Expadox 2: Medcore Logistics
Context, objectives, and scope of the document
MedCore Logistics is a growing fintech startup that provides online payment processing and wallet services across multiple African countries. The company recently expanded its infrastructure to include both on-premise systems and cloud workloads (AWS & Azure). As its customer base grows, it is increasingly concerned about potential cyber threats targeting its payment APIs and user data. Currently, MedCore has little visibility into user activity, failed login attempts, or network anomalies. Leadership wants to establish a centralized visibility and detection environment— something that helps them see what’s happening across endpoints, servers, and the cloud in real time. Cybernetwork has been brought in to design, implement, and operationalize a threat detection and monitoring setup using open-source tools while following standard security practices.
Research findings, data insights, and key considerations

Cybernetwork provides a walkthrough on how to achieve full visibility across Medcore’s cloud and onpremise infrastructure. this aims to provide an integrated solution to monitor endpoints, network traffic and cloud resources across different geographical regions.
Medcore Logistics currently operates 4 endpoints and 2 cloud accounts across four locations - 2 Windows workstations, 1 Linux workstation and a linux server.
The resulting inventory is four endpoints. Endpoints MED-PC-W003, MED-PC-W004 and MED-PC-L002 are designed to run both a Wazuh Agent and an Action1 Agent while the MED-SVR-L001 endpoints will run as the Wazuh server and will also host an Action1 agent.

The organization lacked a reliable and centralized endpoint inventory repository, resulting in limited visibility and accountability across its technology environment. In addition, there was no centralized logging and monitoring capability covering endpoints, servers, and cloud resources across the hybrid infrastructure ecosystem.