Case Study — Government / SOC & Managed Security
SOC-as-a-Service for a State Government Department: 4 APT Attempts Detected in 6 Months
A state government IT department managing 15 citizen-facing applications and 3,000+ endpoints across 22 district offices required 24×7 threat monitoring — without the budget or timeline to build an in-house SOC. eNeoteric deployed a cloud-SIEM SOC-as-a-Service in 30 days, and detected 4 confirmed APT-linked intrusion attempts in the first 6 months of operation.
The Challenge
The department had experienced a data exfiltration incident the previous year — personal data of 2.3 lakh citizens had been extracted via an undetected intrusion into their citizen services portal. Post-incident, the department was under CERT-In scrutiny and had a 90-day mandate to establish continuous security monitoring.
Budget constraints ruled out an on-premises SIEM deployment. Staff availability ruled out shift-based in-house monitoring. The solution had to be operational within 30 days and had to meet CERT-In's mandatory log retention and incident notification requirements.
Our Approach
- Day 1–7: Architecture design — Cloud SIEM (Microsoft Sentinel) selected for integration with existing Azure Government tenancy. Log source inventory: 15 applications, 22 district office network devices, 3,000 Windows/Linux endpoints, and 4 internet-facing servers.
- Day 8–20: Log ingestion & detection rule tuning — 180 custom detection rules created, tailored to the department's application architecture and known threat actor TTPs targeting Indian government (APT41, SideWinder). Threat intelligence feeds integrated (CERT-In TI, MISP).
- Day 21–30: SOC go-live — L1, L2, L3 analyst coverage activated. Runbooks and escalation procedures agreed with the client's IT team. Monthly board reporting template approved.
Key Detections
In the first 6 months, 4 confirmed APT-linked intrusion attempts were detected and contained:
- Attempt 1 (Day 12): Spear-phishing campaign targeting 8 officials — malicious PDF with CVE-2023-36884 exploit. Blocked at email gateway after SOC alert; no endpoint compromise.
- Attempt 2 (Month 2): Credential stuffing attack against the citizen portal login — 47,000 login attempts over 90 minutes. Rate limiting enforced in real-time; no accounts compromised.
- Attempt 3 (Month 4): Living-off-the-land lateral movement from a compromised contractor endpoint. Detected via Sentinel ML anomaly detection; isolated within 22 minutes of first alert.
- Attempt 4 (Month 6): DNS tunnelling exfiltration attempt from a district office server. Blocked via DNS security control; CERT-In notified as per mandate.
Outcomes & Impact
Zero successful breaches in 6 months of operation — a marked contrast to the prior year's undetected exfiltration. All 4 detections were escalated, contained, and documented in CERT-In-compliant incident reports within mandate timelines.
The department's subsequent CERT-In compliance review rated their security monitoring posture as "substantially improved." The SOC contract was renewed and extended to 2 additional departments.
“We went from zero monitoring to detecting an APT attempt in 12 days. eNeoteric's SOC team was treating our alerts like their own infrastructure — that level of ownership was exactly what we needed.”Principal Secretary (IT)State Government Department
Related services
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.