Platform Overview

AI SOC — What It Actually Does

ARIA's AI SOC sits above Wazuh's detection layer. Every alert is enriched before AI sees it, triaged with evidence citation requirements, verified by a second model, and routed to the right destination — with a full trace on every single alert.

What an AI SOC Replaces — and What It Doesn't

The phrase "AI SOC" is often used to mean an AI product with a security use case. The more useful framing is narrower: an AI SOC automates the manual triage process — the part where a security analyst reads an alert, looks up the IP, checks whether the file hash is known-bad, pulls recent alerts for that user, and decides whether this is worth investigating further. That process is rule-following and evidence-gathering, which is exactly what AI can do reliably.

What an AI SOC does not replace is judgment on critical incidents: whether to isolate a production server, whether to revoke credentials during business hours, whether a pattern that looks like data exfiltration is actually a legitimate backup job. These decisions have operational consequences that require context only a human has. ARIA's AI SOC handles the triage pipeline; a security engineer handles the escalations.

This distinction matters for setting expectations. An AI SOC reduces the time between alert and disposition for routine events. It does not guarantee that every threat is caught. It makes a security engineer more effective by routing only the alerts that genuinely need human judgment.

Detection Layer — Wazuh

ARIA uses Wazuh as its detection layer. Wazuh generates security events from endpoint agents, log analysis, vulnerability detection, file integrity monitoring, and cloud security modules. ARIA ingests those events and runs them through its triage pipeline.

Wazuh's strength is breadth: it covers the MITRE ATT&CK framework extensively, and its rule set maps most events to specific techniques and tactics. ARIA's pipeline preserves these mappings — the MITRE technique tag on each alert comes from the Wazuh sensor, not from AI inference, which matters for auditability. An AI-inferred MITRE tag is a guess; a sensor-sourced tag is evidence.

Wazuh's limitation in a small-business context is volume and noise. Default Wazuh rules generate many alerts per day in a typical environment, the large majority of which are not actionable. ARIA's triage pipeline is designed to address this: deterministic bypass rules close known-benign patterns before AI is invoked, and the AI triage stage filters the remainder to the subset that warrants human attention.

What the AI Layer Does

Before any alert reaches an LLM, a deterministic enrichment stage runs: threat intelligence lookups, alert history for the involved entity, and — for cloud events — identity context (MFA status, assigned roles, recent login events). The LLM receives a fully enriched alert package, not a raw Wazuh event.

The LLM produces a structured verdict with a specific constraint: each claim must cite the enrichment data that supports it. A verdict claiming "this IP has a poor reputation" must cite the threat intel lookup result. A verdict claiming "this user has no recent login history from this geography" must cite the identity context query result. The structure is enforced at the model output layer — a verdict that makes claims without citations does not pass validation.

The verdict then goes to a second model from a different vendor for independent verification. If the verifier agrees, the alert is routed based on the verdict: benign alerts are auto-closed with the full trace preserved; uncertain alerts are queued for a security engineer; high-confidence threat alerts escalate with the full evidence package. If the verifier disputes the verdict, the alert is held for a security engineer regardless of the triage conclusion.

What Every Alert Carries

Every alert that moves through ARIA's pipeline carries a complete trace: which enrichment sources were queried, what each returned, the triage verdict with its citations, the verifier's assessment, and the final routing decision. This trace is preserved whether the alert is auto-closed or escalated.

This matters for two reasons. First, for an alert that escalates to a human, the trace is the starting point for investigation — the engineer does not need to re-run the enrichment queries. Second, for auto-closed alerts, the trace is the evidence that the closure was justified. If a question arises later about why a particular alert was closed without escalation, the trace shows exactly what evidence the decision rested on.

What ARIA's AI SOC monitors:

  • Endpoint events via Wazuh (Windows, macOS, Linux)
  • Cloud audit logs (Microsoft 365, Azure AD, Google Workspace)
  • File integrity events and configuration changes
  • Vulnerability findings per host
  • Email threat indicators
  • Network and DNS telemetry
Common Questions
Does an AI SOC replace the need for a security engineer?
No — it reduces the load on one. Routine, classifiable alerts are handled automatically. Genuinely ambiguous situations, confirmed threats, and any alert where the verifier and triage model disagree go to a security engineer. The AI SOC is a force multiplier, not a replacement for human judgment on the cases that need it.
What alert sources does ARIA's AI SOC monitor?
ARIA ingests alerts from Wazuh (endpoint events across Windows, macOS, and Linux; log analysis; file integrity; vulnerability detection), Microsoft 365 and Azure AD, Google Workspace, and email threat indicators. The specific sources active for a given client depend on the plan and the integrations configured during onboarding.
How does an AI SOC differ from a traditional SIEM?
A SIEM collects and correlates logs, generates alerts, and requires analysts to triage the output. The alert disposition — closed, escalated, investigated — is a human step. ARIA's AI SOC adds an automated triage layer on top of Wazuh's SIEM functionality: enrichment, LLM verdict, verification, and routing happen without human intervention for the large share of alerts that are unambiguous. The SIEM is still there; the AI layer handles the triage step that would otherwise require analyst time.
What happens when the AI SOC detects a critical threat?
High-confidence threat alerts escalate with the full enrichment package: the MITRE technique, threat intel results, identity context, the LLM verdict with its citations, and the verifier's confirmation. The security engineer receives enough context to assess and respond without needing to re-gather evidence. Response actions — isolating a device, revoking credentials — require the engineer's explicit approval before executing.
Can the AI SOC handle a cloud-only environment with no on-premises endpoints?
Yes. ARIA can operate in cloud-only configurations monitoring Microsoft 365, Azure AD, and Google Workspace without endpoint agents. The detection coverage for cloud environments focuses on identity events, application access patterns, email threats, and administrative actions rather than endpoint process telemetry.

See ARIA in Practice

Book a free assessment to see how the pipeline handles your actual alert environment.

Book Free Assessment
No contract. No setup fee. Cancel anytime.

See Plans

Starting at $799/month. No long-term contracts required.

View Pricing