Defending the digital backbone of a leading sustainable freight operator
How Progression's SOC as a Service turned 6,141 raw events at a single site into 15 investigable cases — surfacing a sustained credential-attack campaign against privileged accounts before it could escalate.
The highest incident volume in the group, from just two monitored assets
Despite having only two monitored assets, this site's environment absorbed the highest incident volume of any site in the wider group — 6,141 events in a single month — driven by a sustained, targeted credential-attack campaign against its privileged accounts.
- ! A sustained credential-attack campaign targeted the site's Administrator, admin, and default-account privileged accounts.
- ! Attackers attempted logons from dozens of public IPs, including simultaneous successful and failed logons from different countries and cities — a pattern of coordinated, targeted activity.
- ! A potential PowerShell-based malware dropper was also detected on a key virtual machine, raising the risk that credential compromise could translate into a network foothold.
- ! With only a lean, two-asset footprint and a small internal IT team, the site had no realistic way to correlate dozens of simultaneous login anomalies and a malware alert into a coherent picture on its own.
- ! The site needed a managed security partner to cut through the authentication noise and give the internal team a clear, actionable path to contain the threat.
A correlation-first approach that turned noise into a prioritized threat
Progression's SOC treated the flagged virtual machine as the common thread running through the campaign, and prioritized triage accordingly.
- ✓ The PowerShell-based malware dropper alert was treated as the highest-risk finding and prioritized for immediate escalation.
- ✓ Dozens of related login-failure incidents — one cluster alone carrying 92 related events — were correlated and consolidated into a small number of actionable cases.
- ✓ The affected virtual machine was tracked as the common thread across the credential-attack campaign, connecting the dropper alert to the surrounding authentication anomalies.
- ✓ Each consolidated case was delivered with clear findings, so the site's IT team could focus on containment rather than sifting through thousands of raw events.
A clear, prioritized picture — and fast containment
The SOC's triage and escalation gave the site's IT team a clear, prioritized picture of a genuinely serious campaign, and they moved quickly to contain it.
Massive noise reduction
6,141 raw incidents in the month were condensed into 15 investigable cases — all 15 raised were also investigated and closed.
Direct containment action
The team blocked the attacking IPs, requested access from outside India be blocked at the firewall, and stood up a new, separately-managed privileged account.
Critical alert surfaced, not buried
The PowerShell dropper finding was escalated and confirmed with the customer directly, rather than being lost among thousands of routine events.
Enterprise-grade coverage, lean staffing
A small IT team was able to respond to a genuinely serious credential-attack campaign without needing to build and staff a 24x7 SOC of its own.
Highest-risk site, fastest response
Despite running only two monitored assets, the site's exposure was identified and addressed as quickly as larger, more heavily monitored sites in the group.
Worried about what's hiding in your authentication logs?
See how Progression's SOC as a Service can turn a flood of raw security events into a clear, actionable set of cases.
Talk to Our Team Download Case Study