SHOLI AI threat intelligence by CNRG

Every threat. Your context. One answer.

SHOLI watches the threat landscape around the clock, correlates it with your organization, and answers in plain language with evidence you can cite.

Threat research✦TTP extraction✦Kaspersky feeds✦Telegram channels✦X & TweetFeed✦Private intelligence✦
IPs/Domains/File hashes/CVEs/Threat actors/Credentials/Malware families/

01 The problem

Threat data is everywhere and nowhere useful at once. It is scattered across hundreds of sources, generic AI answers without evidence, and analysts lose hours before they can act on a single threat.

0+
research sources mined for TTPs and indicators
24/7
collection, even when your analysts are offline
0
connected view, framed around your organization

02 From signal to answer

01

Collect

Always-on collectors pull published threat research, licensed Kaspersky threat data feeds, monitored Telegram channels, and X / TweetFeed intelligence into one stream.

  • Research reports
  • Kaspersky feeds
  • Telegram
  • X / TweetFeed
02

Extract

Language models read every source and pull out the concrete facts: techniques, tools and indicators, refanged and normalized so they can be searched and matched.

  • TTPs
  • IPs
  • Domains
  • Hashes
  • CVEs
03

Organize

Everything lands in a structured, searchable intelligence store with a semantic index, so a question in plain language finds the right evidence, not just the right keywords.

  • Structured store
  • Semantic index
  • Your private intel
04

Correlate

Findings are pivoted across incidents and matched against your organization profile: your domains, IP ranges, vendors, VIPs and watchlists.

  • Artifact pivots
  • Asset matches
  • Vendor risk
05

Answer

You get an answer with numbered sources, extracted indicators, severity and relevance to you. Every material claim points back to the evidence behind it.

  • [S1] Cited
  • Severity
  • Relevance
  • Export

03 Ask SHOLI

Ask like a person.
Get answered like an analyst.

Type a question in plain language. SHOLI retrieves the relevant intelligence, checks it against your organization, and replies with severity, relevance, indicators and the sources it used.

SHOLI / new chatSTANDARD
›
Illustrative simulation. Names and values are examples, not live data.

04 Deep investigation

Pull one thread.
See the whole web.

Deep investigation pivots on the artifacts behind a finding, a hash, a domain, an address, and follows them into every other incident where they appear. Hidden connections surface as a graph you can read.

  • Incident
  • Artifact
  • Threat actor
  • Your asset

05 HuntIQ IOC hunter

Turn a lead
into a hunt list.

Search indicators across every intelligence index at once, by value, type, actor, sector or geography. Get a verdict, the sources that saw it, and an export ready for your SOC and SIEM workflows.

0Malicious
0Suspicious
0Clean
IndicatorTypeVerdict

Example values use reserved documentation ranges.

06 Your context

A threat is global.
Your exposure is personal.

Build an organization profile once: sector, domains, IP ranges, vendors, VIP persons, compliance frameworks and watchlists. SHOLI checks every finding against it and raises asset alerts when the landscape touches you.

  1. Bring your environment into view. Profile, assets and approved private indicators.
  2. Find the intersections. Asset matches, vendor risk, watchlist and VIP hits.
  3. Focus the next decision. Exposure, evidence and compliance implications together.

07 Everything around the answer

Built for the whole
intelligence lifecycle.

Exposure score

Key numbers and overall exposure on one dashboard: critical alerts, malicious IOCs and asset coverage.

0/100 example

Sector peer benchmark

See where you stand against your sector average. Benchmarks appear only when there are enough peers to keep everyone anonymous.

Scheduled intelligence

Keep the right questions running. Results arrive on your schedule.

Shareable reports

Choose sections, fields and redaction, then export a polished PDF for management.

File analysis

Attach a suspicious file for sandbox and attribution analysis, right inside the conversation.

Proactive alerts

Evidence-based alerts with gap analysis and compliance implications under each finding.

08 Built for sensitive environments

Your context
stays yours.

SHOLI is designed for organizations that cannot leak what they are looking at. It can run in your own environment, including air-gapped networks, with its language models served locally.

  • OPSEC by default. Your assets and uploaded file hashes are never sent to external lookup services.
  • Grounded answers. The model sees exactly the sources it cites, with indicator grounding, citation checks and prompt-injection guards.
  • Customer-scoped data. Shared intelligence excludes customer values, and every workspace is isolated by role.
[security]server_config.ini
CORS restriction
Generic error responses
Login throttling
Password policy
Internal index protection
Admin audit log
File analysis capacity limits
● All protections switchable per deployment

09 One platform, three views

10 CNRG, the company behind SHOLI

Make itrelevant.

See how SHOLI fits your team's priorities in a personal demo.

Request a demo

rotem@cnrg.co.il