Drawing on years of accumulated cyber threat data and proprietary AI models, CTX connects files, IPs, domains, and URLs to attackers, campaigns, and TTPs. Its LLM-based investigation environment selects the analysis tools and threat intelligence needed for each query, supporting threat analysis, explanation, summarization, and reporting in a single flow.
CTX isn’t CTI with AI added. It’s AI-native CTI built on years of threat research.
CTX’s AI wasn’t built overnight. Here’s what it’s built on.
Years of Threat Research
SANDS Lab has collected and analyzed malware and cyber threat data for years. CTX’s AI is built on that foundation.
Expertise in Interpreting Attack Context
Years of experience connecting individual indicators to attack groups, campaigns, and TTPs—not simply flagging them—form the basis of CTX’s AI analysis.
Threat Intelligence Proven in Real-World Operations
From malwares.com to CTX, our threat intelligence has been developed and validated through real-world operations.
From malware analysis to AI-native CTI that interprets attack context.
CTX’s foundation wasn’t built overnight. SANDS Lab has collected and analyzed malware and cyber threat data for years, continuously building on the data and analytical capabilities accumulated along the way—from IoC-centric intelligence to attacker-centric CTI and now to an AI-native investigation environment.
Collecting and Analyzing Malware and IoCs
The foundation began with a public intelligence service that collected and analyzed large-scale malware and threat data—including files, IPs, and domains—and provided maliciousness status and related information.
Connecting IoCs to Attacker and Campaign Context
The intelligence evolved into CTI that connects individual threat indicators to attack groups, campaigns, target countries and industries, and MITRE ATT&CK TTPs to analyze the purpose and flow of APT attacks.
AI Supports the Investigation Workflow
CTX combines proprietary AI detection models and threat data with LLM-based intelligent orchestration to create an investigation environment that selects the analysis tools and data required for each question and synthesizes the results.
AI-Native CTI starts with threat data at scale.
An LLM alone can't create threat intelligence. CTX's AI runs on malware, IoCs, attack groups, campaigns, attack techniques, and related information that SANDS Lab has directly collected and analyzed over a long period. It's built on tens of billions of records of threat and profiling data.
Malware data
Analyzes malicious/benign files, malware families, file structure, similarity, and behavior.
IoC data
Collects and analyzes threat indicator data — files, IPs, domains, URLs, and more.
Attack context data
Connects threat actors, campaigns, target countries, target industries, and threat types.
Attack technique data
Includes MITRE ATT&CK, attack technique, and behavior information.
Related information data
Connects associated files, communicating IPs, domains, URLs, C2, and campaign relations.
Not CTI with an LLM bolted on. AI is built into the analysis process.
CTX's AI isn't limited to generating answers in a chat window. It applies AI across multiple stages of CTI — from threat detection to correlation analysis, tool selection, and result synthesis and reporting.
Identifies threats.
Our own AI models analyze the maliciousness and threat characteristics of files, IPs, domains, and more.
Connects the actor and technique behind an attack.
Identifies attack context — attack groups and MITRE ATT&CK TTPs — based on analyzed threat information.
AI builds the analysis sequence a question needs.
The LLM understands the user's question, selects the analysis tools and data-lookup order needed, and synthesizes the results.
Explains analysis results in a way people can understand.
Summarizes complex analysis results and threat intelligence in natural language, letting the investigation continue through follow-up questions.
Organizes investigation results into a reportable form.
Summarizes the analysis process results, and is being advanced to generate them as LLM-based reports.
Expand a single IoC into the broader context of an attack.
It doesn't stop at what's malicious — it connects who, why, where, and how the attack happened.
IoC Intelligence
Checks the maliciousness and threat characteristics of files, IPs, domains, and URLs, along with similar files and related IoCs.
APT Intelligence
Connects threat actors, campaigns, attacker countries, victim countries, victim industries, threat types, MITRE ATT&CK, and related IoCs.
Skip the search box — ask like an analyst.
CTX provides a conversational investigation environment where entering your investigation goal in natural language connects the analysis functions and threat information you need and synthesizes the results. For example, you can ask like an analyst: "Analyze whether this file is information-stealing malware."
Combines analysis based on the purpose of your question
Automatically selects the analysis tools and execution order based on the purpose of your question.
Remembers and continues from previous investigations
Remembers previous analysis results and continues the investigation with follow-up questions.
Shows the analysis process in real time
Displays analysis progress and results in real time.
Manages your investigation in one workspace
Manages files, analysis results, and conversation history in a single investigation workspace.
From file analysis to threat intelligence—all in CTX.
Static analysis
Analyzes a file's static characteristics — hash, strings, PE/ELF/Mach-O structure, certificates, sections, entropy, and more.
Reverse engineering analysis
Investigates a file's internal structure and behavior using Ghidra- and Radare2-based analysis.
Behavior & capability analysis
Uses YARA, capa, FLOSS, and more to analyze rule matching, behavioral characteristics, obfuscated strings, and more.
Variant & similar file analysis
Compares related samples and variants based on similarity information such as ssdeep and imphash.
Document malware analysis
Analyzes document-type files such as PDF, HWP, and Office (DOC/XLS/PPT).
CTX data powers new threat analysis every day.
CTX doesn't stop at collecting real-time threat data — it continuously generates new threat intelligence by analyzing the relationships between attack infrastructure, files, and campaigns. Collected data becomes intelligence, and that intelligence expands again into ongoing analysis content.
APT threat reports
CTX Threat News continuously publishes reports analyzing threats related to attack groups and campaigns.
C2 threat reports
Publishes reports analyzing threats related to C2 confirmed as attack infrastructure.
Malicious file reports
Publishes reports analyzing newly identified malicious files.
Reports are analyzed first by AI based on CTX data, with editorial review where needed before publishing.
Combine conditions to investigate a threat scenario.
Search for related campaigns and IoCs by combining files, IPs, domains, URLs, attack groups, countries, industries, TTPs, and threat types with AND / OR / NOT conditions.
Combine attack conditions
Combine files, IPs, domains, URLs with attack groups, countries, industries, TTPs, and threat types using AND / OR / NOT — for example, Threat Type=Ransomware, Threat Actor=Lazarus Group, Victim Country=KR, Victim Industry=Government OR Telecommunications, MITRE TTP=T1047.
See related campaigns and IoCs
See every campaign, file, IP, domain, and URL that matches your combined conditions at once.
Connect CTX threat intelligence to your existing security stack.
Web Intelligence
Look up and analyze files, IPs, domains, URLs, and APT intelligence directly on the web.
API
Look up CTX intelligence — IoC analysis results, related information, attack groups and campaigns — from your existing systems.
Real-time Feed
Delivers newly identified malicious files, IPs, domains, URLs, and attack group/campaign information tailored to your operating environment.
MNX integration
Cross-validates file, IP, and domain information MNX collected from the network against CTX's threat intelligence, adding attack context to detection results.
SIEM / SOAR / NDR
Can connect to security platform categories such as SIEM, SOAR, and NDR. Products with confirmed official integration will be announced individually.
From checking an IoC to tracking an attack campaign.

Breach investigation
Look up a suspicious file, IP, or domain to investigate not just its maliciousness but related IoCs and attack groups/campaigns.

APT campaign tracking
Trace the flow of an attack campaign by connecting the files, C2, domains, TTPs, and target information an attacker used.

Enriching SOC threat information
Adds CTX intelligence to IoCs detected by SIEM, SOAR, and security monitoring systems to support prioritization and response.

Threat hunting
Proactively searches for attack traces and IoCs related to a specific organization by combining attack group, country, industry, TTP, and threat type.
From cloud to internal environments.
CTX Cloud
Provides a web-based threat investigation and analysis environment via CTX Cloud.
Internal deployment
In closed networks, we're considering a structure that restricts external threat intelligence and external LLM calls, applying a self-hosted LLM where needed. The detailed scope of availability needs to be confirmed at the time of adoption.
CTI built on threat data, AI, profiling, and correlation.
Years of accumulated threat analysis experience
We've developed CTX based on SANDS Lab's years of malware and cyber threat research and service operation experience.
A track record of new-technology certification
We have a track record of earning new-technology certification related to file-based attack technique and attack group identification and profiling technology.
Our own AI, trained on security data
Uses cybersecurity-specialized AI models — malware detection, threat labeling, attack technique, threat actor, and more — to generate CTX intelligence.
Frequently asked questions about CTX.
How is CTX different from traditional IoC lookup services?
CTX goes beyond telling you whether a file, IP, domain, or URL is malicious. It connects an IoC to related threat actors, campaigns, target countries and industries, and MITRE ATT&CK techniques to reveal the broader context behind the threat.
What role does AI play in CTX?
CTX uses its own AI models for threat detection and attack technique/attack group analysis. The latest version of CTX combines this with LLM-based intelligent orchestration, expanding into a conversational investigation environment that selects the analysis tools and data a user's question needs and synthesizes the results.
Can I request threat analysis in natural language?
Yes. You can ask natural-language questions about files, IoCs, and threat intelligence, then continue the investigation with follow-up questions based on the results.
Does CTX also provide threat actor and campaign information?
Yes. CTX connects individual IoCs with related threat actors, campaigns, target countries and industries, threat types, and MITRE ATT&CK techniques to provide broader APT context.
Can CTX integrate with SIEM or SOAR platforms?
Yes. CTX can deliver threat intelligence to existing security systems through APIs and threat feeds, including information on malicious files, IPs, domains, URLs, threat actors, and campaigns. Integration scope may vary depending on the target platform and available APIs.
Can CTX be deployed on premises?
CTX is being developed with both cloud and internal deployment in mind. In closed networks, there may be restrictions on external threat intelligence or external LLM calls, and a self-hosted LLM structure may also be considered. The latest scope of availability should be confirmed at the time of adoption.
How is CTX Threat News related to CTX?
CTX Threat News is SANDS Lab’s threat intelligence newsroom, built on threat data collected and analyzed through CTX. It turns ongoing intelligence on APTs, C2 infrastructure, malicious files, and emerging threats into timely analysis and content.
Go beyond threat indicators — see the context behind the attack.
See threat intelligence connected from files, IPs, domains, and URLs to attack groups, campaigns, and TTPs in CTX, and experience an AI-based investigation environment.
How does this product behave in your environment?
Whether you're exploring, evaluating, or rolling out, you connect directly with a SANDS Lab solutions engineer. Clear every question before contract — that's the point.
Product evaluation & PoC
Real-data PoCs, technical deep-dive sessions, and custom integration scoping. Everything you'd need to validate technical fit before the paperwork starts.
Technical collaboration & licensing
If you want to use the product in an academic benchmark or co-authored paper, we support research licenses and the underlying datasets. Co-authorship is on the table.