AshES CTI Documentation

AshES CTI is a Windows-native, offline-first threat intelligence workstation for SOC, DFIR, detection engineering, threat hunting, and air-gapped environments.

Installation Guide

AshES CTI is designed to keep deployment simple. No servers, no cloud accounts, and no external platform setup are required. Install the application, activate the license, and begin working from the local workstation.

System Requirements

  • Windows 10 / 11 64-bit
  • Admin rights required only for installation
  • No server required
  • No cloud account required
  • Internet access required only for live OSINT ingestion, live enrichment, or update checks
  • Offline workflows supported when intelligence is preloaded

Download

Download AshES CTI from the official product page:
https://ashes-cybersecurity.com/ashescti/

Installation Steps

  • Download the latest AshES CTI installer.
  • Run the installer.
  • Follow the on-screen instructions.
  • Launch AshES CTI from the Start Menu or installation folder.
  • Enter your license key or select your license file when prompted.

First Run & License Activation

On first launch, AshES CTI displays a license activation window.

  • Select your license file or paste your license key.
  • Activation is performed locally.
  • Your activation persists on the licensed machine.
  • License validation uses cryptographically signed license data.
  • Restricted and offline environments are supported depending on deployment requirements.

Using the Graphical Interface

  • Open AshES CTI.
  • Run OSINT ingestion or import intelligence manually.
  • Review summaries, IOCs, MITRE ATT&CK mappings, and actor context.
  • Use the IOCs view to inspect extracted indicators.
  • Use the Actors view to review threat actor intelligence and ATT&CK-linked context.
  • Run enrichment where required.
  • Export intelligence using supported formats.

Using the Command-Line Interface

Run from PowerShell or Command Prompt:

ashes-ti.exe ingest-yesterday-only
ashes-ti.exe enrich-iocs
ashes-ti.exe ioc-add
ashes-ti.exe --help
ashes-ti.exe --version

Key Features

  • OSINT Feed Ingestion: Process supported intelligence sources and extract useful context.
  • IOC Extraction: Extract IPs, hashes, domains, URLs, CVEs, and other relevant indicators.
  • Threat Actor Intelligence: Review actor profiles, aliases, associated malware, sectors, and ATT&CK techniques.
  • MITRE ATT&CK Mapping: Quickly understand adversary techniques and detection relevance.
  • Rule Artifact Support: Work with YARA, SNORT, and Sigma rule content.
  • Exports: TAXII 2.1, STIX 2.1, CSV, JSON, YARA, SNORT, and Sigma.
  • Daily Routine: Run ingestion, review intelligence, enrich IOCs, and export validated outputs.

Notes & Tips

  • AshES CTI is a self-contained Windows application.
  • No server deployment is required.
  • No telemetry is collected.
  • All normal analysis, viewing, mapping, and exporting workflows run locally.
  • Air-gapped usage is supported when intelligence is manually imported or preloaded.
  • Use the update checker only when the workstation is allowed to access the internet.

Checksums & Verification

SHA-256 checksums are provided with releases where applicable. Digitally signed offline bundles are available on request.

Frequently Asked Questions

Does AshES CTI require internet?
Internet access is only required for live OSINT ingestion, live enrichment, or update checks. Analysis, viewing, exporting, MITRE mapping, and local usage run offline.

Does it send telemetry?
No. AshES CTI does not collect usage telemetry or send customer intelligence data to AshES Cybersecurity.

Is there a server?
No. AshES CTI is a self-contained Windows workstation application.

Do I need special hardware?
No. Any modern Windows 10 / 11 64-bit system is sufficient.

Can AshES CTI be used in air-gapped environments?
Yes. Air-gapped workflows are supported when intelligence is imported, transferred, or preloaded according to the organization’s process.

Support

If you need help installing, activating, or using AshES CTI:
Email: support@ashes-cybersecurity.com

Security & Privacy

AshES CTI is designed for organizations that require local control over threat intelligence workflows. The product prioritizes privacy, data ownership, and operational control over cloud-dependent workflows.

Local Control

Local-First Operation

Threat intelligence data is stored locally on the analyst workstation. Reports, extracted indicators, enrichment results, ATT&CK mappings, rule artifacts, and actor intelligence remain under organizational control.

Restricted Networks

Offline & Air-Gapped Use

AshES CTI supports offline workflows for restricted environments. Organizations can preload intelligence, import files manually, and continue analysis without relying on a cloud-hosted platform.

Privacy

No Telemetry

AshES CTI does not collect analytics, usage metrics, behavioral telemetry, or customer intelligence data. Normal product usage remains local to the organization operating the software.

Ownership

Customer-Controlled Data

Intelligence processed inside AshES CTI remains under the organization’s control. The product is designed for teams that require local retention, privacy, and operational control.

Optional

VirusTotal Enrichment

VirusTotal enrichment is optional and uses the organization’s own API key. No enrichment data is sent to AshES Cybersecurity as part of the enrichment process.

Activation

Cryptographic Licensing

AshES CTI uses cryptographically signed licenses for activation and entitlement validation. Licensing is designed to support both connected and restricted deployment environments.

Note: AshES CTI is intentionally local-first. It is designed for operational cybersecurity teams that cannot rely on cloud-only intelligence workflows.

Use Cases

AshES CTI is built for operational cybersecurity teams that need to transform intelligence into actionable defensive outcomes. The product is most useful when intelligence must support investigations, detection engineering, threat hunting, reporting, or isolated-network operations.

SOC

Security Operations Centers

SOC teams can use AshES CTI to process threat reports, extract indicators, map adversary behavior, review actor context, and export operational intelligence.

  • Review threat reports
  • Inspect extracted IOCs
  • Map activity to ATT&CK
  • Export validated intelligence
CTI

Threat Intelligence Teams

Threat intelligence teams can use AshES CTI to centralize collection, enrich indicators, review threat actor context, and maintain a local intelligence repository.

  • Collect intelligence from supported sources
  • Review actor and malware context
  • Track ATT&CK-linked activity
  • Maintain local intelligence records
Detection

Detection Engineering

Detection engineers can use AshES CTI to connect intelligence with detection workflows by reviewing techniques, procedures, malware associations, and supported rule artifacts.

  • Review ATT&CK techniques
  • Inspect actor procedures
  • Work with YARA, SNORT, and Sigma
  • Support detection validation workflows
Hunting

Threat Hunting

Threat hunters can use actor procedures, malware associations, and ATT&CK mappings to guide investigations around adversary behavior instead of relying only on isolated indicators.

  • Prioritize relevant adversary behaviors
  • Use ATT&CK context for hunting ideas
  • Review actor-linked malware
  • Investigate related indicators
DFIR

DFIR Teams

DFIR teams can use AshES CTI to investigate indicators, identify related malware or actor context, and support incident response investigations.

  • Investigate suspicious indicators
  • Review related adversary context
  • Export investigation artifacts
  • Support reporting workflows
MSSP

Managed Security Providers

MSSPs can use AshES CTI to process intelligence from multiple sources, support customer-facing intelligence workflows, and export intelligence in standard formats.

  • Process intelligence efficiently
  • Review threat actor activity
  • Export STIX, TAXII, CSV, and JSON
  • Support customer reporting
Isolated Networks

Air-Gapped SOC Environments

Organizations operating isolated networks can use AshES CTI to maintain threat intelligence workflows without depending on cloud-hosted platforms.

  • Import intelligence manually
  • Operate without cloud dependency
  • Maintain local intelligence repositories
  • Support restricted environments
Enterprise

Government & Critical Infrastructure

AshES CTI supports environments where data sovereignty, privacy, local control, and offline-capable cybersecurity workflows are operational requirements.

  • Support local data retention
  • Reduce cloud dependency
  • Operate in restricted environments
  • Maintain control over intelligence workflows