Data goes where it should
The ARRTECH SIEM agent holds logs when the server is unreachable and encrypts them in transit. Systems where you cannot install software can be read remotely.
Common log types parse out of the box, and parsers fall back to one another when a format changes. When a source is not yet supported, ARRTECH writes the parser at no charge under an active support contract.
ARRTECH DLP feeds its events to ARRTECH SIEM, and a SIEM alert can open an ARRTECH SOAR case or run an automation. All three products are managed from the same console.
Alerts reach your team where it already works: email, messaging, ticketing, a script or a case. ARRTECH SOAR playbooks reach security tools, systems and web services through their APIs.
ARRTECH SIEM ships with threat-intelligence feeds and takes commercial, open-source and your own internal sources. Searches and rules check activity against them, and feeds refresh on a schedule.
Cyberdroid AI Detection, in the AI layer of the ARRTECH Security Suite, reads ARRTECH SIEM’s export. A third-party SIEM connects through a supported export format. Cyberdroid AI Investigation, in early access, requires AI Detection and reads its findings and SIEM alerts. Neither changes your estate.
Every source in view
Every source shows its status on one page, and a source that goes silent raises an alert.
Network
Network devices, firewalls and flow data connect through standard protocols.
Windows
Windows systems send their event logs and performance data, filtered at the agent so only what matters travels.
Databases
Applications that log to a database are read directly, with no export step.
Files
Log files are read from servers, shares and local disks, including legacy fixed-format files.
Cloud
Cloud and streaming platforms connect through their own APIs.
APIs
Each product has a REST API, and sign-in works with your existing directory.
Products

Runs incident playbooks through API integrations, with a human decision built into the flow.

Behavioral detection on your SIEM, baselined against each user, host and application’s own history.

Read-only investigation of AI Detection findings, with each case written up for a person to decide.

