ANIE — Autonomous Network Intelligence Engine
SOC teams drown in alerts because every detector hands them rows, not stories. ANIE — the Autonomous Network Intelligence Engine — turns every critical detection into a written forensic report with MITRE ATT&CK citations, evidence trail, and an explicit verdict (ESCALATE / MONITOR / DISMISS). It does this with the analytical depth of a senior threat analyst at €1–3 per day total Claude spend, thanks to the v4.31+ Claude prompt-caching layer that cuts token cost by ~80 % and a 4-layer Threat-Intel Digest Pipeline that dropped daily spend from $282 to single-euro figures.
ANIE runs a 6-layer Claude-powered investigation with two model tiers — Haiku for high-volume enrichment (~2,000 calls/day) and Sonnet 4.6 for deep investigation and threat hunting (~40 investigations + ~96 proactive hunts daily). The operating cadence is operator-friendly: a tri-daily handover at 06 / 14 / 22 UTC ships a written shift summary covering everything that happened in the previous 8 hours, with named incidents, links, and a “what to watch” pre-brief for the incoming shift. Every detection cycle pipes anomalies through ANIE, but a hard budget cap ($15/day ceiling, €1–3 typical) and a deterministic fallback enrichment path mean Claude can be unreachable and the SOC still gets reports.
6-Layer investigation pipeline
Layer 1 — Detection Enrichment: every CRITICAL detection auto-enriched with MITRE ATT&CK technique mapping, kill-chain positioning, impact scoring (0–10), FP/TP classification (~2,000 Haiku calls/day). Layer 2 — Autonomous Investigation: 50-item FIFO queue at 30-second processing, gathers evidence from RIB / ClickHouse / threat feeds / network context, writes forensic narrative with ESCALATE/MONITOR/DISMISS verdict. Layer 3 — Continuous Threat Hunting: proactive hunts every 15 minutes targeting C2 beacons, data exfiltration, port-scan campaigns. Layer 4 — Conviction Gate 8: final Claude review before blackhole inject — sanity-check on operator-relevant impact. Layer 5 — Self-Tuning ML Orchestrator: tunes ML thresholds every 2 h, assesses feed quality every 6 h. Layer 6 — Network Context Memory: persistent learning of peer profiles, known behaviours, suppression patterns — ANIE remembers what it’s seen before.
Tri-daily handover — 06 / 14 / 22 UTC
Three times a day ANIE produces a written shift handover Telegram + email: total incidents this shift, top 5 by severity with named hosts, top external actor ASNs, ongoing investigations carried over to the next shift, and a “what to watch” pre-brief. The format is operator-readable in 30 seconds. Combined with the Daily Digest and Predictive Alerts (24–72 h forecast), the on-call engineer arrives already briefed.
Claude caching v4.31+ — 80 % cost reduction
Every prompt to Claude is structured with stable context blocks (network topology, peer roster, MITRE taxonomy, threat-feed primer) marked as cache_control: ephemeral. Anthropic caches the prefix; only the per-incident delta is billed. v4.31+ rollout dropped daily cost by ~80 %, taking ANIE from “interesting but expensive” to “operational baseline”. Budget cap is hard-enforced: at $15/day the engine falls back to deterministic enrichment (template-based, zero Claude cost) and continues operating.
Key Capabilities
- 6-layer Claude-powered pipeline in
anie-service.ts— Haiku for enrichment, Sonnet 4.6 for investigation + hunting - Layer 1 Detection Enrichment: MITRE ATT&CK mapping, kill-chain positioning, impact 0–10, FP/TP classification (~2,000 calls/day)
- Layer 2 Autonomous Investigation: 50-item FIFO queue at 30 s, ESCALATE/MONITOR/DISMISS verdicts with evidence trail (~40/day)
- Layer 3 Continuous Threat Hunting: every 15 min targeting C2 beacons, exfiltration, port scans (~96 hunts/day)
- Layer 4 Conviction Gate 8: final Claude review on blackhole decisions before SSH inject
- Layer 5 Self-Tuning ML Orchestrator: threshold tuning every 2 h, feed quality every 6 h
- Layer 6 Network Context Memory: peer profiles, known behaviours, suppression patterns — persistent across restarts
- Tri-daily handover at 06 / 14 / 22 UTC: written Telegram + email summary, what-to-watch pre-brief for incoming shift
- Claude prompt-caching v4.31+: stable context marked
cache_control: ephemeral→ ~80 % token cost reduction - Budget enforced at $15/day ceiling, €1–3 typical, deterministic-fallback path if cap reached
- 4-layer Threat-Intel Digest Pipeline: $282/day → €1–3/day (~99 % cost optimisation)
- 13 detection types mapped to MITRE ATT&CK Enterprise v15 for standardised classification
- Evidence gathering across RIB, ClickHouse (1.6B rows), 39 threat feeds, MISP, Wazuh, RouteViews, RIS
- Predictive Alerts: 24–72 h forecast surfaces likely upcoming attack windows from temporal patterns
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →