An interactive map of every node in the ARIA pipeline. Drag nodes, click ▶ to walk stage-by-stage, or press Escape to see the full flow.
ARIA — Pipeline Arc Map
Stage Breakdown
8 Stages, Zero Gaps
Every alert travels the same path. Every decision is logged. Every stage has a fallback.
01
Ingest
Endpoints (Sysmon/FIM/YARA) and cloud tenants feed Wazuh. The ARIA engine pulls alerts every cycle and a 2-hour dedup guard drops exact duplicates before anything else runs.
02
Bypass
Five git-reviewed rules auto-close known-benign alert classes instantly — zero AI calls, no verifier, nothing queued for triage. Only novel or unrecognised alerts proceed.
03
Log Aggregation
Before any AI sees the alert, ARIA queries the Wazuh indexer for every event within ±1 hour on the same agent (SIEM Neighbor Pull). Google Workspace alerts also get an oauth_client_id lookup from the token table. In parallel, four external intel feeds run: CISA KEV, OTX, VirusTotal, and AbuseIPDB. All results merge into a context bundle before triage.
04
Triage
The enriched context bundle goes to L2: Claude Haiku 4.5 for standard alerts, Sonnet for severity ≥13. Groq 70B then a local Ollama instance are automatic fallbacks if the Claude API is unavailable. The model returns a structured verdict with reasoning and a claim list.
05
Verify
A deterministic Sufficiency Gate first checks whether the neighbor pull returned enough log context — alerts with thin evidence are held for re-check. If context is sufficient, Groq (never Claude) independently judges the verdict. Cross-family verification is a hard rule. The gate then routes to close, escalate, or hold.
06
Respond
Playbooks fire automatically on MITRE technique match. Destructive steps — process kill, endpoint quarantine, network isolation — require explicit Telegram approval before Wazuh executes them on the affected endpoint.
07
Record
Every verdict, trace, and response action persists in Supabase with row-level security per tenant. Decisions surface on the SOC board in real time and roll into monthly PDF compliance reports via Puppeteer and Resend.
08
Scheduled Ops
Off the per-alert path: nightly threat hunts (03:00), IOC sweeps against CISA KEV and OTX (03:30, no AI), batch re-verification of prior verdicts (02:00), self-healing diagnostics, and on-demand L3 deep-dive investigations.
Get Started
Ready to Get Protected?
Book a free security assessment. We'll review your current posture, identify gaps, and show you exactly how ARIA would protect your organisation.