Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

Back to RoutePulse Overview

RoutePulse — ANIE — Autonomous Network Intelligence Engine

ANIE — Autonomous Network Intelligence Engine

SOC teams drown in alerts because every detector hands them rows, not stories. ANIE — the Autonomous Network Intelligence Engine — turns every critical detection into a written forensic report with MITRE ATT&CK citations, evidence trail, and an explicit verdict (ESCALATE / MONITOR / DISMISS). It does this with the analytical depth of a senior threat analyst at €1–3 per day total Claude spend, thanks to the v4.31+ Claude prompt-caching layer that cuts token cost by ~80 % and a 4-layer Threat-Intel Digest Pipeline that dropped daily spend from $282 to single-euro figures.

ANIE runs a 6-layer Claude-powered investigation with two model tiers — Haiku for high-volume enrichment (~2,000 calls/day) and Sonnet 4.6 for deep investigation and threat hunting (~40 investigations + ~96 proactive hunts daily). The operating cadence is operator-friendly: a tri-daily handover at 06 / 14 / 22 UTC ships a written shift summary covering everything that happened in the previous 8 hours, with named incidents, links, and a “what to watch” pre-brief for the incoming shift. Every detection cycle pipes anomalies through ANIE, but a hard budget cap ($15/day ceiling, €1–3 typical) and a deterministic fallback enrichment path mean Claude can be unreachable and the SOC still gets reports.

6
Investigation Layers
€1–3
Daily Spend
80%
Cache Savings
Daily Handovers

6-Layer investigation pipeline

Layer 1 — Detection Enrichment: every CRITICAL detection auto-enriched with MITRE ATT&CK technique mapping, kill-chain positioning, impact scoring (0–10), FP/TP classification (~2,000 Haiku calls/day). Layer 2 — Autonomous Investigation: 50-item FIFO queue at 30-second processing, gathers evidence from RIB / ClickHouse / threat feeds / network context, writes forensic narrative with ESCALATE/MONITOR/DISMISS verdict. Layer 3 — Continuous Threat Hunting: proactive hunts every 15 minutes targeting C2 beacons, data exfiltration, port-scan campaigns. Layer 4 — Conviction Gate 8: final Claude review before blackhole inject — sanity-check on operator-relevant impact. Layer 5 — Self-Tuning ML Orchestrator: tunes ML thresholds every 2 h, assesses feed quality every 6 h. Layer 6 — Network Context Memory: persistent learning of peer profiles, known behaviours, suppression patterns — ANIE remembers what it’s seen before.

Tri-daily handover — 06 / 14 / 22 UTC

Three times a day ANIE produces a written shift handover Telegram + email: total incidents this shift, top 5 by severity with named hosts, top external actor ASNs, ongoing investigations carried over to the next shift, and a “what to watch” pre-brief. The format is operator-readable in 30 seconds. Combined with the Daily Digest and Predictive Alerts (24–72 h forecast), the on-call engineer arrives already briefed.

Claude caching v4.31+ — 80 % cost reduction

Every prompt to Claude is structured with stable context blocks (network topology, peer roster, MITRE taxonomy, threat-feed primer) marked as cache_control: ephemeral. Anthropic caches the prefix; only the per-incident delta is billed. v4.31+ rollout dropped daily cost by ~80 %, taking ANIE from “interesting but expensive” to “operational baseline”. Budget cap is hard-enforced: at $15/day the engine falls back to deterministic enrichment (template-based, zero Claude cost) and continues operating.

Key Capabilities

  • 6-layer Claude-powered pipeline in anie-service.ts — Haiku for enrichment, Sonnet 4.6 for investigation + hunting
  • Layer 1 Detection Enrichment: MITRE ATT&CK mapping, kill-chain positioning, impact 0–10, FP/TP classification (~2,000 calls/day)
  • Layer 2 Autonomous Investigation: 50-item FIFO queue at 30 s, ESCALATE/MONITOR/DISMISS verdicts with evidence trail (~40/day)
  • Layer 3 Continuous Threat Hunting: every 15 min targeting C2 beacons, exfiltration, port scans (~96 hunts/day)
  • Layer 4 Conviction Gate 8: final Claude review on blackhole decisions before SSH inject
  • Layer 5 Self-Tuning ML Orchestrator: threshold tuning every 2 h, feed quality every 6 h
  • Layer 6 Network Context Memory: peer profiles, known behaviours, suppression patterns — persistent across restarts
  • Tri-daily handover at 06 / 14 / 22 UTC: written Telegram + email summary, what-to-watch pre-brief for incoming shift
  • Claude prompt-caching v4.31+: stable context marked cache_control: ephemeral → ~80 % token cost reduction
  • Budget enforced at $15/day ceiling, €1–3 typical, deterministic-fallback path if cap reached
  • 4-layer Threat-Intel Digest Pipeline: $282/day → €1–3/day (~99 % cost optimisation)
  • 13 detection types mapped to MITRE ATT&CK Enterprise v15 for standardised classification
  • Evidence gathering across RIB, ClickHouse (1.6B rows), 39 threat feeds, MISP, Wazuh, RouteViews, RIS
  • Predictive Alerts: 24–72 h forecast surfaces likely upcoming attack windows from temporal patterns

Engineered and operated by the GOLINE SOC & Network Engineering team.

Explore all RoutePulse features →
75 / 100 SEO Score