When ARIA confirms a threat, a real analyst reviews the evidence before any containment action fires. Automated speed, human judgment — not fully automated playbooks that can isolate the wrong machine.
Automation can contain a real attacker in seconds — or isolate your CEO's laptop because a patch updated a hash. Fully automated containment in a business environment without human review creates real operational risk. Isolating the wrong endpoint takes a revenue-generating employee offline. Disabling the wrong account locks out someone on a client call. Blocking a legitimate IP address breaks an integration your business depends on.
These are not hypothetical concerns. They happen to organizations that deploy automated response tools without human oversight gates, and the disruption they cause can equal or exceed the disruption of the original incident.
ARIA uses automation for speed of detection and speed of execution once a decision is made — but containment decisions require human judgment. That is not security theater. It is the difference between appropriate response and creating a second incident while trying to stop the first one.
Incident response at ARIA is a five-stage sequence from detection to documentation. Automation handles the first two stages — detection and triage. Human judgment governs the containment decision. Automation then executes that decision at machine speed.
ARIA's monitoring layer detects the behavioral indicator — process injection attempt, credential dump activity, anomalous admin privilege escalation, ransomware precursor behavior (shadow copy deletion, rapid file encryption, backup tampering). The raw alert arrives from the Wazuh monitoring stack with full context: agent identity, timestamp, event chain.
ARIA's triage pipeline enriches the alert with temporal neighbor context (all events from the same agent in the ±1 hour window), OSINT threat intelligence (CISA KEV, OTX, VirusTotal, AbuseIPDB), and behavioral baseline analysis. The AI model produces a structured verdict — suspicious or malicious — with a reasoning narrative and the specific events driving the conclusion. A cross-family verifier model reviews the verdict before escalation routes to a human.
A SOC analyst receives the full triage report via secure notification: the alert details, the AI verdict and reasoning, the neighbor event chain, and the OSINT enrichment results. The analyst reviews the evidence and makes the containment decision. For confirmed malicious activity, the analyst approves the specific containment playbook to execute. If the threat appears to involve a critical business system where containment would cause significant operational disruption, the analyst escalates to the client for input before acting. No containment fires without analyst approval.
Once the analyst approves, the containment playbook executes via Wazuh active response. Actions run in seconds — endpoint isolation, account suspension, firewall rule deployment. The speed advantage of automation applies at the execution stage, after the human judgment that prevents misapplication.
Full written incident report within 24 hours of containment completion. The report covers: what was detected and when, the complete event timeline from first indicator to containment, the MITRE ATT&CK technique mapping, what containment actions were taken, which systems were affected and which were not, and recommended remediation steps. Evidence package generated for insurance claims and regulatory notifications.
ARIA's active response playbooks cover three primary containment categories. All require analyst approval before execution.
The Wazuh agent cuts the endpoint's network access — blocking all traffic except the agent's own management channel — while maintaining ARIA's visibility into the isolated machine. The endpoint remains visible and manageable from the SOC without being able to communicate laterally or reach the internet.
Active Directory or Azure AD account suspension, executed via the Wazuh active response or direct API call to the identity provider. The account is suspended — not deleted — preserving audit trail and allowing re-enablement after investigation. Session tokens are invalidated immediately on execution.
Block outbound connections to a confirmed malicious IP address or domain at the host firewall level (via Wazuh active response) or network firewall level (via API integration on Enterprise plans). Used to sever an active C2 channel or stop data exfiltration in progress to a known-malicious destination.
Containment stops the immediate threat. The work after containment determines whether the incident causes lasting damage and whether the same attack could succeed again.
Within 24 hours of containment completion, ARIA delivers a written incident report by email. The report contains the complete event timeline (first indicator through containment action), the specific techniques detected with MITRE ATT&CK references, the scope assessment (which systems were affected, which were confirmed clean), the containment actions taken and their timestamps, and specific remediation recommendations — what to patch, what to reset, what to review.
The evidence package generated alongside the report includes: raw event logs with timestamps and chain-of-custody integrity, the triage reasoning trace, the analyst review and approval record, and the containment execution log. This package is formatted for use in cyber insurance claims and regulatory notifications — the SEC's 30-day material incident reporting requirement and HIPAA's breach notification rule both require documentation that ARIA's evidence package directly supports.
ARIA also performs a post-incident coverage review: did the incident reveal a monitoring gap? Was the detection rule that caught this indicator the right one, or did the attack vector expose an area where additional detection coverage should be added? Coverage gaps identified during post-incident review are addressed in the next detection ruleset update.
Response time is measured from AI triage completion to analyst acknowledgment — the point at which a human analyst has the case and begins review. Containment execution after approval is not measured by SLA because execution time depends on the containment action approved and the systems involved.
| Plan | Critical Threat Response | Standard Escalation | Non-Critical Alerts |
|---|---|---|---|
| Enterprise | 15 minutes (analyst acknowledgment SLA) | 1 business hour | Next business day summary |
| Professional | Best-effort; on-call escalation for critical | 4 business hours | Next business day summary |
| Starter | 24/7 monitoring; next business day response | Next business day | Weekly digest |
The 15-minute Enterprise SLA applies to confirmed critical threats where AI triage has completed and verdict is malicious. It is measured from escalation routing to analyst acknowledgment. All plans include 24/7 continuous monitoring — the SLA governs human response speed, not monitoring coverage.
Free 30-minute assessment. We'll walk through a real incident scenario and show you the full response chain — from detection to containment to report.
Book Free Assessment View PricingThis is exactly why containment is human-gated. An analyst reviews the full evidence chain before approving any action. If the threat appears to involve a critical business system — a primary production server, a key executive's account, an integration your business depends on — the analyst escalates to the client for input before acting rather than making the containment decision unilaterally. The goal is to stop the attack without creating a different incident. Operational context that the analyst might not have (a planned maintenance window, a system that's currently running a critical process) can change the containment approach. Clients on Enterprise plans have a designated contact for exactly these escalation conversations.
Yes. Wazuh's active response mechanism operates over the agent's management channel, which is maintained independently of the endpoint's general network access. When an endpoint is isolated, its general network traffic is blocked — but the Wazuh agent channel remains open, keeping the endpoint visible and controllable from the SOC. An analyst can execute a containment action on an endpoint in a remote office without being on-site or having VPN access to the local network. The isolation is enforced at the agent level on the endpoint itself, not at the network perimeter.
Written incident reports are delivered by email within 24 hours of containment completion. The report goes to the primary client contact designated during onboarding. For critical incidents on Enterprise plans, the analyst also provides a brief verbal summary within the response SLA window — a quick call to walk through what happened and what was done before the written report is complete. If a regulatory notification timeline is running (HIPAA 60-day breach notification, SEC 30-day material incident reporting), ARIA flags this in the initial incident notification so the client can begin the clock.
Yes. The evidence package generated after a confirmed incident is designed to support both cyber insurance claims and regulatory notifications. It includes: timestamped raw event logs with chain-of-custody documentation, the AI triage reasoning trace, the analyst review and approval record with timestamps, and the containment execution log showing exactly what actions were taken and when. This gives your insurance carrier the documentation they need to process a claim and gives your legal counsel the record they need for breach notification compliance. The package is available within 24 hours of incident closure.
The 15-minute critical response SLA applies to Enterprise plan clients and is measured from the moment AI triage completes and the escalation routes to the on-call analyst queue. The analyst must acknowledge the case — confirm receipt and begin review — within 15 minutes of that routing event. This covers the human-review stage. Containment execution via Wazuh active response typically takes seconds after analyst approval is given. The SLA does not cover the triage pipeline processing time, which is a separate metric (median under 3 seconds for standard alerts; slightly longer for high-severity alerts requiring the full enrichment and cross-verification chain).