Part of the RST intelligence layer

cti-assistant-icon

RST CTI Assistant

Grounded in the entire RST corpus, reachable over MCP, an OpenAI-compatible endpoint, or in Slack and Microsoft Teams — source-referenced answers, 24x7.

Trusted interface — source-referenced answers for agents and analysts.

Grounded in the whole corpus, not one dataset

The Assistant is retrieval-augmented over RST's own threat feeds, report library, threat actor profiles and enrichment APIs — plus public threat research, in more than one language. Every answer links back to the report it came from, so you check the source instead of taking the sentence on faith.

Ask it directly — across the SOC
CISOWhat is our exposure to the ransomware campaigns hitting our sector this quarter?
CTI analystWhat aliases does APT28 go by across different vendor reporting?
SOC managerHow many high-confidence indicators has Threat Feed added for our region this week?
SOC analystWhat do you know about this IP address?
Detection engineerWhat TTPs does LockBit use that our current detections might miss?
DFIR specialistWhich files does this malware create for persistence?
Threat hunterWhat newer C2 frameworks are being used against financial services?
Threat researcherWhat threats target Retail in Australia?

Answers in seconds

No manual pivoting between tools to build the picture, and no ticket in a queue — the reasoning already ran.

Global by default

Multilingual collection and reporting across industries and regions — not just the loudest English-language headlines.

No dedicated headcount required

The corpus and the reasoning are already built — a mid-market team gets the same answer a Tier-1 SOC does.

Never stale

Grounded in the same corpus that feeds Report Hub, Threat Library and Threat Feed — it doesn't fall behind what the rest of the layer already knows.

The intelligence brain any agent can call

Most “CTI MCP” offerings are thin wrappers exposing one dataset as tool calls, with the reasoning still happening in your ungrounded model. CTI Assistant is grounded in the entire RST corpus and returns source-referenced answers — reachable two ways.

For agents — two ways in: MCP + OpenAI-compatiblePoint any SOAR, SOC tool, or agent framework that speaks the OpenAI API at CTI Assistant with a one-line base-URL change, and it becomes CTI-grounded.
base_url: https://api.rstcloud.net/v1/chat/completions
api_key:  <your RST API key>
model:    rst-research-1
For agents

API & MCP

OpenAI-compatible endpoint or MCP tool calls — grounded, source-referenced answers any agent framework can call directly.

MCPOpenAI-compatible

Usage guide →

For humans, with local AI tools

MCP in Claude, Cursor & friends

The same MCP server your agents use also works from Claude Desktop, Cursor, or any MCP-speaking client — grounded CTI answers inside the tools an analyst already has open, not a separate portal.

Claude DesktopCursorany MCP client
For humans, in chat

Slack & Microsoft Teams

A 24x7 virtual CTI analyst where responders already are — source-referenced answers in whatever language the question was asked in, no context-switch at 3 AM.

SlackMicrosoft Teams

See the Teams bot →

Your 24x7 virtual CTI analyst, already in Teams

Ask what's targeting your sector this week, what a suspicious IP is doing, or how a piece of malware behaves — and get a source-referenced answer back in the same chat, in the language you asked in.

  • Personal, team or group chat — no separate tool to open
  • One-time setup: an admin sets your RST API key with setkey in a direct message to the bot
  • Type help any time for a refresher on what to ask, or report to send feedback
Microsoft Teams
RST CTI Assistant Bot in Microsoft Teams answering an IP address risk-scoring question

See it answer your question, not a demo script.

Bring a real indicator, actor, or sector question to a live session — or start with the Teams bot if your team already lives in chat.

Request a demo