Cyberdroid AI Detection

Available now to select organizations

Behavioral detection on your SIEM

Built by ARRTECH AI researchers working alongside SOC practitioners: methods from time-series, sequence, neural and graph analysis, engineered to be inspected and measured on your own telemetry before they go live.

Cyberdroid Neural Engine: nine analytics families

How it works

Cyberdroid AI Detection baselines every user, host and application against its own history and its neighbors, across identity, network, DNS, process and firewall telemetry. Every finding arrives with the evidence behind it, so you read behavior instead of another score. Schedule a meeting and we will walk you through the workflow.

Cyberdroid AI Detection, relationship graph

Atlas workspace — the relationships around every user, host and application, across one hour of one estate.

Cyberdroid AI DetectionAdvantages

Behavior is assessed without reference to a known signature.

Five analytic families run against every entity: time-series baselines with change detection, sequence models covering rare authentication transitions and parent–child process novelty, a UEBA autoencoder with persisted model state, relationship-graph anomalies, and known-threat and intelligence detection across DNS, Sysmon, firewall and Windows events. Findings from all five correlate into a single attack chain with MITRE tactic and technique context.

Every entity is measured against its own history and against its peers.

Users, hosts and applications are baselined on their own activity over time and against comparable entities in the organization. Relationship analysis extends that to the systems an entity normally reaches and the accounts it operates alongside, so a change in an entity’s surroundings is detectable even where each individual action is permitted.

Every finding carries the values that produced it.

ML findings show the observed value, the baseline it departed from, the score and the threshold crossed, alongside an ordered evidence timeline, process lineage and corroborating findings. Threat-intelligence matches carry feed provenance, age and trust, so the weight an indicator deserves is visible. Selected-threat reports export as Markdown into the case-management process.

The condition of the data behind each detection is reported with it.

Required-field completeness, field types and schema changes are checked as data is ingested, and the Runtime workspace reports source availability and processing diagnostics. An absent or degraded source is therefore distinguishable from an absence of suspicious activity.

New detectors are evaluated on customer data before they reach production.

The catalog holds 21 ML detectors, each explicitly disabled, in shadow or in production, with shadow findings carried on a separate channel. Replay tooling measures detector-scoped precision, recall, stability and volume, and promotion and rollback decisions are recorded. Configurable hourly caps route overflow to shadow rather than into the production stream.

Performance is measured against the incumbent before purchase.

A proof of value runs side by side with existing detection on agreed labeled replay scenarios and at least one representative business week of telemetry. Scoring covers detection overlap and gaps, time to a defensible disposition, evidence completeness, precision and duplicate rate, and event-to-finding latency including the hourly wait. The scorecard is agreed before the evaluation begins.

Requirements

ARRTECH SIEM, or a third-party SIEM with a supported export format. CPUs in your environment, no GPU. Sizing guidance on request.

Limits

Detection analyzes each hour after it closes, so it is not a real-time control. It does not block or change anything in the estate, and a risk score is a prioritization aid, not a verdict.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.