Building a fully operational security operations center with Wazuh EDR, automated alerting, and incident response playbooks for a logistics company.
No centralized security monitoring. Alerts were manually checked via individual server logs. Mean time to detect incidents: hours to days. No incident response process existed.
Fully operational SOC with Wazuh EDR on 150+ endpoints, 50+ automated alert rules, mean time to detect under 5 minutes, and 12 documented incident response playbooks.
Full Wazuh stack deployed across 150+ endpoints with agents, file integrity monitoring, and vulnerability detection.
50+ custom alert rules covering brute force, privilege escalation, malware detection, and policy violations.
12 documented incident response playbooks covering ransomware, data breach, phishing, and unauthorized access.
Real-time Grafana dashboards showing threat landscape, endpoint health, and alert trends.