How Embee Software stood up a unified Microsoft Sentinel SOC for a new international airport, turning a greenfield site with zero security analytics into an identity-first, automated Cyber Defense Center.
The Challenge
The customer, a new international airport in India, was coming online as a greenfield operation and was set to go live with no centralized security analytics of any kind. Security ran out of individual product consoles (Microsoft Defender, Check Point, Cisco, Entra ID), with no single pane of glass and no way to correlate alerts across them.
The core gaps:
- No SIEM/SOAR platform — zero security analytics capability
- Siloed, single-product monitoring with no unified visibility
- No cross-product alert correlation to surface full attack chains
- Manual SOC operations, slowing detection and response
- No identity-centric threat detection for a distributed field workforce
The trigger was timing. A greenfield airport is a one-time opportunity to build security in from Day 1 rather than retrofit it later and with zero existing capability, the risk window was already live. With a Microsoft-heavy, cloud-first estate migrating to Azure and hybrid, Microsoft Sentinel was the natural foundation for a unified SOC spanning both Microsoft and non-Microsoft tools.
The Solution
Embee Software delivered an end-to-end Cyber Defense Center on Microsoft Sentinel — SIEM, SOAR, UEBA, and managed SOC under one roof using its structured Understand → Evaluate → Test → Implement → Transform methodology across a seven-phase journey from kickoff to SOC handover.
What Embee Software built:
- Deployed Microsoft Sentinel with a Log Analytics Workspace in Azure
- Stood up a Syslog/CEF server to ingest firewall, switch, and router logs
- Established a Site-to-Site IPSec tunnel (Airtel primary + JIO failover) for resilient on-prem log forwarding
- Configured 11 data connectors — Entra ID, Defender XDR, Microsoft 365, Azure WAF, Netskope, Syslog/CEF, and more
- Built 108 built-in plus 29 custom KQL analytic rules, each mapped to MITRE ATT&CK
- Enabled UEBA and ML behaviour analytics for anomaly detection
- Deployed a SOAR playbook to auto-revoke risky user sessions
- Integrated ServiceNow ITSM for automated incident ticketing and SLA tracking
- Built custom CISO and CDIO dashboards as KQL workbooks for executive visibility
- Delivered a knowledge-transfer session to the airport’s security team
Microsoft products & services: Microsoft Sentinel, Azure Log Analytics, Microsoft Defender XDR, Microsoft Entra ID, Microsoft 365, and Azure Web Application Firewall integrated alongside non-Microsoft tools (Check Point, Cisco, Netskope).
“Standing up a full SOC from scratch is a once-in-an-airport opportunity and Embee Software made sure we got it right the first time. From day one, we had unified visibility, automated response, and a security architecture built to scale.”
— Head of Information Security, leading Indian international airport
Results & Impact
| Metric | Before → After / Outcome |
| Mean time to detect (MTTD) | No automated detection → under 15 minutes |
| Mean time to respond (MTTR) | Manual & ad hoc → ~2 hours |
| Identities & endpoints monitored | 400+ identities and 600+ endpoints |
| Daily log ingestion | ~30 GB/day across 11 sources |
| Analytic rules deployed | 137 total — 108 built-in + 29 custom KQL |
| Alert noise reduced (correlation + Fusion ML) | ~60% fewer low-value alerts |
| Manual SOC effort reduced | ~50% |
| MITRE ATT&CK coverage | Mapped across all 14 enterprise tactics |
| Risky-session containment | Automated within minutes via SOAR playbook |
| Time to first measurable value | 3 months post go-live |
How the airport operates differently now:
- Single-pane-of-glass visibility across all users, access, activity, and data
- Cross-product alert correlation revealing full attack chains for the first time
- Identity-first threat detection that catches account compromise early
- Automated incident response through SOAR, reducing manual SOC dependency
- Lower MTTD and MTTR with continuous monitoring of a distributed field workforce
- Zero Trust enforcement continuously monitored across identity and access
- MITRE ATT&CK coverage visibility showing defensive gaps and strengths
- Audit-ready incident lifecycle via ServiceNow integration
- Eliminated blind spots from siloed monitoring; data-driven decisions replace gut-feel calls
The AI & Automation Angle
The build is intelligence-led, not just rules-led:
- ML behaviour analytics for anomalous SSH/RDP and sign-in detection
- UEBA baselining of users, hosts, and IPs with deviation alerting
- Fusion ML correlating low-fidelity signals into high-confidence incidents
- SOAR-driven containment, including auto-revoke of risky sessions
- Security Copilot-ready — positioning the airport for AI-driven investigations as the next step
Why the Airport Chose Embee Software
- POC-first approach that de-risked the decision before full commitment
- 29 custom KQL rules co-created with the airport’s security team — tailored, not out-of-the-box
- End-to-end delivery under one roof — SIEM + SOAR + UEBA + dashboards + ITSM + hybrid integration
- 5 Microsoft Solution Partner designations and 11 Advanced Specializations (including Threat Protection), backed by Embee Software’s standing as a Microsoft Frontier Partner
- A track record of 95% customer retention across 2,500+ customers
- An agile, relationship-driven team versus process-heavy large SIs
Build Your Cyber Defense Centre with Embee Software
Whether you are securing a greenfield site or consolidating a sprawling estate, the pattern is the same: unified visibility, correlated detection, and automated response on one platform. Embee Software designs and runs enterprise SIEM and SOAR environments on Microsoft Sentinel, backed by managed security services from our Cyber Defense Centre, and extends that protection across identity and access, endpoints, cloud workloads, and Zero Trust architecture.
As a Microsoft Frontier Partner with 17 Advanced Specializations, including Threat Protection, Cloud Security, and Identity and Access Management, we bring the engineering depth to design detections around your business, not around a template. Explore our full cybersecurity portfolio or read more customer success stories.
Ready to see where your blind spots are? Talk to our security experts for a no-obligation assessment of your current detection and response posture.















































