Use Cases

What ARIA Monitors

ARIA collects telemetry across email, identity, endpoints, and cloud — triaging alerts automatically and surfacing confirmed findings to a security engineer for review.

Email Security

ARIA receives phishing and BEC alerts from Google Workspace Alert Center and investigates each one — checking sender reputation, link destinations, and account context — before surfacing confirmed threats.

Gmail Alert Center Phishing BEC

Identity & Access

ARIA monitors Google Workspace admin events to detect MFA gaps, unexpected admin privilege changes, suspicious sign-in patterns, and third-party OAuth grants that expand beyond their stated scope.

MFA Status Admin Roles Sign-in History OAuth Grants

Endpoint Detection

Wazuh agents on Windows and Linux endpoints feed Sysmon process telemetry into ARIA. A YARA signature library scans files weekly. ARIA detects ransomware precursors, credential dumping, and lateral movement before they complete.

Wazuh Sysmon YARA Windows / Linux

Cloud Activity

ARIA ingests Google Workspace admin audit logs, Drive sharing events, and token lifecycle changes — detecting mass file exports, permission escalations, and OAuth token anomalies that the Admin Console surfaces but doesn't investigate.

Google Workspace Drive Token Lifecycle M365 Available

Detection Engineering

ARIA tracks which rules consistently fire on legitimate activity in a tenant, extracts the common field patterns across those cases, and proposes a tuning change — with the supporting evidence attached. A security engineer reviews each proposal and approves or rejects it. Nothing is applied automatically.

Rule Tuning Suppression Proposals Human Approval Evidence-Backed

How ARIA Handles an Alert

Every alert that enters ARIA goes through the same sequence — regardless of source. There is no manual queue for initial triage.

01 — Ingest
Telemetry arrives
Wazuh agents, Google Workspace Alert Center, and cloud API pollers feed events continuously into ARIA's pipeline. Duplicate and known-benign events are filtered before reaching the triage stage.
02 — Triage
ARIA investigates
ARIA pulls context — neighboring events, historical behavior for the account or host, threat intelligence lookups — and produces a verdict: benign, suspicious, or malicious. Benign findings close automatically with a recorded rationale.
03 — Escalation
Security engineer reviews confirmed threats
Suspicious or malicious findings escalate to a security engineer, who reviews ARIA's evidence and approves any containment action. No action runs without that approval — ARIA proposes, the engineer decides.