Wazuh is a powerful detection platform. Its output — thousands of events per day — requires triage that rules alone cannot deliver. ARIA adds an AI layer: deterministic enrichment, LLM investigation, and independent verification above Wazuh's detection engine.
Wazuh generates events from endpoint agents, log analysis, file integrity monitoring, vulnerability detection, and cloud security modules. Its MITRE ATT&CK rule coverage is extensive, and its output includes technique and tactic mappings that most commercial SIEMs charge separately for. For breadth of detection, Wazuh is difficult to match at any price.
What Wazuh does not do is triage. Wazuh generates an alert when a rule fires. It cannot assess whether this specific alert, in the context of this specific environment, with this specific user history, is worth a security engineer's attention — or whether it is the fortieth instance of a known false positive that should have been suppressed three months ago. That decision requires context that Wazuh does not hold.
In practice, a self-managed Wazuh deployment without a triage layer produces too many alerts to review. Engineers either become desensitized to the volume and miss real threats in the noise, or they spend most of their time manually triaging events that are clearly benign. Neither outcome is acceptable. ARIA's role is to make Wazuh's detection output actionable.
ARIA sits above Wazuh's detection layer. When a Wazuh event arrives, a deterministic enrichment stage runs first: the MITRE technique is preserved from the sensor's tag, threat intelligence lookups run against configured feeds, alert history for the involved entity is queried, and — for cloud events — identity context is collected. The enrichment stage is not AI; it is structured queries with deterministic outputs.
The enriched alert then goes to an LLM for triage. The model produces a structured verdict where each stated claim cites the enrichment data that supports it. The verdict is then verified by a second model from a different vendor. If the two models agree and the evidence is sufficient, the alert routes automatically — benign alerts close with their trace preserved; threat alerts escalate. If there is any dispute or evidence gap, the alert goes to a security engineer.
Deterministic bypass rules run before the AI stage for known-benign patterns — specific process-signature combinations that reliably produce false positives. These are narrow, explicitly maintained rules, not machine-learned classifiers. They close a subset of alerts without any AI invocation, reducing the load on the triage pipeline for the most predictable noise.
This page is the hub for ARIA's Wazuh + AI cluster. The sub-pages cover specific aspects of how ARIA integrates AI with Wazuh:
Book a free assessment to see how the pipeline handles your actual alert environment.
Book Free Assessment