ARIA monitors every endpoint, cloud tenant, and inbox — triages alerts with AI, verifies with a cross-family model, and closes threats in seconds. No ticket queues.
Wazuh agents on Windows and macOS endpoints, native GWS Alert Center, Microsoft 365 Defender stream — all decoded into a single normalized event schema with MITRE ATT&CK tagging from the sensor.
L2 routes by alert severity — Haiku for volume, Sonnet for critical paths. If primary fails, Groq or local Ollama picks up without dropping the alert. A cross-family verifier from a different model family validates every verdict before any action fires.
Known-benign process signatures skip AI entirely via hot-loaded bypass rules — eliminating FP veto loops. An early dedup gate kills duplicate triages before spend. The escalation verifier checks every human-escalation claim before paging.
Playbook engine maps verdicts to response actions — isolate host, revoke token, block IP. A Telegram approval gate gives analysts final say before execution. Active response fires via Wazuh AR directly on the endpoint.
A scheduled hunt agent runs nightly deterministic library sweeps with YARA rules across both endpoints. An IOC sweep pulls OTX and CISA KEV feeds at 03:30 daily. Findings feed back into the enrichment layer for future triage context.
Every alert carries enrichment_coverage and l2_trace fields — you can see exactly what context the model had, which tools it called, and why it decided. The SOC board shows live verdicts, governance flags, and hunt drafts for analyst review.
Deploying ARIA takes days, not months. Talk to us about your environment.