See It In Action

The page an analyst opens, running live. Not a screenshot and not a diagram: this is the real product surface, driven by real generated output.

This is the page an analyst opens

A real generated response for a ShadowPad incident: verdict and confidence, TLP handling, the matched indicator, and the response plan broken into NIST 800-61 phases. Expand a phase and tick the steps off.

app.neotelix.com/incidents/INC-48213

Neotelix analyst page for a ShadowPad incident

KNOWN THREAT confidence: medium INC-48213 · 54.8s
TLP:CLEAR. May be shared without restriction.

Malware

ShadowPad inferred

Matched indicator

9c9976adbb1f…9c211
hash_md5 · medium

Sweep list

18
same-campaign indicators

Intelligence

Cyber espionage operation targeting Thailand's Ministry of Finance. Attack leveraged Hermes, an autonomous AI agent in unattended mode, alongside a custom Go-based implant called Hades. Chinese-language indicators and historical ShadowPad presence suggest probable Chinese-speaking attribution.

AlienVault OTX: Thailand's Ministry of Finance Targeted With Hermes AI Agent

Ingress Tool Transfer T1105 UNREVIEWED
Generated on demand and NOT yet reviewed by a human analyst. Grounded in the knowledge base, but it has no knowledge of your environment. Verify before executing containment or eradication steps.

Adversaries may transfer tools or other files from an external system into a compromised environment.

Tactics

Command and Control

Why this technique

matched malware

Response: NIST 800-61

Supporting evidence: what the guidance was built from

Was this useful?

Interactive demo. Expand any phase. Feedback buttons and the report builder are illustrative here.

See it against your own incident

Bring a technique ID from an incident you have already closed. We will run it through the platform and you can judge the output against what your team concluded.

Request a Demo