Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

Back to RoutePulse Overview

RoutePulse — Unified Threat Intelligence Dashboard

Unified Threat Intelligence Dashboard

SOC teams typically juggle multiple consoles — one for ML detections, another for threat feed matches, a third for SIEM alerts, and yet another for mitigation status. RoutePulse’s Unified Threat Intelligence Dashboard consolidates all of these into a single 5-tab interface, merging ML detections, cyber events, threat feed matches, and active mitigations into one coherent operational view. With 39 built-in threat feeds, 52,000+ indicators in a Bloom filter delivering sub-microsecond lookups, and bidirectional MISP and Wazuh SIEM integration, your SOC gains a comprehensive threat picture without context-switching between tools. Context-aware severity ensures that outbound C2 traffic is immediately flagged as CRITICAL while inbound scanner traffic is appropriately classified as WARNING.

The dashboard’s 5 tabs provide layered operational depth. The Overview tab presents 10 KPI cards, a 24-hour threat timeline, a live threat scoreboard ranked by severity, and a TI hub. The Detection tab visualizes the 3-stage detection pipeline — Stage 1 fast rules executing in under 1ms, Stage 2 statistical analysis using EMA, Z-score, CUSUM, and Shannon entropy in 10-50ms, and Stage 3 AI classification — with event type breakdowns and EMA baselines. The Feeds tab displays an integration strip for MISP (4,894 events, 9.5M attributes from soc.goline.ch) and Wazuh (295 agents), alongside feed status monitoring, indicator search, and top matched hosts. The Events tab provides distribution charts and a live event feed with expandable rows and category-specific detail panels. The Scoring tab delivers a 5-pillar unified threat scoring visualization with per-host gauges and pipeline summaries. Under the hood, 37 named detection rules cover volumetric DDoS, SYN flood, amplification, port scanning, DNS tunneling, slowloris, and more, while temporal decay with 7-day half-life, multi-feed consensus boost, and campaign fingerprinting (5+ IPs from the same ASN/feed in 1 hour) ensure threat scores reflect current reality.

5 Tabs
Unified SOC View
39
Threat Feeds
52K+
Indicators
<1μs
Bloom Filter Lookup
37
Detection Rules

Key Capabilities

  • 5-tab unified SOC dashboard merging ML detections, cyber events, threat feed matches, and mitigations into a single pane of glass
  • Overview tab: 10 KPI cards, 24-hour threat timeline, live threat scoreboard ranked by severity, and TI hub
  • Detection tab: 3-stage pipeline visualization — fast rules under 1ms, statistical analysis (EMA/Z-score/CUSUM/Shannon entropy) in 10-50ms, AI classification
  • Feeds tab: MISP integration (4,894 events, 9.5M attributes) and Wazuh SIEM bidirectional integration (295 agents), feed status monitoring, indicator search
  • Events tab: distribution charts with live event feed, expandable rows, and category-specific detail panels
  • Scoring tab: 5-pillar unified threat scoring visualization with per-host gauges and pipeline summaries
  • 39 built-in threat feeds including Spamhaus DROP/DROPv6/ASN-DROP, Feodo, ThreatFox, URLhaus, FireHOL L1/L2, IPsum, ET Compromised, CISA KEV, and 25+ more
  • 52,000+ threat indicators in Bloom filter with sub-microsecond lookup against every flow
  • 37 named detection rules spanning volumetric DDoS, SYN flood, amplification, port scanning, DNS tunneling, slowloris, and more
  • Temporal decay with 7-day half-life, multi-feed consensus boost, and campaign fingerprinting (5+ IPs from same ASN/feed in 1 hour)
  • Context-aware severity: outbound C2 traffic classified as CRITICAL, inbound scanner traffic as WARNING
  • Bidirectional Wazuh SIEM integration: syslog export to Wazuh plus OpenSearch alert import

Engineered and operated by the GOLINE SOC & Network Engineering team.

Explore all RoutePulse features →
69 / 100 SEO Score