SOC & Security

Enterprise SOC & Metrics Monitoring

Deployed a full Security Operations Center with Wazuh SIEM + XDR, combined with comprehensive metrics monitoring for an IT enterprise with many servers.

thousands
High Vulnerabilities
hundreds
Critical Vulnerabilities
15
Wazuh Agents
14
Zabbix Hosts
tens of thousands
Vulnerability Records
5 min
Incident Detection

📌 Challenge

An IT enterprise with many servers had no centralized monitoring system. Key issues:

  • No overview of the entire infrastructure's security posture
  • Vulnerability discovery was manual — many persisted for months
  • No real-time CPU, RAM, disk metrics — incidents only discovered when users complained
  • No alerting system — ops team discovered issues via email or phone calls from users
  • Fragmented legacy system, each server with its own dashboard

🛠 Solution

1. SOC with Wazuh SIEM + XDR

Deployed Wazuh with 15 agents across 2 groups: centralized log collection, intrusion detection, vulnerability scanning, FIM, and compliance monitoring. Wazuh Indexer (OpenSearch 2.19.5) stores tens of thousands vulnerability records.

2. Metrics Monitoring with Zabbix

Deployed Zabbix 7.4 monitoring 14 hosts. Real-time dashboard for CPU, RAM, disk, network, services. Smart alert thresholds with auto-escalation.

3. Telegram Bot Alerts

Integrated Telegram Bot — real-time alerts with severity, CVE ID, description, remediation links.

4. NVD/CISA KEV Tracking

Auto-update vulnerability database from NVD and CISA Known Exploited Vulnerabilities.

🏆 Results

  • many High + Critical vulnerabilities detected, classified, and managed via Wazuh
  • Incident detection within 5 minutes — reduced from 48h+
  • 24/7 metrics monitoring — CPU, RAM, disk, network across 14 hosts
  • Zero downtime since deployment

💼 Technology Stack

Wazuh 4.14 Zabbix 7.4 OpenSearch 2.19.5 Docker n8n Telegram Bot NVD API CISA KEV

Need to deploy SOC for your business?

☎ Call us← View other projects
Call now📞Zalo💬Facebook