
Threat Intelligence
OpenCTI
Open-source CTI platform to unify, operationalize, and prioritize threat intel in SecOps.
OpenCTI Overview
What it does
OpenCTI is an open-source threat intelligence platform that structures, stores, and operationalizes cyber threat knowledge at tactical, operational, and strategic levels using a Structured Threat Information Expression (STIX) 2.1 schema. The platform links technical observables and non-technical context such as attribution and victimology to primary sources with confidence scoring, relationship mapping, and timeline visualization across a STIX-structured knowledge hypergraph with MITRE ATT&CK mappings.
How it works
The platform ingests intelligence through 300+ one-click connectors, a TAXII 2.1 server, and RSS, CSV, and JSON feeds, normalizes everything into STIX 2.1, and deduplicates overlapping objects while decay rules age indicator scores. Enterprise Edition adds Priority Intelligence Requirements (PIRs), a one-click Playbook Library for enrichment and routing automation, FINTEL report templates, case management, and multi-organization data segregation. XTM One, an agentic AI layer released in June 2026, runs agents for threat hunting, dashboard creation, and detection-rule conversion, and the Filigran Browser Extension turns web pages into structured reports. OpenCTI is also sold through the AWS and Microsoft Azure Marketplaces.
Credentials and traction
Filigran holds SOC 2 Type II and ISO 27001:2022 certifications. OpenCTI was named an Outperformer and Challenger in the 2026 GigaOm Radar for Threat Intelligence Platforms, and the Filigran XTM platform won The Hacker News Cybersecurity Stars Award for Best Intelligence-Powered Cybersecurity Platform in 2026. Filigran joined French Tech 120 in 2025. The platform is used by 6,000+ public and private organizations, including the FBI and the European Commission, with named customers including Rivian, ClearDATA, Controlware, ASRG, and Intrinsec.
Key Capabilities
mapped to solution categoriesProvides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.
Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.
Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.
Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.
Auto-generates detection rules and syntax for SIEM, firewalls, IPS or IDS and EDR.
Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.
Produces finished intelligence reports at technical, operational and strategic levels.
Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.
Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.
Profiles threat actors with associated TTPs and attribution context.
Lets analysts define PIRs as criteria and filters, then continuously scores and surfaces entities of interest from the knowledge base against them.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with OpenCTI
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.