Trusted interface — source-referenced answers for agents and analysts.
Grounded in the whole corpus, not one dataset
The Assistant is retrieval-augmented over RST's own threat feeds, report library, threat actor profiles and enrichment APIs — plus public threat research, in more than one language. Every answer links back to the report it came from, so you check the source instead of taking the sentence on faith.
Answers in seconds
No manual pivoting between tools to build the picture, and no ticket in a queue — the reasoning already ran.
Global by default
Multilingual collection and reporting across industries and regions — not just the loudest English-language headlines.
No dedicated headcount required
The corpus and the reasoning are already built — a mid-market team gets the same answer a Tier-1 SOC does.
Never stale
Grounded in the same corpus that feeds Report Hub, Threat Library and Threat Feed — it doesn't fall behind what the rest of the layer already knows.
The intelligence brain any agent can call
Most “CTI MCP” offerings are thin wrappers exposing one dataset as tool calls, with the reasoning still happening in your ungrounded model. CTI Assistant is grounded in the entire RST corpus and returns source-referenced answers — reachable two ways.
base_url: https://api.rstcloud.net/v1/chat/completions
api_key: <your RST API key>
model: rst-research-1
API & MCP
OpenAI-compatible endpoint or MCP tool calls — grounded, source-referenced answers any agent framework can call directly.
MCP in Claude, Cursor & friends
The same MCP server your agents use also works from Claude Desktop, Cursor, or any MCP-speaking client — grounded CTI answers inside the tools an analyst already has open, not a separate portal.
Slack & Microsoft Teams
A 24x7 virtual CTI analyst where responders already are — source-referenced answers in whatever language the question was asked in, no context-switch at 3 AM.
Your 24x7 virtual CTI analyst, already in Teams
Ask what's targeting your sector this week, what a suspicious IP is doing, or how a piece of malware behaves — and get a source-referenced answer back in the same chat, in the language you asked in.
- Personal, team or group chat — no separate tool to open
- One-time setup: an admin sets your RST API key with
setkeyin a direct message to the bot - Type
helpany time for a refresher on what to ask, orreportto send feedback
See it answer your question, not a demo script.
Bring a real indicator, actor, or sector question to a live session — or start with the Teams bot if your team already lives in chat.
Request a demo