Collect
Always-on collectors pull published threat research, licensed Kaspersky threat data feeds, monitored Telegram channels, and X / TweetFeed intelligence into one stream.
- Research reports
- Kaspersky feeds
- Telegram
- X / TweetFeed
SHOLI AI threat intelligence by CNRG
SHOLI watches the threat landscape around the clock, correlates it with your organization, and answers in plain language with evidence you can cite.
01 The problem
02 From signal to answer
Always-on collectors pull published threat research, licensed Kaspersky threat data feeds, monitored Telegram channels, and X / TweetFeed intelligence into one stream.
Language models read every source and pull out the concrete facts: techniques, tools and indicators, refanged and normalized so they can be searched and matched.
Everything lands in a structured, searchable intelligence store with a semantic index, so a question in plain language finds the right evidence, not just the right keywords.
Findings are pivoted across incidents and matched against your organization profile: your domains, IP ranges, vendors, VIPs and watchlists.
You get an answer with numbered sources, extracted indicators, severity and relevance to you. Every material claim points back to the evidence behind it.
03 Ask SHOLI
Type a question in plain language. SHOLI retrieves the relevant intelligence, checks it against your organization, and replies with severity, relevance, indicators and the sources it used.
04 Deep investigation
Deep investigation pivots on the artifacts behind a finding, a hash, a domain, an address, and follows them into every other incident where they appear. Hidden connections surface as a graph you can read.
05 HuntIQ IOC hunter
Search indicators across every intelligence index at once, by value, type, actor, sector or geography. Get a verdict, the sources that saw it, and an export ready for your SOC and SIEM workflows.
Example values use reserved documentation ranges.
06 Your context
Build an organization profile once: sector, domains, IP ranges, vendors, VIP persons, compliance frameworks and watchlists. SHOLI checks every finding against it and raises asset alerts when the landscape touches you.
07 Everything around the answer
Key numbers and overall exposure on one dashboard: critical alerts, malicious IOCs and asset coverage.
See where you stand against your sector average. Benchmarks appear only when there are enough peers to keep everyone anonymous.
Keep the right questions running. Results arrive on your schedule.
Choose sections, fields and redaction, then export a polished PDF for management.
Attach a suspicious file for sandbox and attribution analysis, right inside the conversation.
Evidence-based alerts with gap analysis and compliance implications under each finding.
08 Built for sensitive environments
SHOLI is designed for organizations that cannot leak what they are looking at. It can run in your own environment, including air-gapped networks, with its language models served locally.
09 One platform, three views
See what deserves attention. Exposure, asset alerts and vendor relevance, with reports ready for the board.
↗ 02Work from the finding to the source. Investigate artifacts, hunt indicators, review raw feeds and export.
↗ 03Keep every customer in context with isolated workspaces, role-based access and per-customer intelligence.
↗10 CNRG, the company behind SHOLI
See how SHOLI fits your team's priorities in a personal demo.
Request a demorotem@cnrg.co.il