Security Stack Logo
OpenCTI logo

Threat Intelligence

OpenCTI

Open-source CTI platform to unify, operationalize, and prioritize threat intel in SecOps.

OpenCTI Overview

What it does

OpenCTI is an open-source threat intelligence platform that structures, stores, and operationalizes cyber threat knowledge at tactical, operational, and strategic levels using a Structured Threat Information Expression (STIX) 2.1 schema. The platform links technical observables and non-technical context such as attribution and victimology to primary sources with confidence scoring, relationship mapping, and timeline visualization across a STIX-structured knowledge hypergraph with MITRE ATT&CK mappings.

How it works

The platform ingests intelligence through 300+ one-click connectors, a TAXII 2.1 server, and RSS, CSV, and JSON feeds, normalizes everything into STIX 2.1, and deduplicates overlapping objects while decay rules age indicator scores. Enterprise Edition adds Priority Intelligence Requirements (PIRs), a one-click Playbook Library for enrichment and routing automation, FINTEL report templates, case management, and multi-organization data segregation. XTM One, an agentic AI layer released in June 2026, runs agents for threat hunting, dashboard creation, and detection-rule conversion, and the Filigran Browser Extension turns web pages into structured reports. OpenCTI is also sold through the AWS and Microsoft Azure Marketplaces.

Credentials and traction

Filigran holds SOC 2 Type II and ISO 27001:2022 certifications. OpenCTI was named an Outperformer and Challenger in the 2026 GigaOm Radar for Threat Intelligence Platforms, and the Filigran XTM platform won The Hacker News Cybersecurity Stars Award for Best Intelligence-Powered Cybersecurity Platform in 2026. Filigran joined French Tech 120 in 2025. The platform is used by 6,000+ public and private organizations, including the FBI and the European Commission, with named customers including Rivian, ClearDATA, Controlware, ASRG, and Intrinsec.

Key Capabilities

mapped to solution categories
Cyberthreat Intelligence Technologies

Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.

Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.

Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.

Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.

Auto-generates detection rules and syntax for SIEM, firewalls, IPS or IDS and EDR.

Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.

Produces finished intelligence reports at technical, operational and strategic levels.

Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.

Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.

Profiles threat actors with associated TTPs and attribution context.

Lets analysts define PIRs as criteria and filters, then continuously scores and surfaces entities of interest from the knowledge base against them.

Compliance

certifications
ISO 27001SOC 2 Type II

Integrations

compatible tools
AbuseIPDBAccenture ACTIAkamaiAlienVault OTXAnomaliANY.RUNArcSightArctic WolfAtosCensysChronicleCISA Known Exploited VulnerabilitiesCitalidCloudflareCofenseCrowdSecCrowdStrikeCTM360CVECybelAngelCyber Threat CoalitionCybersixgillDatadogDeepwatchDeloitteDragosEclecticIQElasticElastic SecurityEPSSESETExabeamFeedlyFlareFlashpointFortinetFortinet FortiSIEMGoogle SecOpsGoogle Threat IntelligenceGreyNoiseGroup-IBHarfangLabHybrid AnalysisIBM QRadarIBM X-ForceInfobloxIntel 471IntezerIntrinsecJiraJoe SandboxKasperskyLogRhythmMalpediaMaltiverseMalwareBazaarMandiantMicrosoft DefenderMicrosoft SentinelMISPMITRE ATT&CKOrange CyberdefensePalo Alto Cortex XSOARPalo Alto NetworksPalo Alto WildFireProofpointQualysRecorded FutureReversingLabsRiskIQSekoiaSentinelOneServiceNowShadowserverShodanSigmaHQSilobreakerSlackSOCRadarSplunkSplunk SOARSpyCloudSumo LogicSwimlaneTaniumTeam CymruTeamT5TenableTheHiveThreat FoxThreatConnectThreatQTrellixURLhausurlscan.ioVectra AIVirusTotalVMRayVulnCheckWavestoneWazuhWizZeroFoxZscaler

Implementation & support

Deployment model
Air-GappedCloudOn-PremisesPrivate CloudSaaS
Support channels
24/7 SupportCommunity ForumCustomer Success Manager (CSM)Customer Success TeamDocumentationEmail SupportSlack (Customer Channel)Technical Account Manager (TAM)Ticketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

Start a shortlist with OpenCTI

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.