Operating modes
You stay in control.
ThreatClaw adapts to your level of trust.
Sentinel Mode
ObservationThreatClaw detects, correlates and notifies you. You handle the corrections.
Autonomy
Hybrid Mode
Semi-autonomousThreatClaw detects, correlates, decides and proposes. You keep control to authorize each action.
Autonomy
Autonomous Mode
Fully autonomousThreatClaw detects, correlates, decides and acts. You are notified after each action with a full report.
Autonomy
Architecture
How it works
3 components. A 5-minute cycle. 24/7.
1
ThreatClaw Engine
Orchestrator- ›Autonomous cycle every 5 minutes
- ›Collects findings, Sigma alerts, logs
- ›Correlation in STIX 2.1 graph
- ›26 automatic CTI enrichments
Rust · 24h/24
2
ThreatClaw AI
5 AI levels- ›L0 Conversational, natural language interaction
- ›L1 Triage, fast local classification
- ›L2 Forensic, deep analysis
- ›L2.5 Instruct, auto MITRE playbooks
- ›L3 Cloud, anonymized, optional
Sovereign AI
3
Behavioral detection
Machine Learning- ›Network baseline over 14 days
- ›DNS anomaly detection (DGA)
- ›Behavioral scoring per asset
- ›Signature-independent
ThreatClaw ML Engine
Full stack
Rust
Secure core
Python
ML & detection
Next.js
Dashboard
PostgreSQL
Data & audit
Graph STIX 2.1
Native graph
All open source, all auditable.