The primary achievement of this architecture is the mechanical grounding of SIEM logs within a Zero-Trust Knowledge Graph (Neo4j). By utilizing OCSF normalization and a LangGraph Swarm, the system compresses the Mean Time To Detect (MTTD) for complex threats from days to sub-minute resolution, algorithmically rejecting over 90% of false-positive noise before human escalation.