ARIA Alert Lifecycle

How ARIA Detects, Triages, and Responds.

From a suspicious login on a Google Workspace account to a quarantined endpoint — here's every step ARIA takes, in real time.

2.8s
Median triage time
90%
Pipeline accuracy
8
Pipeline stages
Human-gated
escalations require analyst approval
ARIA Alert Lifecycle

The Full Pipeline

An interactive map of every node in the ARIA pipeline. Drag nodes, click ▶ to walk stage-by-stage, or press Escape to see the full flow.

ARIA — Pipeline Arc Map
Stage Breakdown

8 Stages, Zero Gaps

Every alert travels the same path. Every decision is logged. Every stage has a fallback.

01
Ingest

Endpoints (Sysmon/FIM/YARA) and cloud tenants feed Wazuh. The ARIA engine pulls alerts every cycle and a 2-hour dedup guard drops exact duplicates before anything else runs.

02
Bypass

Five git-reviewed rules auto-close known-benign alert classes instantly — zero AI calls, no verifier, nothing queued for triage. Only novel or unrecognised alerts proceed.

03
Log Aggregation

Before any AI sees the alert, ARIA queries the Wazuh indexer for every event within ±1 hour on the same agent (SIEM Neighbor Pull). Google Workspace alerts also get an oauth_client_id lookup from the token table. In parallel, four external intel feeds run: CISA KEV, OTX, VirusTotal, and AbuseIPDB. All results merge into a context bundle before triage.

04
Triage

The enriched context bundle goes to L2: Claude Haiku 4.5 for standard alerts, Sonnet for severity ≥13. Groq 70B then a local Ollama instance are automatic fallbacks if the Claude API is unavailable. The model returns a structured verdict with reasoning and a claim list.

05
Verify

A deterministic Sufficiency Gate first checks whether the neighbor pull returned enough log context — alerts with thin evidence are held for re-check. If context is sufficient, Groq (never Claude) independently judges the verdict. Cross-family verification is a hard rule. The gate then routes to close, escalate, or hold.

06
Respond

Playbooks fire automatically on MITRE technique match. Destructive steps — process kill, endpoint quarantine, network isolation — require explicit Telegram approval before Wazuh executes them on the affected endpoint.

07
Record

Every verdict, trace, and response action persists in Supabase with row-level security per tenant. Decisions surface on the SOC board in real time and roll into monthly PDF compliance reports via Puppeteer and Resend.

08
Scheduled Ops

Off the per-alert path: nightly threat hunts (03:00), IOC sweeps against CISA KEV and OTX (03:30, no AI), batch re-verification of prior verdicts (02:00), self-healing diagnostics, and on-demand L3 deep-dive investigations.

Get Started

Ready to Get Protected?

Book a free security assessment. We'll review your current posture, identify gaps, and show you exactly how ARIA would protect your organisation.