Threat IntelligenceOpen-Source Threat IntelligenceeXtended Threat Management (XTM)

Open-source threat intelligence platform for structured knowledge management, correlation, and collaborative TI sharing.

OpenCTI featured image

Product Overview

AI-Powered
40 Integrations
2 Certifications

OpenCTI is an open-source threat intelligence platform that enables organizations to manage cyber threat intelligence knowledge and observables at tactical, operational, and strategic levels through a Structured Threat Information Expression (STIX) 2.1-based knowledge schema. The platform structures, stores, organizes, and visualizes both technical information like Tactics, Techniques, and Procedures (TTPs) and non-technical information like attribution and victimology, linking each piece of intelligence to its primary source with confidence levels, first and last seen dates, and relationship mapping between data points for comprehensive threat context.

OpenCTI provides 300+ modular connectors that automatically import and enrich threat intelligence from multiple sources including CrowdStrike, SentinelOne, Sekoia, MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK), and Malware Information Sharing Platform (MISP) in a unified interface, enabling Security Operations Center (SOC) teams to conduct intelligence-driven security operations with automated workflows and collaborative sharing. The platform integrates artificial intelligence (AI) for threat feed imports, search functionality, generating insights and summaries, and creating finished intelligence reports through templates, while serving as the foundation for Filigran's eXtended Threat Management (XTM) suite alongside OpenBAS breach and attack simulation platform for proactive threat validation and testing across the entire threat management lifecycle.

Founded in 2022 by Samuel Hassine (CEO, former France Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) and Tanium executive) and Julien Richard (CTO, former Axway engineering leader), Filigran has raised $60M across three funding rounds led by Insight Partners, Accel, and Moonfire Ventures, growing to 160 employees serving 6,000+ organizations including Airbus, Thales, Marriott, Hermès, Rivian, the Federal Bureau of Investigation (FBI), European Commission, and New York City (NYC) Cyber Command. With 10 million+ downloads, 4,300+ GitHub contributors, and International Organization for Standardization (ISO) 27001 and System and Organization Controls (SOC) 2 certifications, OpenCTI has become the leading community-driven threat intelligence platform with both free Apache 2.0-licensed Community Edition and managed Enterprise Edition offering advanced automation, AI features, and comprehensive support.

Product Details

Security Domain

Security category

Threat Intelligence

Key Capabilities

Specific security problems this product solves

eXtended Threat Management (XTM)Open-Source Threat Intelligence

Key Features

Core capabilities and differentiators

AI-Powered SearchAI-Powered Threat Intelligence SummariesAutomated Data EnrichmentAutomated Finished Intelligence ReportsAutomated Workflow EngineCase ManagementCollaborative Intelligence SharingConfidence Scoring SystemCustom DashboardsData DeduplicationData SegregationGraphQL APIIncident Response IntegrationKnowledge Graph VisualizationMITRE ATT&CK MappingMulti-Source Threat Feed AggregationMulti-Tenancy SupportReal-Time Live StreamsRelationship MappingReport GenerationRole-Based Access Control (RBAC)Role-Based SharingRSS Feed IngestionSTIX 2.1 Native SupportTAXII 2.1 ServerThreat Actor ProfilingThreat Correlation EngineThreat Data CollectionTimeline VisualizationTTP AnalysisUser Activity TrackingVictimology AnalysisVisual Threat GraphsXTM Suite Integration

Compliance & Certifications

Regulatory frameworks and security certifications

ISO 27001SOC 2

Integrations

Compatible tools and platforms

AlienVault OTXAnomaliArctic WolfAtosCrowdStrikeCVECyber Threat CoalitionDeepwatchDeloitteEclecticIQElasticExabeamFortinetIBM QRadarIBM X-ForceIntrinsecKasperskyLogRhythmMaltiverseMalwareBazaarMISPMITRE ATT&CKOrange CyberdefensePalo Alto NetworksProofpointRecorded FutureRiskIQSekoiaSentinelOneShodanSlackSplunkTaniumTheHiveThreat FoxThreatConnectThreatQVirusTotalWavestoneWazuh

Deployment Options

Where and how this solution can be deployed

CloudOn-PremiseSaaS

Support Channels

Available support and communication options

24/7 Enterprise SupportCommunity ForumCommunity SlackCustomer Success TeamDocumentationEmail SupportGitHub IssuesProfessional ServicesTechnical Account ManagementTraining Programs

Pricing Model

How this solution is priced

Open SourceSubscription

Vendor Information

Filigran logo

Filigran

Paris, France