Charlotte AI is a security-based generative AI assistant that helps users of all skill levels improve and streamline their ability to stop breaches while reducing security operations complexity.
Start new conversation/new
Promptbooks
Recent promptbooks
See all promptbooks/promptbook
Recent promptbooks
Adversary Check
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Adversary Summary
Get information about adversaries based on their target countries and sectors, their motivations, and countries of origin to maintain situational awareness.
Zero-day vulnerability
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts.
Back
Back
Example prompts
Which adversaries target the financial sector?What tactics does SILENT CHOLLIMA use?What are the top ten hosts with high severity detections?What is my exposure to critical vulnerabilities?Which hosts have TeamViewer installed?
Capabilities
Charlotte AI provides intuitive, real-time responses to plain English prompts. Charlotte AI simplifies the process of determining risks and malicious activity in your environment and reduces the need to manually review and filter through large amounts of data.
Limitations
Generative AI does not have the capacity for common sense or critical thinking. It is crucial that Charlotte AI always be used in conjunction with human judgment.
Filtered by: Target industries is Financial Services
SearchClear all
Name
Last activity
Status
First activity
Known as
Motivations
Target countries
Target industries
SCION SPIDER
May 2, 2025
Active
Nov. 21, 2021
--
Criminal
Italy,United A...
Government,...
FAMOUS CH...
Mar. 26, 2025
Active
Jul. 2, 2018
Wagemole, C...
State-Sponso...
Costa Rica,Ira...
Insurance,Tel...
SLY SPIDER
Feb. 19, 2025
Active
Jul. 1, 2020
--
Criminal
Malaysia,Phili...
Government,T...
CASCADE PA...
Apr. 5, 2025
Active
Oct. 30, 2020
LuoYu, Storm...
State-Sponso...
United States,...
Chemicals,Fin...
MASKED SPI...
Mar. 30, 2025
Active
Apr. 30, 2022
BianLian
Criminal
Venezuela,Au...
Aviation,Medi...
VETO SPIDER
Feb. 14, 2025
Active
Jul. 15, 2022
nixploiter
Criminal
United States,...
Media,Insuran...
SLIPPY SPID...
May 31, 2022
Inactive
Jun. 1, 2021
Lapsus$ Grou...
Criminal
Portugal,Sout...
Technology,A...
VICE SPIDER
Apr. 23, 2025
Active
May 1, 2021
DEV-0832, Va...
Criminal
Dominican Re...
Local Govern...
PERCUSSION...
Oct. 14, 2024
Active
Apr. 30, 2020
drumrlu, 3lv4...
Criminal
Iraq,Venezuel...
Social Media,...
NIGHT SPIDER
Mar. 28, 2022
Inactive
May 31, 2015
Silent Night, ...
Criminal
--
Financial Serv...
138 results (1-10 shown) Items per page Page 1 of 14 ‹›
Generating summary
Generating summary
Summary
How was this generated?
Charlotte AI queries the Intel API 'QueryActors' for actors targeting the 'Financial Services' industry (target_industries:'Financial Services'). Show response details
Adversaries targeting the financial sector include a total of 138 actors.
Key findings among these actors reveal that the majority originate from Europe, Eastern Europe, and the Russian Federation. Their primary motivations are criminal activities, followed by state-sponsored actions and hacktivism. The most common capabilities employed by these actors include ransomware, remote access tools (RATs), and downloaders. The actors are predominantly involved in eCrime and targeted attacks. The United States, United Kingdom, and Germany are the top countries targeted by these adversaries.
T1078 Valid AccountsContractor accounts are not currently monitored for anomalous first use.No coverage
Execution
2 techniques
PowerShell
T1059.001
T1059.001 PowerShellEncoded PowerShell observed on SE-JAR-WIN10-BL, 11:21 on May 7.Observed here
Windows Management Instrumentation
T1047
T1047 Windows Management InstrumentationCovered by process lineage rules. Not seen in your environment.Covered, not seen
Persistence
2 techniques
Scheduled Task
T1053.005
T1053.005 Scheduled TaskTask created under a service account on two hosts.Observed here
Registry Run Keys
T1547.001
T1547.001 Registry Run KeysCovered by registry monitoring. Not seen in your environment.Covered, not seen
Defense Evasion
3 techniques
Obfuscated Files
T1027
T1027 Obfuscated FilesBase64-layered payload matched on the same two hosts.Observed here
Indicator Removal
T1070.004
T1070.004 Indicator RemovalCovered by file deletion telemetry. Not seen.Covered, not seen
Masquerading
T1036.005
T1036.005 MasqueradingCovered by binary name and path checks. Not seen.Covered, not seen
Credential Access
2 techniques · 1 gap
OS Credential Dumping
T1003.001
T1003.001 OS Credential DumpingLSASS access attempt blocked on SE-JAR-WIN10-BL.Observed here
Input Capture
T1056.001
T1056.001 Input CaptureNo keylogging detection on contractor-managed endpoints.No coverage
Command and Control
2 techniques
Web Protocols
T1071.001
T1071.001 Web ProtocolsBeaconing to two domains at fixed 300s intervals.Observed here
Encrypted Channel
T1573.002
T1573.002 Encrypted ChannelCovered by TLS metadata inspection. Not seen.Covered, not seen
Exfiltration
2 techniques · 1 gap
Exfiltration Over C2
T1041
T1041 Exfiltration Over C2Covered by outbound volume baselines. Not seen.Covered, not seen
Transfer to Cloud Account
T1537
T1537 Transfer to Cloud AccountNo monitoring for uploads to unsanctioned cloud storage.No coverage
4 techniques have no detection coverage
Two of the four sit in Initial Access, both involving third parties — compromised software updates and contractor accounts being used for the first time. That is the same route this adversary took into your environment in May.
Summary
SILENT CHOLLIMA is a state-sponsored adversary attributed to North Korea, active against 19 industries and 22 countries. Falcon has 16 techniques mapped to this actor across 7 ATT&CK tactics.
6 of those techniques have been observed in your environment, all between May 4 and May 7, and all tracing back to a single spearphishing attachment opened by a contractor. The activity progressed as far as a blocked credential dumping attempt on SE-JAR-WIN10-BL before it stopped.
You have detection coverage for 12 of the 16 techniques. The 4 gaps are concentrated in how this adversary gets in and how it takes data out. Closing the two Initial Access gaps would give you coverage of the specific route used against you in May.
Was this response useful?
This recreation has two fully-built example responses. Try asking: "Which adversaries target the financial sector?" or "What tactics does SILENT CHOLLIMA use?"
Start new conversation/new
Promptbooks
Recent promptbooks
See all promptbooks/promptbook
Recent promptbooks
Adversary Check
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Adversary Summary
Get information about adversaries based on their target countries and sectors, their motivations, and countries of origin to maintain situational awareness.
Zero-day vulnerability
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts.
Back
Back
Charlotte AI|Charlotte AI audit
Search
Charlotte AI
_Talon 1
Charlotte AI audit logs
512,078 items
Created Date
Run by
Prompt
Conversation ID
Message ID
Quota used
512,078 results (1-20 shown)Items per pagePage 1 of 25,604
Charlotte AI|Detection triage dashboard
Search
Charlotte AI
_Talon 1
Total detections triaged by Charlotte AI
324
Average triage time per detection
3min 29sec
Time saved
Each triage with a verdict saves an average of 5 minutes
1,620min
Total triaged detections by verdicts
2,784
true_positiveNo verdictfalse_positive
Last refreshed: 14:29:34
Average triage time
30 days
Most recent triaged detections
Severity
Outcome
Outcome confidence
Time
Status
Link
Charlotte AI|Promptbooks
Search
Charlotte AI
_Talon 1
Start new conversation
View promptbooks
Conversation history
Today
Which adversaries target the financi…
Last 30 days
Investigate incident f824f0ef8630…
check if firefox is installed in my en…
Investigate incident a555170fe0a74…
Load more
Promptbooks
CrowdStrike
Organization
Personal
Advanced Event Search Query
Generate a CrowdStrike Query Language (CQL) query for your endpoint data from a plain English prompt
Adversary Summary
Get information about adversaries based on their target countries and sectors, their motivations, and countries of origin to maintain situational awareness
Last run: Mar. 26, 2025 08:18:11
Indicator Hunt
Look for connections to an IP address or domain by hosts in your environment
Intel Reports
Ask a question and get a cited answer drawn from Falcon Adversary Intelligence reporting
Live Asset Query
Generate a live asset query to run on your Falcon for IT-enabled endpoints
Sensor Deployment
Get guidance on how to deploy the Falcon sensor on different platforms
Zero-day vulnerability
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts
Last run: Nov. 21, 2024 09:03:32
Actors Test
Actors Test - for end to end tests
[Copy of] Detection Summary
Detection Details and Remediation
Detection Summary
Detection Triage
Hunt the Adversary
Get information about adversaries based on their target countries and sectors, motivations, countries of origin, and prevalence in your environment to maintain situational awareness.
Resilience Tabletop
Understand PE execution
Zero-day vulnerability - Org
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts
Adversary Check
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Last run: Jan. 9, 2025 11:35:27
Charlotte AI|Promptbooks›Adversary Check
Search
Charlotte AI
_Talon 1
Start new conversation
View promptbooks
Conversation history
Today
Which adversaries target the financi…
Last 30 days
Investigate incident f824f0ef8630…
check if firefox is installed in my en…
Investigate incident a555170fe0a74…
Load more
Adversary Check
Description
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Created by
Natalie Greco
Created on
Jan. 7, 2025 12:59:23
Last edited
Jan. 13, 2025 09:32:02
Prompts required
5
Permissions
Personal
Parameters
Parameter 1
Origin Country
Parameter 2
Target Country
Parameter 3
Motivation
Parameter 4
Sector
Steps
Step 1/5
Are there any actors in my environment?
Step 2/5
Are any of them based in [Origin Country]?
Step 3/5
Do any target [Target Country]?
Step 4/5
Are they motivated by [Motivation]?
Step 5/5
Do any target the [Sector]?
Go to all promptbooks
Charlotte AI|Promptbooks›Promptbooks
Search
Charlotte AI
_Talon 1
Start new conversation
View promptbooks
Conversation history
Today
Which adversaries target the financi…
Last 30 days
Investigate incident f824f0ef8630…
check if firefox is installed in my en…
Investigate incident a555170fe0a74…
Load more
Adversary Check(Go to detail page) ↗
Parameters
Origin Country
Target Country
Motivation
Sector
Steps
Step 1/5
Are there any actors in my environment?
Step 2/5
Are any of them based in [Origin Country]?
Step 3/5
Do any target [Target Country]?
Step 4/5
Are they motivated by [Motivation]?
Step 5/5
Do any target the [Sector]?
Requires 5 prompts to run promptbook
Cancel
Charlotte AI|Conversations›Adversary Check
Search
Charlotte AI
_Talon 1
Start new conversation
View promptbooks
Conversation history
Today
Adversary Check
Which adversaries target the financi…
Last 30 days
Investigate incident f824f0ef8630…
check if firefox is installed in my en…
Investigate incident a555170fe0a74…
Load more
Adversary Check
(detail page)
Steps completed: 0/5
Cancel queued steps
Jan. 7, 2025 12:59:23
Are there any actors in my environment?
Step 1/5Generating
May 7, 2025 11:28:06
Consulting Falcon
Detections
Filtered by: Adversary ids is not null
Severity
Detect time
Process on host
Hostname
User name
Status
Today, May 7, 2025
High
11:21:45
nslookup.exe on SE-JAR-WI...
SE-JAR-...
demo
New
High
11:21:45
PING.EXE on SE-JAR-WI...
SE-JAR-...
demo
New
High
09:43:52
PING.EXE on SE-JAR-WI...
SE-JAR-...
demo
New
May 6, 2025
High
13:49:31
PING.EXE on SE-JSE-WI...
SE-JSE-...
demo
New
20 results (1-10 shown)Page 1 of 2 ‹›
Summary
Yes.
The majority of detections are currently in a "new" status. The most affected device hostname is SE-JAR-WIN10-BL. In terms of triage outcomes, most detections are still awaiting review.
Are any of them based in Origin Country?
Step 2/5Queued
Consulting Falcon
Do any target Target Country?
Step 3/5Queued
Consulting Falcon
Are they motivated by Motivation?
Step 4/5Queued
Consulting Falcon
Do any target the Sector?
Step 5/5Queued
Consulting Falcon
Start new conversation/new
Promptbooks
Recent promptbooks
See all promptbooks/promptbook
Recent promptbooks
Adversary Check
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Adversary Summary
Get information about adversaries based on their target countries and sectors, their motivations, and countries of origin to maintain situational awareness.
Zero-day vulnerability
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts.
Filtered by: FAMOUS CHOLLIMA, Sorted by: Alphabetical
<ColumnLabel>
<ColumnLabel>
<ColumnLabel>
<ColumnLabel>
<ColumnLabel>
<ColumnLabel>
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Text
Was this response useful?
This recreation focuses on one fully-built example response. Try asking: "What tactics does Famous Chollima use?"
Start new conversation/new
Promptbooks
Recent promptbooks
See all promptbooks/promptbook
Recent promptbooks
Adversary Check
Check my environment for adversaries and, if found, brief me on countries of origin, along with target countries, sectors, and motivations.
Adversary Summary
Get information about adversaries based on their target countries and sectors, their motivations, and countries of origin to maintain situational awareness.
Zero-day vulnerability
Get information about a new vulnerability, your exposure, and anomalous behavior on vulnerable hosts.