Filigran and CheckFirst Bring the Pravda Network into OpenCTI
Structured, real-time FIMI intelligence is now directly accessible inside your threat intelligence platform.
State actors don’t choose between hacking and influencing. They do both, often with the same infrastructure, the same funding, and the same strategic objectives. The Pravda network is a textbook example: a large-scale, state-sponsored disinformation apparatus that public reporting has linked to Russian state interests. Its operational fingerprints also show overlaps with cyber espionage activity attributed in public reporting to units associated with FSB’s 16th Centre and the GRU’s Information Operations Troops.
Shared hosting, coordinated domain registration, and bot networks aren’t coincidences. They’re patterns, and patterns can be tracked.
OpenCTI was built with this reality in mind. We designed it to handle not just traditional Cyber Threat Intelligence (CTI), but the full spectrum of hybrid threats, including Foreign Information Manipulation and Interference (FIMI), meaning coordinated efforts to manipulate information environments at scale.
STIX 2.1, the structured data standard at the heart of OpenCTI, provides a common language to model, correlate, and enrich both cyber and information threats within a single knowledge graph. VIGINUM’s April 2025 doctrine formally recognized this, explicitly recommending OpenCTI as a platform for capitalizing on information threat knowledge.
Today, we’re taking that capability a step further. We’re announcing our partnership with CheckFirst, a specialist in online information integrity, to bring the Pravda Network Feed directly into OpenCTI through a dedicated import connector.
TL;DR
- Filigran and CheckFirst are bringing the Pravda Network Feed into OpenCTI via a dedicated import connector.
- The connector makes structured, real-time FIMI intelligence searchable and linkable inside the same knowledge graph as your cyber threat intelligence.
- CheckFirst’s dataset covers more than 7 million Pravda network articles, with daily updates as new content is detected and ingested.
- In OpenCTI, this content can be correlated with infrastructure, campaigns, and threat actors to support investigation, attribution, and detection workflows.
- The feed is offered as an annual subscription with tiered pricing, including historical access, daily updates, documentation, and support.
What the CheckFirst Connector Delivers
CheckFirst has built one of the most comprehensive databases of Pravda network activity in existence: more than 7 million articles published since the network’s inception, continuously updated as new content is detected and ingested daily. Through the CheckFirst Import Connector, this dataset becomes accessible inside OpenCTI, structured, searchable, and ready to be correlated with the rest of your threat intelligence.
Each article is modeled according to best practices for threat knowledge representation, making the data immediately usable for investigations, attribution work, and detection. The connector handles API authentication, pagination, state persistence, and batch ingestion automatically, so analysts can focus on the intelligence rather than the technical overhead.
The feed is available on an annual subscription basis, with tiered pricing adapted to the nature of the client. All tiers include full access to the historical archive, daily updates, the OpenCTI connector with technical documentation, and email-based technical support.

For pricing and access, contact Filigran.
Why This Partnership Matters
Effective threat intelligence requires context. An IP address without a campaign, a campaign without an actor, an actor without a broader strategic picture: each step removed from context reduces an analyst’s ability to act.
The same logic applies to FIMI. A Pravda article analyzed in isolation, without its network relationships, infrastructure overlaps, and connections to broader activity, tells only part of the story.
By connecting CheckFirst’s Pravda Network Feed to OpenCTI, defenders can work with a richer, more complete picture of hybrid threat activity directly inside the platform where they already investigate, correlate, and share intelligence. Specialized expertise, made interoperable, at operational scale.

Conclusion
Hybrid threats don’t respect organizational boundaries, and analysts shouldn’t have to switch tools to follow the thread. With the CheckFirst Import Connector, the Pravda Network Feed becomes first-class intelligence inside OpenCTI: structured, queryable, and ready to correlate with the cyber data you already rely on.
If you want to evaluate the feed, discuss the right tier, or see how this connector fits into your existing OpenCTI workflows, contact us now.
Enjoy and feel free to ask any questions about it on our Slack community channel !
About CheckFirst
Founded in 2020, CheckFirst is committed to protecting the online information landscape from online harms. Through tailored products and services.
About Filigran
Filigran, a cybersecurity company, delivers a unique open-source, threat-informed approach to Continuous Threat Exposure Management (CTEM). Underpinned by an agentic foundation, Filigran’s eXtended Threat Management (XTM) platform delivers proactive security by combining threat intelligence, exposure validation, and cyber risk quantification. The platform includes OpenCTI, OpenAEV, XTMOne and OpenGRC (forthcoming).
Read more
Explore related topics and insights