Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

Back to RoutePulse Overview

RoutePulse — Incident Hub with 47 MITRE ATT&CK-Tagged Playbooks

Incident Hub — 47 MITRE ATT&CK-Tagged Playbooks · Agentic AI Response

Every alert that RoutePulse fires is a story, not a row. The Incident Hub gathers correlated events from BGP anomalies, ML detectors, Wazuh SIEM, Suricata IDS, FortiGate, and 39 threat feeds into a single MITRE ATT&CK-tagged dossier — and 47 production playbooks auto-trigger the right response, from Telegram broadcast to BGP blackhole, with full audit trail.

When a playbook fires, ANIE — the Autonomous Network Intelligence Engine — runs a six-layer Claude-powered investigation: context gathering, threat-feed cross-reference, AS reputation lookup, MITRE-technique-match, blackhole gate review, narrative generation. The output is a plain-English incident summary with citations, an enriched 👥 Actors block (Attacker (external) → Your host: X → Y :port PROTO), and a 🎯 Scope tag distinguishing own-network from external IPs. No more “who is the source and who is the target?” Telegram messages.

47
Playbooks
6
AI Investigation Layers
v15
MITRE ATT&CK
WORM
Audit Chain

47 production playbooks live

Each playbook is tied to a specific event_type or composite trigger condition. v4.32.101 additions: cyber-honeypot-hit, port-scan-aggregate, protocol-anomaly-network, IXP-peer-volume-shift, RIB-divergence, ASPA-violation, RPKI-invalid-active, host-reputation-flip, bgp-flap-aggregate, withdraw-storm. Each carries a Suricata SID taxonomy with per-class weighting for severity escalation. Playbook engine lives under /settings/playbooks for operator customization.

Auto-resolution with bulk digest

When an incident class quiets for the configured idle threshold, RoutePulse emits a “Bulk Auto-Resolved” Telegram digest listing every IP cleared, split into Yours: and External: so own-network noise vs DFZ-traffic is obvious at a glance. Operator no longer has to scroll through 200 raw IPs to find the 3 own-network entries.

Composite actor attribution

Every incident embeds role-tagged actor lines based on triggerEvent details: directional attack (src+dst → "Attacker (external) → Your host"), single-host anomaly ("Your host showing the anomaly: X"), one-sided fact (split into own/external label), or volume/composition ("Top contributors (source|destination side)"). Every IP in every actor block is tagged with (yours) for GOLINE prefixes / RFC1918 / loopback / link-local, (external) otherwise.

Key Capabilities

  • 47 MITRE ATT&CK Enterprise v15-tagged playbooks live in production with auto-trigger on event_type + composite conditions
  • Six-layer Claude-powered investigation engine (ANIE): context, threat-feed, AS-reputation, MITRE-match, blackhole gate, narrative
  • Correlated event ingestion from BGP anomalies, 18 ML detectors, Wazuh SIEM, Suricata IDS, FortiGate, 39 threat feeds, AbuseIPDB, Shodan
  • WORM audit chain (immutable Postgres + SHA-256 hash chaining) for every incident creation / escalation / resolution / playbook fire
  • Auto-resolution Telegram digest split by own-network vs external IPs (own-IP classifier: GOLINE prefixes, RFC1918, loopback, link-local)
  • Composite actor attribution with (yours) / (external) tags on every IP in every actor block
  • Aggregate-anomaly Actors fallback: explicit Aggregate-level anomaly line when no fromIp/toIp/subjectIp can be attributed
  • Top-contributors enrichment via follow-up ClickHouse query on the anomalous protocol over the 60s detection window
  • Per-incident bulk digest (sendIncidentBulkResolved) with humanized event_type names (cyber_threat_ip_active → “Threat IP Active”)
  • Severity rules respecting CRITICAL only for AS202032 and own prefixes 185.54.80.0/22; WARNING for generic DFZ anomalies
  • Configurable notification routing per playbook: Telegram, email, webhook (with rich attack-context payload for downstream SOAR integration)

Engineered and operated by the GOLINE SOC & Network Engineering team.

Explore all RoutePulse features →