The Platform, in Detail
Every capability, and the page an analyst actually opens. What follows is the real product surface, not a diagram of it.
What you send, and what comes back
One HTTPS call from your SIEM or SOAR. There is no agent to install, nothing to deploy inside your environment, and no requirement to forward logs anywhere.
You send a distilled incident
An incident reference, the ATT&CK technique IDs your detection already mapped, and your observables: hashes, IPs, domains, URLs, filenames. Every field is optional. A single hash is enough to get a verdict.
Neotelix answers from vetted intelligence
Your observables are correlated against the knowledge base. You get one of three verdicts, a confidence rating, TLP handling, and where an indicator ties to a campaign, a sweep list of related indicators to hunt wider than the single alert.
You get analyst-ready guidance
Returned as JSON for your tooling, or as display-ready Markdown you can paste straight into an offence note or war-room entry with no parsing.
Platform Capabilities
Everything your security operations need to stay ahead of evolving threats.
AI Powered Enrichment
AI driven enrichment converts security intelligence into meaningful investigation and response guidance.
Investigation Acceleration
Reduce investigation time with structured methodologies and actionable insights.
Threat Intelligence at Scale
Aggregate relevant intelligence from multiple sources to stay informed and prepared.
Response Optimisation
Validated guidance supports consistent and effective response decisions.
Knowledge On Demand
Access analyst ready guidance across threats, techniques, malware and more.
Continuous Learning
The platform evolves with new intelligence and with analyst feedback.
Built for SOC Teams
Designed for analysts, to fit naturally into existing security processes.
Trusted and Secure
Tenant isolation, named permissions and an append only audit trail underpin every capability.
What one incident produces
Nine artefacts, generated for the incident in front of you.
Investigation methodology
Where to look first, which queries to run, and what a true positive looks like.
Detection strategy
Matched rules with severity, the gaps in your coverage, and rules generated to close them.
False positives
The benign explanations that produce this same signal, so noise closes quickly.
Containment
Steps to stop it spreading, flagged distinctly because they change state in your environment.
Eradication
Removing the payload and any persistence it created.
Recovery
Restoring from verified clean backups, and what credentials to rotate.
Threat hunting
Pivots worth chasing beyond the alert: process lineage, command lines, destinations.
Executive summary
What happened and what it means, for someone who will not read a technique ID.
Detection coverage
Incident guidance only helps with incidents you already detected. Coverage analysis raises the standard of the detection itself.
Upload your rules, find the gaps
Export your detection rules and Neotelix reports where your ATT&CK coverage has holes. One endpoint serves every vendor; the platform identifies which SIEM the file came from rather than asking you.
Detection refuses rather than guesses
A match needs both a minimum score and a clear margin over the runner-up. Otherwise the answer is UNKNOWN with a stated reason, because misreading Splunk as Sentinel produces rules you cannot deploy.
Rules delivered, not deployed
Generated detections come back in your own query language, with a confidence rating and a note on whether they were native or translated. Neotelix holds no write credentials into your estate and has no blast radius there.
See it against your own incident
Bring a technique ID from an incident you have already closed. We will run it through the platform and you can judge the output against what your team concluded.
Request a Demo