Enterprise-grade Security Operations Center (QBSOC)
Internal enterprise Security Operations Center built for Quisitive Businesses LLP using Wazuh SIEM, OpenSearch Cluster, centralized logging, MITRE ATT&CK mapping and enterprise security monitoring.
25+
Assets Monitored
10+
Linux Servers
2
Windows Servers
24×7
SOC Monitoring
Production
Deployment
MSSP
Service Model
Wazuh
SIEM Platform
MITRE
ATT&CK Mapping
Project Overview
Organization
Quisitive Businesses LLP
Duration
January 2026 – June 2026
Project Type
Production Enterprise SOC
Approx Assets
25+ Servers & Endpoints
Objective
Centralize security monitoring for Windows, Linux and network infrastructure while delivering Managed Security Services (MSSP) to enterprise customers.
Environment & Infrastructure
Windows Infrastructure
- • Windows Server 2022 Active Directory
- • Windows Biometric Server
- • Group Policy (GPO)
- • Sysmon Monitoring
Linux Infrastructure
- • Ubuntu Server 22.04
- • 10+ Production Servers
- • Syslog Collection
- • Security Monitoring
Network Infrastructure
- • L2/L3 Managed Switches
- • Enterprise Firewalls
- • Wireless Access Points
- • Enterprise VLANs
Security Stack
- • Wazuh Cluster
- • OpenSearch Cluster
- • Wazuh Dashboard
- • MITRE ATT&CK Mapping
High-Level Architecture
Deployment & Implementation Workflow
High-level deployment sequence followed during implementation of the enterprise Security Operations Center.
- ✓Provisioned Ubuntu Server Virtual Machines
- ✓Installed Wazuh Manager Cluster
- ✓Configured OpenSearch Cluster
- ✓Deployed Wazuh Dashboard
Engineering Challenges & Solutions
Production deployment involved multiple infrastructure and integration challenges that required troubleshooting and optimization.
Challenges
- ⚠ Windows agents not registering through GPO
- ⚠ Sysmon Event IDs validation
- ⚠ OpenSearch cluster synchronization
- ⚠ Linux Syslog forwarding issues
- ⚠ Firewall configuration for Syslog traffic
- ⚠ Detection rule tuning & false positives
- ⚠ Dashboard role-based access configuration
Solutions Implemented
- ✓ Validated GPO deployment and agent registration
- ✓ Configured Sysmon policies and verified event collection
- ✓ Optimized OpenSearch cluster configuration
- ✓ Configured Syslog forwarding and log routing
- ✓ Updated firewall rules for secure log transmission
- ✓ Tuned custom detection rules to reduce false positives
- ✓ Implemented RBAC for Admin & Customer dashboards
Detection Engineering
Detection capabilities implemented to improve visibility, reduce false positives and enhance enterprise threat detection.
Custom Rules
Created custom Wazuh detection rules for enterprise use cases.
MITRE Mapping
Mapped detections to MITRE ATT&CK techniques.
Rule Tuning
Reduced false positives through rule optimization.
Alert Severity
Configured severity-based alert prioritization.
Threat Hunting
Performed proactive investigation using collected telemetry.
Sysmon Monitoring
Enhanced Windows visibility using Microsoft Sysmon.
Log Correlation
Centralized Windows and Linux event correlation.
RBAC
Implemented secure access for Admin and Customer dashboards.
Enterprise Security Capabilities
Security capabilities implemented across the production Security Operations Center.
Business Impact
Measurable improvements delivered through the enterprise Security Operations Center implementation.
Assets Centrally Monitored
Continuous Monitoring
Centralized Log Visibility
Threat Mapping Enabled
Investigation Time
Secure Dashboard Access
Enterprise Deployment
Service Delivery Model
Technical Skills Demonstrated
Core enterprise-level cybersecurity skills applied throughout the implementation and operation of the Security Operations Center.
SIEM Engineering
- ✓ Wazuh Deployment
- ✓ Cluster Configuration
- ✓ Log Collection
- ✓ Custom Rules
Detection Engineering
- ✓ MITRE ATT&CK
- ✓ Rule Tuning
- ✓ False Positive Reduction
- ✓ Alert Correlation
Windows Security
- ✓ Active Directory
- ✓ GPO Deployment
- ✓ Sysmon
- ✓ Endpoint Monitoring
Linux Administration
- ✓ Ubuntu Servers
- ✓ Syslog
- ✓ Service Monitoring
- ✓ System Hardening
Enterprise Infrastructure
- ✓ OpenSearch Cluster
- ✓ RBAC
- ✓ Dashboards
- ✓ Health Monitoring
SOC Operations
- ✓ Threat Hunting
- ✓ Alert Investigation
- ✓ Incident Analysis
- ✓ Security Monitoring
My Role vs Team Contribution
This Security Operations Center was implemented as a collaborative enterprise project. My responsibilities focused on SIEM deployment, detection engineering, Windows integration and operational monitoring while working closely with infrastructure and networking teams.
My Direct Contributions
- ✓ Deployed Wazuh Manager Cluster
- ✓ Configured OpenSearch Cluster
- ✓ Integrated Windows endpoints using Active Directory GPO
- ✓ Configured Microsoft Sysmon
- ✓ Integrated Linux Servers through Syslog
- ✓ Developed Custom Detection Rules
- ✓ MITRE ATT&CK Mapping
- ✓ Dashboard Design & RBAC
- ✓ Security Monitoring & Alert Investigation
- ✓ Production Health Monitoring
Team Collaboration
- • Worked alongside Infrastructure Engineers.
- • Coordinated with Network Team for Syslog routing and firewall configuration.
- • Worked with Windows Administrators for Active Directory deployment.
- • Collaborated during production rollout and validation.
- • Supported enterprise SOC operations after deployment.
- • Followed organizational security standards and deployment procedures.
Confidentiality & Responsible Disclosure
This case study has been intentionally sanitized to respect organizational confidentiality while demonstrating technical implementation experience.
Information Removed From This Case Study
Not Publicly Shared
- • Customer Names
- • Internal IP Addresses
- • Production Dashboards
- • Detection Rules
- • Internal Network Diagrams
- • Security Events & Logs
- • Infrastructure Credentials
Publicly Demonstrated
- ✓ Overall Architecture
- ✓ Deployment Workflow
- ✓ Technologies Used
- ✓ Engineering Challenges
- ✓ Security Capabilities
- ✓ Technical Contributions
- ✓ Enterprise Methodology
All sensitive organizational information has been removed or generalized. This project is presented solely to demonstrate enterprise cybersecurity engineering experience while maintaining responsible disclosure practices.
Lessons Learned & Key Takeaways
This project strengthened my understanding of enterprise SOC architecture, SIEM engineering and production security operations beyond individual technologies.
Enterprise Planning
Proper planning and architecture design significantly reduce deployment complexity and operational issues.
Log Quality Matters
High-quality telemetry from Sysmon, Syslog and Windows events is more valuable than collecting excessive logs.
Detection Engineering
Well-tuned detection rules reduce false positives and improve analyst efficiency.
Cross-Team Collaboration
Successful SOC implementation requires coordination between security, infrastructure and networking teams.
Scalability
Cluster-based architecture provides better resilience, availability and future expansion.
Continuous Improvement
SOC deployment is an ongoing process involving monitoring, tuning and optimization rather than a one-time implementation.