Disconnected Environments

Collection, correlation and detection run inside your network.

ARRTECH SIEM, Cyberdroid AI Detection and ARRTECH SOAR

A defense program, a plant, a utility or a ship cannot send its logs to a cloud service, and often cannot receive anything from one. Most security tools assume both directions work. Trend Micro’s own documentation lists behavior monitoring and predictive machine learning among the features that stop working when an agent has no internet access.

Isolation

The NIST glossary, citing CNSSI 4009-2022, describes the boundary this way: two systems are not physically connected, any logical connection is not automated, and data crosses only by hand, under human control. Defense programs, plants, utilities, ships and government enclaves run this way. Three needs remain on the inside.

Updates

Parsers, rules and threat intelligence cannot download. Each update crosses the boundary as a file that someone carries in.

Links

Ships, remote plants and tactical kits lose their connection to the central site, then regain it hours or days later.

Evidence

An auditor or program office still asks for a record that nobody inside the site could have edited.

Collection

A cloud-hosted SIEM needs a route out, and every remote site needs a link to it that stays up. A disconnected site has neither.

ARRTECH SIEM runs on your servers, on Debian, Ubuntu or Red Hat Linux. Processing, search, correlation, reporting and management run on separate servers with load balancing and high availability, and analysts use the console as a web page over HTTPS. The agent buffers logs while the server is unreachable and forwards them, compressed and encrypted, when the link returns. A source that stays silent past a set period raises an alert.

Parsers, rules, reports and queries ship as Store packages installed from the console, and more than 500 log types parse out of the box.

Detection

Behavioral analytics usually run where the vendor’s models run. Without a route to those models, only static rules remain, and a rule has nothing to match when an attacker uses valid access.

Cyberdroid AI Detection installs beside ARRTECH SIEM and reads its export from a read-only network share. It runs on CPUs, with no GPU, and its models are served inside your environment. It measures each user, host and application against its own history across identity, network, DNS, process and firewall telemetry.

Each of its 21 detectors runs in shadow on your own telemetry before it may raise a finding. Inference stays local by default, and any external fallback is a policy your team sets and can see.

Response

Disabling an account or isolating a host on a site that runs a plant or a ship is an operational decision, and it belongs to people. Detection never blocks or changes anything, and a score is a prioritization aid, not a verdict. A person approves, and ARRTECH SOAR runs the playbook, with every decision recorded. The console’s audit log records every login, search and configuration change.

Record

Later, an auditor, a regulator or a program office asks what happened. A log that the site’s own administrators could have edited proves little.

ARRTECH SIEM hashes every log write and signs it with the SIEM certificate. Each signature file records the previous file’s hash, forming a chain. Any source exports with its signatures, the certificate and a standalone verification tool, so a third party can check the record without reaching ARRTECH or the SIEM.

Limits

What the suite does not do on a disconnected site.

Transfer

Nothing crosses the boundary on its own. Your team carries packages and intelligence in, under your own transfer procedure.

Timing

Cyberdroid AI Detection reads the SIEM export read-only and reports near-hourly. It never blocks or changes anything.

Timestamps

Daily timestamping of signature files uses a qualified timestamp authority, which needs a route to that authority.

Evaluation

A proof of value runs on your own servers, inside your network, beside your existing controls, on at least one representative week of your telemetry. Buffering across a dropped link, package installation, detection precision and verification of the signed record are scored against criteria agreed before it begins.

Sources

NIST CSRC Glossary, air gap, from CNSSI 4009-2022Trend Micro, Configure agents that have no internet access

Products

ARRTECH SIEM

Collects, signs and correlates logs on your own servers, and buffers them at any site whose link drops.

Cyberdroid AI Detection

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.

Available now
ARRTECH SOAR

Runs incident playbooks through API integrations, with a human decision built into the flow.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.