The pipeline
Every event follows exactly the same fully decoupled path: no layer calls the next one directly, everything flows through a message bus. This architecture guarantees three things at once, resilience (an isolated failure doesn't bring down the chain), end-to-end traceability (every decision links back to its source event), and controlled latency around 150 ms at the 99th percentile.
The principle
Three promises, kept in a continuous loop, machine by machine, with no day off. It is this sequence, detect, then understand, then act, that separates genuine autonomous cybersecurity from just another alerting tool.
Signatures only catch what's already known. BALLA learns each endpoint's normal, programs, hours, networks, sequences, and flags the slightest deviation, including the targeted, never-seen attacks that do the most damage.
An anomaly score is not a decision. Every threat is cross-referenced with CVE, MITRE ATT&CK and malware intelligence, then explained in plain language. From score to verdict.
Understanding without acting is arriving too late. BALLA blocks, isolates, kills or quarantines in a fraction of a second, faster than any human team, with human sign-off on the calls that matter.
The pipeline
Every event follows exactly the same fully decoupled path: no layer calls the next one directly, everything flows through a message bus. This architecture guarantees three things at once, resilience (an isolated failure doesn't bring down the chain), end-to-end traceability (every decision links back to its source event), and controlled latency around 150 ms at the 99th percentile.
A lightweight agent watches 28+ event families on each endpoint, cryptographically signed, and buffers locally, encrypted, if the network drops.
A decoupled Apache Kafka bus moves events resiliently, tens of thousands per second, keeping every machine's events in order.
The BALLA brain tells normal from abnormal without knowing the threat in advance, catching real attacks without drowning teams in false alarms.
Every alert is qualified by threat intelligence: CVE, malware family, MITRE ATT&CK technique, reputation, cross-machine correlation. A score becomes a diagnosis.
The decision becomes a signed action (Ed25519), reversible and fully audited, with human sign-off for the most sensitive calls.