIPAA, SEC Rule 17a-4).

InfrastructurePattern: EXCHANGE_EVENTSeverity: CRITICALConfidence: 95%Remote Hands4 correlated

Email Attachment Size Policy Causing Bounce Storm

PASS

A message size limit reduction on the Exchange transport rule causes a bounce storm. Automated systems sending reports with large attachments generate NDRs, which trigger auto-reply rules, creating a feedback loop of bounces and replies that overwhelms the mail system.

InfrastructurePattern: EXCHANGE_EVENTSeverity: CRITICALConfidence: 85%Remote Hands4 correlated

SMTP Relay Open Relay Abuse — Spam Storm

PASS

An internal SMTP relay is misconfigured as an open relay after a firewall change exposes it to the internet. Spammers discover and abuse it within hours, sending thousands of spam emails through the relay, causing the company's IP to be blacklisted.

InfrastructurePattern: EXCHANGE_EVENTSeverity: CRITICALConfidence: 95%Remote Hands6 correlated

Exchange Online Protection Blocking Legitimate Email

PASS

Exchange Online Protection (EOP) begins quarantining legitimate business emails from a major client after a policy update. The mail flow disruption goes unnoticed for 6 hours until the client calls to complain about unanswered communications.

InfrastructurePattern: EXCHANGE_EVENTSeverity: CRITICALConfidence: 95%Remote Hands6 correlated

LDAP Channel Binding Enforcement Breaking Legacy Apps

PASS

After enabling LDAP channel binding and signing enforcement on domain controllers (per Microsoft security advisory), multiple legacy applications that use simple LDAP binds break. Printers, scanners, and legacy ERP systems cannot authenticate against Active Directory.

InfrastructurePattern: ACTIVE_DIRECTORYSeverity: CRITICALConfidence: 92%Remote Hands10 correlated

Password Hash Sync Failure

PASS

Active Directory password hash synchronization between on-premises AD and Azure AD breaks after a domain controller is decommissioned. Users who change their on-premises passwords find their Azure AD passwords still use the old value, causing login failures for cloud services.

InfrastructurePattern: ACTIVE_DIRECTORYSeverity: CRITICALConfidence: 92%Remote Hands6 correlated
PreviousPage 6 of 14Next

Every scenario is tested against Corax's Neural Engine in a production environment with AI-powered root cause analysis.

Tests run continuously as new infrastructure patterns are added.