Who
Salt Typhoon — a state-linked advanced persistent threat group, active since at least 2019.
Attributed to operators in the People's Republic of China.
A live demonstration of the CyberSOC platform in action.
Tap anywhere to start
Before we launch the attack, here's who's attacking.
Salt Typhoon — a state-linked advanced persistent threat group, active since at least 2019.
Attributed to operators in the People's Republic of China.
Targets telecommunications, government, and edge-network devices — the routers, VPNs, and management systems that knit a country together.
Recent campaigns have hit major US carriers and dozens of countries simultaneously.
They hide in network management infrastructure for months, quietly collecting lawful-intercept data, credentials, and metadata.
Stealth and persistence — not smash-and-grab. A traditional SOC sees nothing until it's far too late.
Three roles, working in concert.
Adversary emulation platform. Runs the simulated attack — the same TTPs a real adversary would use.
AI Level 1 analyst triages alerts. Hands confirmed threats to a human Level 2 analyst. Drives the playbook.
Endpoint detection and SIEM. Where the human analyst sees the work and takes action.
SIMULATING A SALT TYPHOON CAMPAIGN AGAINST
A national telecommunications provider
Press once. Watch the three live screens next to this kiosk and the simulation below unfold together.
A Salt Typhoon campaign, detected, triaged, and contained.
SiberAMAN AI SOAR · powered by CyberSOC