All Case Studies
Case Study

SOC Setup &
Operations

Building a fully operational security operations center with Wazuh EDR, automated alerting, and incident response playbooks for a logistics company.

Client
Logistics Company — 150+ endpoints
Duration
8 weeks
Hours
160 Delivered
150+Endpoints Monitored
50+Alert Rules
<5minMTTD
12Playbooks
99.9%Uptime
Before & After

The Transformation

The Challenge

No centralized security monitoring. Alerts were manually checked via individual server logs. Mean time to detect incidents: hours to days. No incident response process existed.

The Result

Fully operational SOC with Wazuh EDR on 150+ endpoints, 50+ automated alert rules, mean time to detect under 5 minutes, and 12 documented incident response playbooks.

Technology Stack

Tools Deployed

Wazuhv4.8EDR & XDR
Graylogv6.1SIEM
Grafanav11Dashboards
TheHivev5Incident Response
Cortexv3Automation
N8NLatestWorkflow
Deliverables

What Was Built

Wazuh EDR Deployment

Full Wazuh stack deployed across 150+ endpoints with agents, file integrity monitoring, and vulnerability detection.

Automated Alerting

50+ custom alert rules covering brute force, privilege escalation, malware detection, and policy violations.

IR Playbooks

12 documented incident response playbooks covering ransomware, data breach, phishing, and unauthorized access.

SOC Dashboard

Real-time Grafana dashboards showing threat landscape, endpoint health, and alert trends.

Need a SOC Built?

From zero to operational SOC in weeks, not years.