Graph Neural Networks

Attacks move through relationships that single events do not show.

ARRTECH SIEM and AI Detection · Updated Sep 24, 2026

What do relationships reveal that events hide?

A multi-step attack is a path across users, hosts and applications. ARRTECH SIEM and Cyberdroid AI Detection model those relationships, so the path is visible, not only the steps.

See the method

Method

The SIEM’s AI module runs on an in-memory graph database, so events are analyzed with the relationships around them.

Machine learning, deep learning and graph neural network models run on the graph to find anomalies and multi-step attack patterns.

Threats appear as filterable neighborhoods on the graph, so an analyst sees what surrounds each finding.

A dedicated graph query language lets hunters ask how entities connect, not only what each one logged.

AI Detection adds a relationship-graph anomaly family beside its entity-level behavioral baselines, near-hourly, over what the SIEM holds.

Measures

For AI Detection, precision, false positives, duplicates and latency, measured on your telemetry during a proof of value. We publish the method, not a score.

Limits

A graph relationship does not prove intent, and a score is never a verdict. Attackers can shape activity to look normal on a graph.

Sources

Related

Unsupervised Behavioral Modeling

Method

Evaluations and Benchmarks

Method

Publications

Paper
Contact

Products

Collects, signs and correlates logs from every source, with a risk score per user on a timeline.

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.

Available now
ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.