Skip to main content

OpenCTI

Threat intelligence platform for organizing, storing, and visualizing STIX-based knowledge, observables, and threat actors.

Technical Architecture & Overview

OpenCTI is an open-source cyber threat intelligence platform developed and maintained by Filigran. It structures, stores, and organizes technical and non-technical threat information using a STIX 2.1 knowledge graph, with a modern web UI, a GraphQL API, and a connector ecosystem for ingesting, enriching, and exporting intelligence.

Targeted Technical Use Cases

Centralizing structured threat intelligence, correlating IOCs and adversary TTPs, and sharing knowledge across a SOC or CTI team.

Evaluation & Trade-offs

Core Strengths

  • +STIX 2.1 knowledge graph with interactive graph views, relationship inference, and MITRE ATT&CK mapping.
  • +Connector ecosystem for MISP, MITRE ATT&CK, TAXII feeds, CSV, and many other external sources.
  • +Modern web UI with dashboards, reports, and a GraphQL API for automation and third-party integration.

Trade-Offs & Limitations

  • -Multi-service deployment (Elasticsearch, MinIO, RabbitMQ, etc.) requires significant infrastructure and planning.
  • -Advanced AI, automation, and enterprise support features require a paid OpenCTI Enterprise Edition license.

Defensive Security Application

Acts as a central CTI repository to correlate threat data, map adversaries to MITRE ATT&CK, and feed IOCs to detection systems.

Frequently Asked Questions

What is OpenCTI?

OpenCTI is an open-source cyber threat intelligence platform developed and maintained by Filigran. It structures, stores, and organizes technical and non-technical threat information using a STIX 2.1 knowledge graph, with a modern web UI, a GraphQL API, and a connector ecosystem for ingesting, enriching, and exporting intelligence.

What is OpenCTI used for?

Centralizing structured threat intelligence, correlating IOCs and adversary TTPs, and sharing knowledge across a SOC or CTI team.

What are the strengths of OpenCTI?
  • +STIX 2.1 knowledge graph with interactive graph views, relationship inference, and MITRE ATT&CK mapping.
  • +Connector ecosystem for MISP, MITRE ATT&CK, TAXII feeds, CSV, and many other external sources.
  • +Modern web UI with dashboards, reports, and a GraphQL API for automation and third-party integration.
What are the limitations of OpenCTI?
  • +Multi-service deployment (Elasticsearch, MinIO, RabbitMQ, etc.) requires significant infrastructure and planning.
  • +Advanced AI, automation, and enterprise support features require a paid OpenCTI Enterprise Edition license.
How is OpenCTI used defensively?

Acts as a central CTI repository to correlate threat data, map adversaries to MITRE ATT&CK, and feed IOCs to detection systems.