Enterprise Case Study

Enterprise-grade Security Operations Center (QBSOC)

Internal enterprise Security Operations Center built for Quisitive Businesses LLP using Wazuh SIEM, OpenSearch Cluster, centralized logging, MITRE ATT&CK mapping and enterprise security monitoring.

25+

Assets Monitored

10+

Linux Servers

2

Windows Servers

24×7

SOC Monitoring

Production

Deployment

MSSP

Service Model

Wazuh

SIEM Platform

MITRE

ATT&CK Mapping

Project Overview

Organization

Quisitive Businesses LLP

Duration

January 2026 – June 2026

Project Type

Production Enterprise SOC

Approx Assets

25+ Servers & Endpoints

Objective

Centralize security monitoring for Windows, Linux and network infrastructure while delivering Managed Security Services (MSSP) to enterprise customers.

Environment & Infrastructure

Windows Infrastructure

  • • Windows Server 2022 Active Directory
  • • Windows Biometric Server
  • • Group Policy (GPO)
  • • Sysmon Monitoring

Linux Infrastructure

  • • Ubuntu Server 22.04
  • • 10+ Production Servers
  • • Syslog Collection
  • • Security Monitoring

Network Infrastructure

  • • L2/L3 Managed Switches
  • • Enterprise Firewalls
  • • Wireless Access Points
  • • Enterprise VLANs

Security Stack

  • • Wazuh Cluster
  • • OpenSearch Cluster
  • • Wazuh Dashboard
  • • MITRE ATT&CK Mapping

High-Level Architecture

InternetEnterprise FirewallCore L2 / L3 SwitchWindows InfrastructureLinux InfrastructureWazuh Manager ClusterOpenSearch ClusterDetection EngineAdmin DashboardCustomer Dashboard

Deployment & Implementation Workflow

High-level deployment sequence followed during implementation of the enterprise Security Operations Center.

  • Provisioned Ubuntu Server Virtual Machines
  • Installed Wazuh Manager Cluster
  • Configured OpenSearch Cluster
  • Deployed Wazuh Dashboard

Engineering Challenges & Solutions

Production deployment involved multiple infrastructure and integration challenges that required troubleshooting and optimization.

Challenges

  • ⚠ Windows agents not registering through GPO
  • ⚠ Sysmon Event IDs validation
  • ⚠ OpenSearch cluster synchronization
  • ⚠ Linux Syslog forwarding issues
  • ⚠ Firewall configuration for Syslog traffic
  • ⚠ Detection rule tuning & false positives
  • ⚠ Dashboard role-based access configuration

Solutions Implemented

  • ✓ Validated GPO deployment and agent registration
  • ✓ Configured Sysmon policies and verified event collection
  • ✓ Optimized OpenSearch cluster configuration
  • ✓ Configured Syslog forwarding and log routing
  • ✓ Updated firewall rules for secure log transmission
  • ✓ Tuned custom detection rules to reduce false positives
  • ✓ Implemented RBAC for Admin & Customer dashboards

Detection Engineering

Detection capabilities implemented to improve visibility, reduce false positives and enhance enterprise threat detection.

Custom Rules

Created custom Wazuh detection rules for enterprise use cases.

MITRE Mapping

Mapped detections to MITRE ATT&CK techniques.

Rule Tuning

Reduced false positives through rule optimization.

Alert Severity

Configured severity-based alert prioritization.

Threat Hunting

Performed proactive investigation using collected telemetry.

Sysmon Monitoring

Enhanced Windows visibility using Microsoft Sysmon.

Log Correlation

Centralized Windows and Linux event correlation.

RBAC

Implemented secure access for Admin and Customer dashboards.

Enterprise Security Capabilities

Security capabilities implemented across the production Security Operations Center.

Centralized Log Collection
Windows Endpoint Monitoring
Linux Syslog Monitoring
MITRE ATT&CK Mapping
Custom Detection Rules
Role Based Access Control
Cluster High Availability
Dashboard Segregation
Threat Detection
Security Monitoring
Alert Investigation
Health Monitoring

Business Impact

Measurable improvements delivered through the enterprise Security Operations Center implementation.

25+

Assets Centrally Monitored

24×7

Continuous Monitoring

100%

Centralized Log Visibility

MITRE

Threat Mapping Enabled

Reduced

Investigation Time

RBAC

Secure Dashboard Access

Production

Enterprise Deployment

MSSP

Service Delivery Model

Technical Skills Demonstrated

Core enterprise-level cybersecurity skills applied throughout the implementation and operation of the Security Operations Center.

SIEM Engineering

  • Wazuh Deployment
  • Cluster Configuration
  • Log Collection
  • Custom Rules

Detection Engineering

  • MITRE ATT&CK
  • Rule Tuning
  • False Positive Reduction
  • Alert Correlation

Windows Security

  • Active Directory
  • GPO Deployment
  • Sysmon
  • Endpoint Monitoring

Linux Administration

  • Ubuntu Servers
  • Syslog
  • Service Monitoring
  • System Hardening

Enterprise Infrastructure

  • OpenSearch Cluster
  • RBAC
  • Dashboards
  • Health Monitoring

SOC Operations

  • Threat Hunting
  • Alert Investigation
  • Incident Analysis
  • Security Monitoring

My Role vs Team Contribution

This Security Operations Center was implemented as a collaborative enterprise project. My responsibilities focused on SIEM deployment, detection engineering, Windows integration and operational monitoring while working closely with infrastructure and networking teams.

My Direct Contributions

  • ✓ Deployed Wazuh Manager Cluster
  • ✓ Configured OpenSearch Cluster
  • ✓ Integrated Windows endpoints using Active Directory GPO
  • ✓ Configured Microsoft Sysmon
  • ✓ Integrated Linux Servers through Syslog
  • ✓ Developed Custom Detection Rules
  • ✓ MITRE ATT&CK Mapping
  • ✓ Dashboard Design & RBAC
  • ✓ Security Monitoring & Alert Investigation
  • ✓ Production Health Monitoring

Team Collaboration

  • • Worked alongside Infrastructure Engineers.
  • • Coordinated with Network Team for Syslog routing and firewall configuration.
  • • Worked with Windows Administrators for Active Directory deployment.
  • • Collaborated during production rollout and validation.
  • • Supported enterprise SOC operations after deployment.
  • • Followed organizational security standards and deployment procedures.

Confidentiality & Responsible Disclosure

This case study has been intentionally sanitized to respect organizational confidentiality while demonstrating technical implementation experience.

🔒

Information Removed From This Case Study

Not Publicly Shared

  • • Customer Names
  • • Internal IP Addresses
  • • Production Dashboards
  • • Detection Rules
  • • Internal Network Diagrams
  • • Security Events & Logs
  • • Infrastructure Credentials

Publicly Demonstrated

  • ✓ Overall Architecture
  • ✓ Deployment Workflow
  • ✓ Technologies Used
  • ✓ Engineering Challenges
  • ✓ Security Capabilities
  • ✓ Technical Contributions
  • ✓ Enterprise Methodology

All sensitive organizational information has been removed or generalized. This project is presented solely to demonstrate enterprise cybersecurity engineering experience while maintaining responsible disclosure practices.

Lessons Learned & Key Takeaways

This project strengthened my understanding of enterprise SOC architecture, SIEM engineering and production security operations beyond individual technologies.

Enterprise Planning

Proper planning and architecture design significantly reduce deployment complexity and operational issues.

Log Quality Matters

High-quality telemetry from Sysmon, Syslog and Windows events is more valuable than collecting excessive logs.

Detection Engineering

Well-tuned detection rules reduce false positives and improve analyst efficiency.

Cross-Team Collaboration

Successful SOC implementation requires coordination between security, infrastructure and networking teams.

Scalability

Cluster-based architecture provides better resilience, availability and future expansion.

Continuous Improvement

SOC deployment is an ongoing process involving monitoring, tuning and optimization rather than a one-time implementation.