One unified console — correlated across every plane. Start at the Command Center; the areas below are drill-downs.
⬡ SOC COMMAND CENTER
Unified cross-plane picture — correlated incidents, live posture across IR · VS · UEBA · M365, and one auto/manual response model.
Open →
Areas of the platform
Loading…
INTEGRATION IN PROGRESS
Module
—
This system runs standalone today. It will be surfaced here as a module once integrated — same pattern as Security Ops: a read-only data adapter, its own tab set, and a posture contribution. Planned views:
Paste a reference URL from NIST, SANS, MITRE, CISA, OWASP, or FIRST — or describe a scenario. ARIA will check this deployment’s real agents, optionally pull the reference doc, and draft a playbook tailored to your actual infrastructure.
⊞
Drag & drop a playbook or click to browse
Supports PDF, Markdown (.md), Text (.txt)
Ransomware Incident Response Playbook
IR
Step-by-step containment and recovery guide for ransomware. Covers isolation, evidence preservation, eradication, and full recovery with agent verification.
14 steps · Updated 2026-05-20
3 / 14 completed
Lateral Movement Threat Hunt
HUNT
Hypothesis-driven hunt for lateral movement. Targets T1021, T1075, T1550 — pass-the-hash, PtT, and RDP-based techniques across all active agents.
8 steps · Updated 2026-05-31
Credential Access Hunt — Brute Force
HUNT
Identify brute force campaigns targeting SSH, RDP, and web login endpoints. Correlates source IPs across agents to detect distributed attacks.
6 steps · Updated 2026-06-01
Network Discovery & Asset Inventory Sweep
HUNT
Live host inventory across all active agents — open ports, running processes, persistence checks, and per-agent risk summary.
8 steps · Updated 2026-06-19
Demo Playbook — Network Scan & Triage
HUNT
Short 4-step walkthrough: inventory agents, pull recent alerts, check for known CVEs, summarise findings and recommend next action.
4 steps · Updated 2026-06-19
Critical Alert Escalation Procedure
ESCALATION
Decision framework for escalating a critical alert to senior staff. Includes 3am escalation criteria and communication templates.
5 steps · Updated 2026-04-15
Linux Post-Compromise Forensics
FORENSICS
Memory acquisition, log collection, timeline reconstruction, and persistence mechanism identification for compromised Linux endpoints.
11 steps · Updated 2026-03-28
ISO 27001 Incident Reporting
COMPLIANCE
Required steps for documenting and reporting a security incident under ISO 27001 controls. Covers timeline, evidence packaging, and notification.