OpenCTI
Threat intelligence platform for organizing, storing, and visualizing STIX-based knowledge, observables, and threat actors.
Technical Architecture & Overview
OpenCTI is an open-source cyber threat intelligence platform developed and maintained by Filigran. It structures, stores, and organizes technical and non-technical threat information using a STIX 2.1 knowledge graph, with a modern web UI, a GraphQL API, and a connector ecosystem for ingesting, enriching, and exporting intelligence.
Targeted Technical Use Cases
Centralizing structured threat intelligence, correlating IOCs and adversary TTPs, and sharing knowledge across a SOC or CTI team.
Evaluation & Trade-offs
Core Strengths
- +STIX 2.1 knowledge graph with interactive graph views, relationship inference, and MITRE ATT&CK mapping.
- +Connector ecosystem for MISP, MITRE ATT&CK, TAXII feeds, CSV, and many other external sources.
- +Modern web UI with dashboards, reports, and a GraphQL API for automation and third-party integration.
Trade-Offs & Limitations
- -Multi-service deployment (Elasticsearch, MinIO, RabbitMQ, etc.) requires significant infrastructure and planning.
- -Advanced AI, automation, and enterprise support features require a paid OpenCTI Enterprise Edition license.
Defensive Security Application
Acts as a central CTI repository to correlate threat data, map adversaries to MITRE ATT&CK, and feed IOCs to detection systems.
Frequently Asked Questions
What is OpenCTI?→
OpenCTI is an open-source cyber threat intelligence platform developed and maintained by Filigran. It structures, stores, and organizes technical and non-technical threat information using a STIX 2.1 knowledge graph, with a modern web UI, a GraphQL API, and a connector ecosystem for ingesting, enriching, and exporting intelligence.
What is OpenCTI used for?→
Centralizing structured threat intelligence, correlating IOCs and adversary TTPs, and sharing knowledge across a SOC or CTI team.
What are the strengths of OpenCTI?→
- +STIX 2.1 knowledge graph with interactive graph views, relationship inference, and MITRE ATT&CK mapping.
- +Connector ecosystem for MISP, MITRE ATT&CK, TAXII feeds, CSV, and many other external sources.
- +Modern web UI with dashboards, reports, and a GraphQL API for automation and third-party integration.
What are the limitations of OpenCTI?→
- +Multi-service deployment (Elasticsearch, MinIO, RabbitMQ, etc.) requires significant infrastructure and planning.
- +Advanced AI, automation, and enterprise support features require a paid OpenCTI Enterprise Edition license.
How is OpenCTI used defensively?→
Acts as a central CTI repository to correlate threat data, map adversaries to MITRE ATT&CK, and feed IOCs to detection systems.