The Platform, in Detail

Every capability, and the page an analyst actually opens. What follows is the real product surface, not a diagram of it.

What you send, and what comes back

One HTTPS call from your SIEM or SOAR. There is no agent to install, nothing to deploy inside your environment, and no requirement to forward logs anywhere.

You send a distilled incident

An incident reference, the ATT&CK technique IDs your detection already mapped, and your observables: hashes, IPs, domains, URLs, filenames. Every field is optional. A single hash is enough to get a verdict.

Neotelix answers from vetted intelligence

Your observables are correlated against the knowledge base. You get one of three verdicts, a confidence rating, TLP handling, and where an indicator ties to a campaign, a sweep list of related indicators to hunt wider than the single alert.

You get analyst-ready guidance

Returned as JSON for your tooling, or as display-ready Markdown you can paste straight into an offence note or war-room entry with no parsing.

Platform Capabilities

Everything your security operations need to stay ahead of evolving threats.

AI Powered Enrichment

AI driven enrichment converts security intelligence into meaningful investigation and response guidance.

Investigation Acceleration

Reduce investigation time with structured methodologies and actionable insights.

Threat Intelligence at Scale

Aggregate relevant intelligence from multiple sources to stay informed and prepared.

Response Optimisation

Validated guidance supports consistent and effective response decisions.

Knowledge On Demand

Access analyst ready guidance across threats, techniques, malware and more.

Continuous Learning

The platform evolves with new intelligence and with analyst feedback.

Built for SOC Teams

Designed for analysts, to fit naturally into existing security processes.

Trusted and Secure

Tenant isolation, named permissions and an append only audit trail underpin every capability.

What one incident produces

Nine artefacts, generated for the incident in front of you.

Investigation methodology

Where to look first, which queries to run, and what a true positive looks like.

Detection strategy

Matched rules with severity, the gaps in your coverage, and rules generated to close them.

False positives

The benign explanations that produce this same signal, so noise closes quickly.

Containment

Steps to stop it spreading, flagged distinctly because they change state in your environment.

Eradication

Removing the payload and any persistence it created.

Recovery

Restoring from verified clean backups, and what credentials to rotate.

Threat hunting

Pivots worth chasing beyond the alert: process lineage, command lines, destinations.

Executive summary

What happened and what it means, for someone who will not read a technique ID.

Detection coverage

Incident guidance only helps with incidents you already detected. Coverage analysis raises the standard of the detection itself.

Upload your rules, find the gaps

Export your detection rules and Neotelix reports where your ATT&CK coverage has holes. One endpoint serves every vendor; the platform identifies which SIEM the file came from rather than asking you.

Detection refuses rather than guesses

A match needs both a minimum score and a clear margin over the runner-up. Otherwise the answer is UNKNOWN with a stated reason, because misreading Splunk as Sentinel produces rules you cannot deploy.

Rules delivered, not deployed

Generated detections come back in your own query language, with a confidence rating and a note on whether they were native or translated. Neotelix holds no write credentials into your estate and has no blast radius there.

See it against your own incident

Bring a technique ID from an incident you have already closed. We will run it through the platform and you can judge the output against what your team concluded.

Request a Demo