SIEM · log correlation and detection

A SIEM that correlates logs across 13,000+ rules and blocks threats on its own

Aegis SIEM unifies logs from across your infrastructure, correlates them through 13,000+ detection rules mapped to MITRE ATT&CK and automatically blocks threats — with data in the EU and per-node billing, not by log volume.

First monitoring in about 15 minutes MITRE ATT&CK mapping Data in the EU
What Aegis SIEM does

From raw logs to a confirmed threat —
without manual correlation

The SIEM is the heart of the SOC: it collects events from servers, the network and applications, normalises them and correlates them until it recognises an attack. Aegis SIEM ships with rules and automation already built in — you don't build them from scratch.

Unified logs

Linux, Windows and macOS, web servers, databases, firewalls and cPanel — all events in one place, normalized and searchable.

Correlation across 13,000+ rules

The SDS engine joins events into attack chains in real time and recognizes patterns that a single tool would miss.

MITRE ATT&CK mapping

Every alert carries an attack-technique label (e.g. brute-force, public application exploit), so triage and reports have context from the first second.

CVE and CISA KEV

Detection of known vulnerabilities prioritized by those actually being exploited (KEV) — not by the alphabet, but by risk.

Auto-block and SOAR

A risky source can be blocked automatically through playbooks (block / notify / case / webhook), without waiting for an on-call analyst.

COVERAGE SCORE

A measurable score of 0–100 (A–F) shows how much your SIEM actually covers and what specifically to fix next.

HOW IT WORKS

The journey of a single event through Aegis SIEM

1
The agent collectsA lightweight agent on each node reads logs and telemetry and sends them over outbound HTTPS traffic on port 443 — without opening any inbound ports.
2
NormalizationDifferent formats (syslog, Windows Event, web-access, cPanel) are reduced to a single schema so they can be correlated with one another.
3
Correlation and MITRE mappingThe SDS engine applies 13,000+ rules, joins related events into an incident and assigns it a MITRE ATT&CK technique.
4
Auto-verificationAegisVerify additionally confirms the finding before escalation, reducing the number of false positives.
5
Response and evidenceThe threat is blocked through a SOAR playbook, a case is opened, and everything remains in the audit trail for later review.
The result: instead of thousands of raw lines, you get a handful of confirmed, contextualized incidents a day — with a clear recommendation on what to do.
Aggregate metrics illustration

What a SIEM runs on

380M+
security logs processed
13.000+
active detection rules
280.000+
automatic threat blocks
19.000+
security cases processed

Aggregated, anonymised and illustratively rounded production metrics from the Aegis network. They do not reveal the identity of any customer or individual system.

COMPARISON

Aegis SIEM vs. a typical global SIEM

Global SIEM tools charge by data volume and require a team to tune them. Aegis is built differently.

CRITERIONAegis SIEMTYPICAL GLOBAL SIEM
Billing modelPer node — predictablePer ingest — grows with your logs
Data location✓ Croatia / EUUS or an "EU region" in the cloud
Detection rules13,000+ built in, mapped to MITREYou build/buy content separately
Auto-block and SOAR✓ IncludedA separate product / license
WAF + UEBA + NDR✓ In the same platform✗ Separate products
Time to first monitoringabout 15 minutesweeks or months of integration

The comparison is general and describes typical differences in approach; specific capabilities depend on the individual product and configuration.

Basics

What a SIEM is and why you need it

SIEM (Security Information and Event Management) is a system that collects security logs from across the whole organization into one place — servers, workstations, network equipment, applications and databases — and analyzes them in real time to detect attacks that a single device can't see on its own.

SIEM is not just a log store

Plain log storage (log management) answers „what happened“ only after an incident. SIEM goes a step further: correlates seemingly unrelated events — e.g. failed logins on one server, suspicious outbound traffic on another and a system file change on a third — and recognizes them as one coordinated attack.

Why MITRE ATT&CK mapping

MITRE ATT&CK is a public framework that classifies attacker tactics and techniques. When a detection rule is mapped to ATT&CK, every alert immediately tells you which which technique the attacker is using and which phase of the attack they're in. This speeds up triage, eases communication within the team and simplifies regulatory reporting.

SIEM as the foundation of NIS2 compliance

For entities under the NIS2 Directive, SIEM is a practical foundation: continuous monitoring, event logging and an audit trail prove that the organization monitors and records security events. Aegis turns these records into NIS2 evidence pack ready for audit.

Who it is for: companies with their own IT that want central oversight, as well as those without a security team who use SIEM through SOC as a service, where Aegis takes over monitoring and triage.
Frequently asked questions

SIEM — frequently asked questions

What is SIEM and how does it work in Aegis? +
SIEM collects logs from the whole infrastructure, normalizes them and correlates them through detection rules to recognize attacks. Aegis does this through 13,000+ active rules mapped to MITRE ATT&CK, with real-time correlation and CVE detection, and can automatically block risky sources.
Is Aegis SIEM billed by log volume? +
No. Billing is by the number of nodes you monitor, not by ingest. You can log as much as you want and the bill stays predictable. We explain the model in detail on the page Pricing.
Where are my logs stored? +
Depending on the chosen model: in your infrastructure (on-prem) or in a managed service in Croatia. Primary data (logs, events, reports) stays in HR/EU.
Do I need my own security team for SIEM? +
Not necessarily. With SOC as a service our team monitors, triages and escalates threats to an agreed SLA (8×5, 12×5 or 24×7).
How long does onboarding take? +
Typically about 15 minutes to first active monitoring. The agent installs in a few minutes per node, and communication uses outbound HTTPS traffic over port 443.
RELATED

Keep exploring the platform

See Aegis SIEM on your own logs

A demo environment with your real events — first monitoring, as a rule, in around 15 minutes, with no obligation. Tell us how many nodes you monitor and we'll propose a configuration.

Odgovaramo isti radni dan · info@aegis.hr