Skip to content
CYBER THREAT INTELLIGENCE

Drawing on years of accumulated cyber threat data and proprietary AI models, CTX connects files, IPs, domains, and URLs to attackers, campaigns, and TTPs. Its LLM-based investigation environment selects the analysis tools and threat intelligence needed for each query, supporting threat analysis, explanation, summarization, and reporting in a single flow.

Large-scale Cyber Threat DataProprietary AI-based Threat AnalysisAttacker, Campaign & TTP CorrelationLLM-Assisted Investigation & Analysis
OVERVIEW

CTX isn’t CTI with AI added. It’s AI-native CTI built on years of threat research.

CTX’s AI wasn’t built overnight. Here’s what it’s built on.

LONG-TERM THREAT RESEARCH

Years of Threat Research

SANDS Lab has collected and analyzed malware and cyber threat data for years. CTX’s AI is built on that foundation.

APT ANALYSIS EXPERTISE

Expertise in Interpreting Attack Context

Years of experience connecting individual indicators to attack groups, campaigns, and TTPs—not simply flagging them—form the basis of CTX’s AI analysis.

OPERATIONAL INTELLIGENCE

Threat Intelligence Proven in Real-World Operations

From malwares.com to CTX, our threat intelligence has been developed and validated through real-world operations.

CTX EVOLUTION

From malware analysis to AI-native CTI that interprets attack context.

CTX’s foundation wasn’t built overnight. SANDS Lab has collected and analyzed malware and cyber threat data for years, continuously building on the data and analytical capabilities accumulated along the way—from IoC-centric intelligence to attacker-centric CTI and now to an AI-native investigation environment.

01MALWARE INTELLIGENCE

Collecting and Analyzing Malware and IoCs

The foundation began with a public intelligence service that collected and analyzed large-scale malware and threat data—including files, IPs, and domains—and provided maliciousness status and related information.

02CYBER THREAT INTELLIGENCE

Connecting IoCs to Attacker and Campaign Context

The intelligence evolved into CTI that connects individual threat indicators to attack groups, campaigns, target countries and industries, and MITRE ATT&CK TTPs to analyze the purpose and flow of APT attacks.

03AI-NATIVE CTI

AI Supports the Investigation Workflow

CTX combines proprietary AI detection models and threat data with LLM-based intelligent orchestration to create an investigation environment that selects the analysis tools and data required for each question and synthesizes the results.

DATA FOUNDATION

AI-Native CTI starts with threat data at scale.

An LLM alone can't create threat intelligence. CTX's AI runs on malware, IoCs, attack groups, campaigns, attack techniques, and related information that SANDS Lab has directly collected and analyzed over a long period. It's built on tens of billions of records of threat and profiling data.

MALWARE

Malware data

Analyzes malicious/benign files, malware families, file structure, similarity, and behavior.

IOC

IoC data

Collects and analyzes threat indicator data — files, IPs, domains, URLs, and more.

ATTACK CONTEXT

Attack context data

Connects threat actors, campaigns, target countries, target industries, and threat types.

TTP

Attack technique data

Includes MITRE ATT&CK, attack technique, and behavior information.

RELATION

Related information data

Connects associated files, communicating IPs, domains, URLs, C2, and campaign relations.

AI-NATIVE CTI

Not CTI with an LLM bolted on. AI is built into the analysis process.

CTX's AI isn't limited to generating answers in a chat window. It applies AI across multiple stages of CTI — from threat detection to correlation analysis, tool selection, and result synthesis and reporting.

01Threat Intake02CTX AI AnalysisAI03Analysis Output04UsageFileJEXE · PDF · APKIPExternal threatindicatorDomainExternal threatindicatorURLExternal threatindicatorLog DataEvent records1JudgmentAssess the situation andidentify analysistargets2Plan the AnalysisSelect the analysismethods and tools needed3Run AnalysisExecute analysis toolsper the planIn-depth file analysisLog/event correlationThreat intelligenceanalysisBehavior/TTP analysis4Synthesize ResultsCombine tool outputs intoa verdict and reportVerdictMalicious verdictand risk levelAnalysis ReportDetailed findingsby sectionEvidenceYARA · MITREATT&CK and othersupportingevidenceResponse GuidanceSuggestsblocking/isolationprioritiesFinal ReviewSupports analystjudgment anddecisionsFollow-up QueriesConfirm detailsthroughconversationDownload ResultsSave analysisresults andreportsDeep-DiveExtend into deeperanalysisAPI IntegrationLink results toexternal systems
AI DETECTION

Identifies threats.

Our own AI models analyze the maliciousness and threat characteristics of files, IPs, domains, and more.

AI ATTRIBUTION

Connects the actor and technique behind an attack.

Identifies attack context — attack groups and MITRE ATT&CK TTPs — based on analyzed threat information.

AI ORCHESTRATION

AI builds the analysis sequence a question needs.

The LLM understands the user's question, selects the analysis tools and data-lookup order needed, and synthesizes the results.

AI EXPLANATION

Explains analysis results in a way people can understand.

Summarizes complex analysis results and threat intelligence in natural language, letting the investigation continue through follow-up questions.

AI REPORTING

Organizes investigation results into a reportable form.

Summarizes the analysis process results, and is being advanced to generate them as LLM-based reports.

THREAT CONTEXT

Expand a single IoC into the broader context of an attack.

It doesn't stop at what's malicious — it connects who, why, where, and how the attack happened.

IOC INTELLIGENCE

IoC Intelligence

Checks the maliciousness and threat characteristics of files, IPs, domains, and URLs, along with similar files and related IoCs.

APT INTELLIGENCE

APT Intelligence

Connects threat actors, campaigns, attacker countries, victim countries, victim industries, threat types, MITRE ATT&CK, and related IoCs.

AI INVESTIGATION WORKSPACE

Skip the search box — ask like an analyst.

CTX provides a conversational investigation environment where entering your investigation goal in natural language connects the analysis functions and threat information you need and synthesizes the results. For example, you can ask like an analyst: "Analyze whether this file is information-stealing malware."

01

Combines analysis based on the purpose of your question

Automatically selects the analysis tools and execution order based on the purpose of your question.

02

Remembers and continues from previous investigations

Remembers previous analysis results and continues the investigation with follow-up questions.

03

Shows the analysis process in real time

Displays analysis progress and results in real time.

04

Manages your investigation in one workspace

Manages files, analysis results, and conversation history in a single investigation workspace.

SECURITY ANALYSIS

From file analysis to threat intelligence—all in CTX.

STATIC ANALYSIS

Static analysis

Analyzes a file's static characteristics — hash, strings, PE/ELF/Mach-O structure, certificates, sections, entropy, and more.

REVERSE ENGINEERING

Reverse engineering analysis

Investigates a file's internal structure and behavior using Ghidra- and Radare2-based analysis.

BEHAVIOR / CAPABILITY

Behavior & capability analysis

Uses YARA, capa, FLOSS, and more to analyze rule matching, behavioral characteristics, obfuscated strings, and more.

VARIANT ANALYSIS

Variant & similar file analysis

Compares related samples and variants based on similarity information such as ssdeep and imphash.

DOCUMENT MALWARE

Document malware analysis

Analyzes document-type files such as PDF, HWP, and Office (DOC/XLS/PPT).

LIVE INTELLIGENCE

CTX data powers new threat analysis every day.

CTX doesn't stop at collecting real-time threat data — it continuously generates new threat intelligence by analyzing the relationships between attack infrastructure, files, and campaigns. Collected data becomes intelligence, and that intelligence expands again into ongoing analysis content.

APT

APT threat reports

CTX Threat News continuously publishes reports analyzing threats related to attack groups and campaigns.

C&C

C2 threat reports

Publishes reports analyzing threats related to C2 confirmed as attack infrastructure.

FILE

Malicious file reports

Publishes reports analyzing newly identified malicious files.

Go to CTX Threat News

Reports are analyzed first by AI based on CTX data, with editorial review where needed before publishing.

SEARCH SCENARIO

Combine conditions to investigate a threat scenario.

Search for related campaigns and IoCs by combining files, IPs, domains, URLs, attack groups, countries, industries, TTPs, and threat types with AND / OR / NOT conditions.

FILTER BUILDER

Combine attack conditions

Combine files, IPs, domains, URLs with attack groups, countries, industries, TTPs, and threat types using AND / OR / NOT — for example, Threat Type=Ransomware, Threat Actor=Lazarus Group, Victim Country=KR, Victim Industry=Government OR Telecommunications, MITRE TTP=T1047.

CORRELATED RESULTS

See related campaigns and IoCs

See every campaign, file, IP, domain, and URL that matches your combined conditions at once.

INTEGRATION

Connect CTX threat intelligence to your existing security stack.

WEB

Web Intelligence

Look up and analyze files, IPs, domains, URLs, and APT intelligence directly on the web.

API

API

Look up CTX intelligence — IoC analysis results, related information, attack groups and campaigns — from your existing systems.

FEED

Real-time Feed

Delivers newly identified malicious files, IPs, domains, URLs, and attack group/campaign information tailored to your operating environment.

CTX × MNX

MNX integration

Cross-validates file, IP, and domain information MNX collected from the network against CTX's threat intelligence, adding attack context to detection results.

CONNECT TO

SIEM / SOAR / NDR

Can connect to security platform categories such as SIEM, SOAR, and NDR. Products with confirmed official integration will be announced individually.

USE CASES

From checking an IoC to tracking an attack campaign.

Breach investigation

Breach investigation

Look up a suspicious file, IP, or domain to investigate not just its maliciousness but related IoCs and attack groups/campaigns.

APT campaign tracking

APT campaign tracking

Trace the flow of an attack campaign by connecting the files, C2, domains, TTPs, and target information an attacker used.

Enriching SOC threat information

Enriching SOC threat information

Adds CTX intelligence to IoCs detected by SIEM, SOAR, and security monitoring systems to support prioritization and response.

Threat hunting

Threat hunting

Proactively searches for attack traces and IoCs related to a specific organization by combining attack group, country, industry, TTP, and threat type.

DEPLOYMENT

From cloud to internal environments.

CLOUD

CTX Cloud

Provides a web-based threat investigation and analysis environment via CTX Cloud.

ON-PREMISE

Internal deployment

In closed networks, we're considering a structure that restricts external threat intelligence and external LLM calls, applying a self-hosted LLM where needed. The detailed scope of availability needs to be confirmed at the time of adoption.

PROVEN TECHNOLOGY

CTI built on threat data, AI, profiling, and correlation.

LONG-TERM RESEARCH

Years of accumulated threat analysis experience

We've developed CTX based on SANDS Lab's years of malware and cyber threat research and service operation experience.

CERTIFIED TECHNOLOGY

A track record of new-technology certification

We have a track record of earning new-technology certification related to file-based attack technique and attack group identification and profiling technology.

AI MODELS

Our own AI, trained on security data

Uses cybersecurity-specialized AI models — malware detection, threat labeling, attack technique, threat actor, and more — to generate CTX intelligence.

FAQ

Frequently asked questions about CTX.

How is CTX different from traditional IoC lookup services?

CTX goes beyond telling you whether a file, IP, domain, or URL is malicious. It connects an IoC to related threat actors, campaigns, target countries and industries, and MITRE ATT&CK techniques to reveal the broader context behind the threat.

What role does AI play in CTX?

CTX uses its own AI models for threat detection and attack technique/attack group analysis. The latest version of CTX combines this with LLM-based intelligent orchestration, expanding into a conversational investigation environment that selects the analysis tools and data a user's question needs and synthesizes the results.

Can I request threat analysis in natural language?

Yes. You can ask natural-language questions about files, IoCs, and threat intelligence, then continue the investigation with follow-up questions based on the results.

Does CTX also provide threat actor and campaign information?

Yes. CTX connects individual IoCs with related threat actors, campaigns, target countries and industries, threat types, and MITRE ATT&CK techniques to provide broader APT context.

Can CTX integrate with SIEM or SOAR platforms?

Yes. CTX can deliver threat intelligence to existing security systems through APIs and threat feeds, including information on malicious files, IPs, domains, URLs, threat actors, and campaigns. Integration scope may vary depending on the target platform and available APIs.

Can CTX be deployed on premises?

CTX is being developed with both cloud and internal deployment in mind. In closed networks, there may be restrictions on external threat intelligence or external LLM calls, and a self-hosted LLM structure may also be considered. The latest scope of availability should be confirmed at the time of adoption.

How is CTX Threat News related to CTX?

CTX Threat News is SANDS Lab’s threat intelligence newsroom, built on threat data collected and analyzed through CTX. It turns ongoing intelligence on APTs, C2 infrastructure, malicious files, and emerging threats into timely analysis and content.

Go beyond threat indicators — see the context behind the attack.

See threat intelligence connected from files, IPs, domains, and URLs to attack groups, campaigns, and TTPs in CTX, and experience an AI-based investigation environment.

How does this product behave in your environment?

Whether you're exploring, evaluating, or rolling out, you connect directly with a SANDS Lab solutions engineer. Clear every question before contract — that's the point.

FOR EVALUATORS

Product evaluation & PoC

Real-data PoCs, technical deep-dive sessions, and custom integration scoping. Everything you'd need to validate technical fit before the paperwork starts.

FOR RESEARCHERS

Technical collaboration & licensing

If you want to use the product in an academic benchmark or co-authored paper, we support research licenses and the underlying datasets. Co-authorship is on the table.