Security Monitoring Environment

MedCore Logistics · Expadox Limited internship, cohort 3

Team project · 14-day sprint · 4 endpoints across hybrid on-premise + AWS/Azure infrastructure

The problem

MedCore Logistics is a fintech startup providing online payment processing and wallet services across multiple African countries. Its infrastructure spans on-premise systems and AWS and Azure cloud workloads, but there was no centralized logging, no visibility into failed logins or network anomalies, and no structured detection or escalation process. Payment APIs and user data were a direct target for credential stuffing and data exfiltration, with detection delay as the single biggest driver of breach cost. The team had 14 days to design and stand up a centralized security monitoring environment delivering real-time detection, automated alerting, and evidence-based reporting across endpoints, network, and cloud.

Slide showing MedCore's visibility gap: current state and why it matters
The visibility gap going in: no centralized logging, unnoticed anomalies, and growing exposure on payment APIs.
14-day delivery roadmap covering foundation, detection, validation, and reporting phases
The 14-day delivery roadmap: foundation, detection, validation, and reporting phases.

My role

This was a team build, split across analyst, engineer, and responder responsibilities. My specific contributions:

Solution architecture

Log sources from on-premise servers, Windows and Linux endpoints, AWS CloudTrail, Azure Activity Log, and Suricata network sensors are tied together through an encrypted Tailscale mesh, removing the need for open inbound firewall ports. Wazuh sits at the core for ingestion, correlation, and detection mapped to MITRE ATT&CK, with Action1 covering endpoint patch and vulnerability visibility and Suricata covering network-based detection.

Proposed architecture diagram showing log sources flowing through Tailscale into the Wazuh, Action1, and Suricata core platform
The proposed architecture: log sources, secure transport via Tailscale, the Wazuh/Action1/Suricata core, and detection output.
Table showing the tool stack, what each platform covers, and the scope boundaries of the 14-day build
Tool stack and scope: what each platform covers and the boundaries of the 14-day proof of concept.
Tailscale admin console showing all four MedCore endpoints connected to the mesh network
All four endpoints connected and visible on the Tailscale mesh, tying the distributed locations together.

Deployment

The Wazuh manager, indexer, and dashboard were deployed on MED-SVR-L001, with agents rolled out across the Windows and Linux endpoints. Suricata was installed and configured on every endpoint, generating structured EVE JSON logs and feeding alerts back into the Wazuh dashboard for correlation, with severity-based email alerting configured on top.

Installing the Wazuh agent and registering it with the manager
Installing the Wazuh agent and registering it with the manager on MED-SVR-L001.
Completing Wazuh agent enrollment and confirming the connection to the manager
Completing agent enrollment and confirming the connection back to MED-SVR-L001.
Wazuh dashboard overview showing alert counts and MITRE ATT&CK breakdown for the newly onboarded endpoints
Wazuh dashboard overview after onboarding, showing alert volume and top MITRE ATT&CK techniques observed.
Wazuh dashboard confirming all four endpoints reporting in as active agents
Wazuh dashboard confirming all four endpoints reporting in as active, connected agents.
Terminal output showing Suricata installation and rules database setup on a Linux endpoint
Suricata installation on MED-SVR-L001.
Suricata rules database configured and loaded on the Linux endpoints
Suricata rules database configured and loaded on the Linux endpoints.
Suricata alerts flowing into the Wazuh dashboard confirming network detection is live
Suricata alerts flowing into the Wazuh dashboard, confirming network detection is live end to end.
Severity-based email alerting configured on the Wazuh server
Severity-based email alerting configured on the Wazuh server, the notification channel used alongside the dashboard.

Cloud visibility (AWS & Azure)

Alongside the endpoint and network layers, AWS CloudTrail and Azure Activity Log were brought into the same Wazuh pipeline, so account and subscription-level activity in both clouds is visible from the same dashboard the SOC analyst already uses.

AWS account set up to capture CloudTrail activity for the environment
AWS account set up to capture CloudTrail activity for the environment.
Azure account set up to capture Activity Log events for the environment
Azure account set up to capture Activity Log events for the environment.
AWS and Azure log ingestion configured on the Wazuh server
AWS and Azure log ingestion configured on the Wazuh server.
AWS CloudTrail and Azure Activity Log events confirmed flowing into the Wazuh dashboard
AWS CloudTrail and Azure Activity Log events confirmed flowing into the Wazuh dashboard.

Attack simulation and detection validation

Atomic Red Team was used to safely reproduce three real-world attack patterns from MED-PC-L002 and confirm the monitoring stack actually detects them, not just logs activity.

Atomic Red Team installed on MED-PC-L002, the host used to run all three attack simulations
Atomic Red Team installed on MED-PC-L002, the host used to run all three attack simulations.
ScenarioMITRE ATT&CK IDStatus
Brute force (SSH credential stuffing)T1110.004Confirmed on Wazuh dashboard + email
Privilege escalation (sudo to root)T1548.003Confirmed on Wazuh dashboard
Data exfiltration (HTTP over non-standard port)T1048.003Executed live; custom Suricata rule authored, detection tuning in progress
Terminal showing the brute force simulation conclusion and the resulting Wazuh email alert notification
Brute force simulation on MED-PC-L002, and the resulting Wazuh alert email received within minutes.
Wazuh dashboard showing privilege escalation alerts mapped to MITRE ATT&CK technique T1548.003
Wazuh dashboard correlating repeated sudo-to-root events to MITRE ATT&CK T1548.003.
Terminal output showing the data exfiltration test executed against MED-PC-L002
Data exfiltration test executed against MED-PC-L002 to validate the custom detection rule.

Vulnerability visibility

Action1 covered endpoint patch and vulnerability visibility across all four enrolled endpoints, starting from an enrollment baseline before any remediation, through to a full vulnerability assessment by severity.

Action1 console showing all four endpoints enrolled and reporting for patch management before remediation
Action1 baseline: all four endpoints enrolled and reporting for patch management, captured before remediation began. This shows enrollment and coverage, not a vulnerability count.

Action1 then ran an initial vulnerability assessment across all four enrolled endpoints, surfacing 426 critical, 2,425 high, 2,473 medium, and 27 low severity findings to establish a remediation baseline.

Wazuh vulnerability detection dashboard showing findings by severity across MedCore endpoints
Vulnerability findings by severity, top affected OS, and top vulnerable packages across the enrolled endpoints.

Outcome

Final Network Architecture / Security Posture After Security Solutions Were Deployed

Before this build, MedCore had no centralized logging, no vulnerability baseline, and no visibility into failed logins or network anomalies across its on-premise and cloud infrastructure. After deployment, every endpoint reports into a central Wazuh platform correlated against AWS CloudTrail and Azure Activity Log, vulnerabilities are tracked through Action1, and confirmed threats trigger both a dashboard alert and a severity-based email notification to the SOC analyst.

Final MedCore security monitoring architecture showing exact endpoint specs, AWS and Azure log sources, and email alerting
The as-delivered architecture with actual endpoint specs, cloud log sources, and the email alerting path.

By the end of the sprint, all four endpoints were connected through the Tailscale mesh with Wazuh operational as the central correlation platform and Suricata active across every endpoint. Two of the three required attack simulations, brute force and privilege escalation, were fully confirmed end to end with dashboard and email evidence. The third, data exfiltration, was executed as a live test with a custom Suricata rule authored for it; detection tuning was still in progress at the time of reporting rather than treated as silently complete. The environment reliably detects and alerts on unauthorized access and privilege escalation attempts today, with the remaining work scoped to narrowing one specific detection gap rather than any further deployment.

The full project report, including the detailed 14-day roadmap, architecture notes, every deployment screenshot, and the incident response runbooks for all three scenarios, is documented on Notion.

View full report on Notion →