AshES CTI is a Windows-native, offline-first threat intelligence workstation for SOC, DFIR, detection engineering, threat hunting, and air-gapped environments.
AshES CTI is designed to keep deployment simple. No servers, no cloud accounts, and no external platform setup are required. Install the application, activate the license, and begin working from the local workstation.
Download AshES CTI from the official product page:
https://ashes-cybersecurity.com/ashescti/
On first launch, AshES CTI displays a license activation window.
Run from PowerShell or Command Prompt:
ashes-ti.exe ingest-yesterday-only
ashes-ti.exe enrich-iocs
ashes-ti.exe ioc-add
ashes-ti.exe --help
ashes-ti.exe --version
SHA-256 checksums are provided with releases where applicable. Digitally signed offline bundles are available on request.
Does AshES CTI require internet?
Internet access is only required for live OSINT ingestion, live enrichment,
or update checks. Analysis, viewing, exporting, MITRE mapping, and local usage
run offline.
Does it send telemetry?
No. AshES CTI does not collect usage telemetry or send customer intelligence
data to AshES Cybersecurity.
Is there a server?
No. AshES CTI is a self-contained Windows workstation application.
Do I need special hardware?
No. Any modern Windows 10 / 11 64-bit system is sufficient.
Can AshES CTI be used in air-gapped environments?
Yes. Air-gapped workflows are supported when intelligence is imported,
transferred, or preloaded according to the organization’s process.
If you need help installing, activating, or using AshES CTI:
Email: support@ashes-cybersecurity.com
AshES CTI is designed for organizations that require local control over threat intelligence workflows. The product prioritizes privacy, data ownership, and operational control over cloud-dependent workflows.
Threat intelligence data is stored locally on the analyst workstation. Reports, extracted indicators, enrichment results, ATT&CK mappings, rule artifacts, and actor intelligence remain under organizational control.
AshES CTI supports offline workflows for restricted environments. Organizations can preload intelligence, import files manually, and continue analysis without relying on a cloud-hosted platform.
AshES CTI does not collect analytics, usage metrics, behavioral telemetry, or customer intelligence data. Normal product usage remains local to the organization operating the software.
Intelligence processed inside AshES CTI remains under the organization’s control. The product is designed for teams that require local retention, privacy, and operational control.
VirusTotal enrichment is optional and uses the organization’s own API key. No enrichment data is sent to AshES Cybersecurity as part of the enrichment process.
AshES CTI uses cryptographically signed licenses for activation and entitlement validation. Licensing is designed to support both connected and restricted deployment environments.
AshES CTI is built for operational cybersecurity teams that need to transform intelligence into actionable defensive outcomes. The product is most useful when intelligence must support investigations, detection engineering, threat hunting, reporting, or isolated-network operations.
SOC teams can use AshES CTI to process threat reports, extract indicators, map adversary behavior, review actor context, and export operational intelligence.
Threat intelligence teams can use AshES CTI to centralize collection, enrich indicators, review threat actor context, and maintain a local intelligence repository.
Detection engineers can use AshES CTI to connect intelligence with detection workflows by reviewing techniques, procedures, malware associations, and supported rule artifacts.
Threat hunters can use actor procedures, malware associations, and ATT&CK mappings to guide investigations around adversary behavior instead of relying only on isolated indicators.
DFIR teams can use AshES CTI to investigate indicators, identify related malware or actor context, and support incident response investigations.
MSSPs can use AshES CTI to process intelligence from multiple sources, support customer-facing intelligence workflows, and export intelligence in standard formats.
Organizations operating isolated networks can use AshES CTI to maintain threat intelligence workflows without depending on cloud-hosted platforms.
AshES CTI supports environments where data sovereignty, privacy, local control, and offline-capable cybersecurity workflows are operational requirements.