Skip to content
Ambara Digital Nusantara

SOC & security monitoring

A SOC on Wazuh, or on the SIEM you already have

No SIEM yet? We build the SOC on Wazuh. Already running a SIEM or EDR? We monitor and improve it where it is, with no platform change. The focus is a SOC process that is ready to run with measurable KPIs, not just installing software.

Timeline
Set by scope
From
Rp 45m / month
Platform
Wazuh or your SIEM
FrameworksMITRE ATT&CKNIST SP 800-92NIST SP 800-61 Rev. 3
Log sourcesServerEndpointFirewallOdooWazuhdecoders · rulesAlertATT&CK T1110TriageanalystResponseplaybookKPIs on the dashboardMTTAtime to acknowledgeMTTRtime to resolveCoverageATT&CK
Logs flow into Wazuh; detections mapped to MITRE ATT&CK go to triage and a playbook.

01

Scope of the implementation

01

Architecture and operating model

SOC design, monitoring coverage, roles and escalation paths.

02

Wazuh deployment

Installation and normalisation of priority log sources, in the cloud or on premises.

03

Your existing SIEM

If you already run Microsoft Sentinel, Google SecOps (Chronicle), FortiSIEM, Elastic, or EDR/XDR such as Palo Alto Cortex XDR, SentinelOne and Trellix, we monitor, review and tune it on that platform.

04

Detection use cases

Detection rules mapped to MITRE ATT&CK for your organisation’s risks.

05

False-positive tuning

Rule tuning so analysts focus on the alerts that matter.

06

Response playbooks

Triage, containment and escalation procedures for critical scenarios.

07

KPI dashboards

MTTA, MTTR, detection coverage and response effectiveness.

02

Packages

Prices depend on log volume, number of assets, hours of coverage and the complexity of your cloud or on-premises environment.

SOC Foundation (8×5)

From Rp 45 million / month

  • Wazuh deployment, or onboarding to your existing SIEM
  • Baseline detection use cases and an operations dashboard
  • Triage and escalation runbook
  • Weekly reports and a monthly review
Book a SOC discussion →

SOC Advanced (16×5)

From Rp 85 million / month

  • Deeper alert correlation and false-positive tuning
  • Threat intelligence integration and context enrichment
  • Playbooks for ransomware, account takeover and data exfiltration
  • Escalation SLA and structured post-incident reviews
Book a SOC discussion →

SOC Custom

By proposal

  • Coverage hours as agreed, including outside office hours
  • Ongoing detection engineering mapped to MITRE ATT&CK
  • Incident commander support and cross-team coordination
  • Board-level KPIs: MTTA, MTTR, coverage and maturity
Book a SOC discussion →

03

What you receive

  • SOC architecture and monitoring scope documentation
  • Priority detection rule library with initial tuning results
  • Incident playbooks for critical scenarios
  • Security posture report and recommendations for continuous improvement

04

Frequently asked questions

What are the benefits of a Wazuh-based SOC?

Centralised threat monitoring, faster detection and a measurable incident response process, without commercial SIEM licence fees.

We already run a SIEM other than Wazuh. Can you help?

Yes. We work in Microsoft Sentinel, Google SecOps (Chronicle), FortiSIEM, Elastic, or EDR/XDR such as Palo Alto Cortex XDR, SentinelOne and Trellix. We can monitor alerts on your platform, tidy up detection use cases, reduce false positives and write response playbooks, with no migration needed.

Is it suitable if we have no SOC yet?

Yes. It is designed both for organisations starting a SOC and for those maturing an existing one.

How long does implementation take?

It depends on the scope: the number of assets, the variety of log sources, the detection use cases needed and how ready the infrastructure is. We give a time estimate after scoping.

Are incident response playbooks included?

Yes. Every package includes triage, containment and escalation runbooks and playbooks so your team responds consistently.

05

Build detection you can measure

We support you from the initial assessment, through a Wazuh deployment or strengthening your existing SIEM, to day-to-day incident response.

Book a SOC discussion