Agentic AI
CTEM

Filigran Named Outperformer in 2026 GigaOm Threat Intelligence Radar

Jul 1, 2026 8 min read

Filigran has been recognized as an Outperformer and Challenger in GigaOm’s 2026 Radar for Threat Intelligence Platforms (TIP), validating OpenCTI’s rapid pace of innovation and its position as a leading open-source, agentic threat intelligence platform. Out of the 13 leading TIPs evaluated, Filigran is one of only a handful to receive the Outperformer designation, a distinction reserved for vendors who demonstrated an exceptional rate of technology development and innovation over the past year.

We did not earn this by standing still. We earned it by continuously investing in our platform, listening to our customers, and delivering on our promises. This blog breaks down what the recognition means, what GigaOm evaluated, where OpenCTI excels, and where we’re headed next. Whether you’re a current customer, evaluating TIP vendors, or just following the threat intelligence space, this one’s worth a read.


TL;DR

  • GigaOm named Filigran an Outperformer in its Threat Intelligence Platforms Radar v3, one of the few vendors to earn the designation, recognizing outstanding pace of innovation.
  • Two milestones drove the recognition: the ongoing expansion of OpenCTI’s integration ecosystem to nearly 300 no-code connectors, and the launch of XTM One, Filigran’s agentic AI layer for automated enrichment, summarization, and reporting.
  • OpenCTI also performed strongly across key evaluation criteria: (1) our wide set of integrations across feeds, security, and enrichment tools, (2) our visual graph analysis and MITRE ATT&CK mapping, and (3) our automation capabilities including low-code workflows, customizable taxonomies, and automated actions across downstream systems.
  • Flexible deployment and transparent pricing: full feature parity across SaaS, on-premises, air-gapped, and hybrid models; priced per instance with no user limits, no feature tiers, and no hidden fees.

The Market Has a Direction. We’re Building Toward It.

Here’s the thing about most threat intelligence platforms: they have a data problem. They’re extraordinarily good at collecting threat data, normalizing it, storing it, and presenting it in dashboards that look impressive in vendor demos. What they’re considerably less good at is turning that data into something a security team can actually act on: quickly, reliably, and without an army of integrators and professional services consultants to make it work.

The GigaOm report is upfront about the state of the threat intelligence platform market, and it’s worth taking seriously. The analyst’s core argument is this: the category has moved, decisively and irreversibly, from data aggregation to actionable intelligence. Platforms that still think their job is to collect and store indicators are already behind. The expectation today is automation, correlation, workflow integration, and measurable impact on security outcomes.

We agree. In fact, we’ve already been successfully building towards this for some time. The GigaOm Outperformer designation is great validation that we’re moving in the right direction, fast.

Actionable Intelligence

OpenCTI doesn’t just tell you what is happening, but it tells you who, why and what to do about it. It’s the difference between receiving a list of thousands of indicators of compromise and knowing which three of them are actively targeting your infrastructure right now, automatically informing your security tools, and providing information on exactly how to respond.

Raw threat data, on its own, is noise. Actionable intelligence is what you get when that data has been enriched with context, automatically mapping relationships between adversaries, infrastructure, capabilities, and victims, correlated against your specific environment. It’s what you get when it’s prioritized by relevance and risk and delivered straight to your security tools so teams can immediately act on it. This is exactly what OpenCTI does.

PIR-driven dashboard showing active threats, threat actors, and recent incidents in a specific industry

The results are measurable: less time on manual analysis, sharper focus on real threats over theoretical ones, faster incident response, and a meaningfully lower risk profile.

Why OpenCTI is Recognized as an Outperformer

Here‘s what GigaOm’s Research Analyst Seth Byrnes said about us:

“Filigran is classified as an Outperformer due to its rate of technology development in the last year, including a large expansion of its OpenCTI integrations and agentic AI (XTM One), both enhancements within OpenCTI.”

2026 GigaOm Radar for Threat Intelligence Platforms (TIP)

1. Fast-paced Integrations Expansion

The first reason why OpenCTI is rated an outperformer is the pace at which we added prebuilt integrations with open-source and commercial feeds, and security tools such as SIEM, SOAR, EDR, vulnerability management tools and more. Notable integrations include Microsoft, CrowdStrike, Recorded Future, Flashpoint, Tanium, Google, and IBM QRadar. We’re nearly at 300 in total, with plenty more to come.

2. Agentic AI for Driving Real Outcomes

The second reason is because our Agentic AI is ahead of the game. XTM One consolidates all AI capabilities available within OpenCTI and OpenAEV and adds pre-packaged, dedicated agents to take on the most time-consuming analyst workflows: threat enrichment and hunting, report generation, attack scenario building, and remediation guidance. In addition, you can bring your own LLM, build your own agents, and set your own rules, giving you full control over your data, your workflows, and your governance.

XTM One includes pre-built AI agents connecting OpenCTI and OpenAEV to deliver continuous CTEM

Other Areas Where OpenCTI Stood Out

GigaOm evaluated every vendor across a rigorous set of criteria. In addition to the points mentioned above, we also stood out for our:

  • End-to-End CTEM: Intelligence, Validation, and Action
    In addition to our prebuilt third-party integrations with feeds, enrichment, and security tools, OpenCTI natively integrates with OpenAEV, our adversarial exposure validation platform. This means you can go directly from intelligence context to attack simulation, closing the loop between knowing what threatens you, finding out whether you can stop it, and taking appropriate action. No other TIP does this.
OpenCTI shows OpenAEV results to indicate whether your environment is exposed to the threat

  • Graph and Link Analysis: Intelligence That Surfaces Relationships
    Threat intelligence that treats every indicator as an isolated data point is not intelligence, it’s a list. OpenCTI’s STIX 2.1-native, graph-based architecture models the world the way adversaries actually operate: as a web of interconnected relationships between actors, infrastructure, capabilities, and victims. Unlike the majority of TIPs on the market, OpenCTI standardizes all data using STIX 2.1 from the ground up, significantly reducing redundancies and providing a structured, interoperable foundation that makes automation, correlation, and genuine workflow integration possible at scale. The report also recognized our use of natural language processing to automatically extract entities and relationships from unstructured sources – reducing the manual curation burden that burns out analysts and slows down investigations.
OpenCTI visualizes relationships between actors, infrastructure, capabilities, and victims

  • Automation and Orchestration: Low-Code, High Impact
    GigaOm specifically highlighted our low-code automation workflows and user-defined taxonomies as genuine differentiators. Security teams should not need a developer to define enrichment logic or build a triage workflow. In OpenCTI, they don’t. Analysts can define and deploy automation that triggers downstream actions across SOAR, SIEM, ticketing, and validation platforms – without writing a line of code. This is true operationalized intelligence.

Where We’re Honest About Room to Grow

The report called out areas where we can do better, including native sandboxing capabilities, in-house digital risk protection data, and brand intelligence gathering. We agree, and we’re already on it. Being a company that’s three years old means we’re still maturing, but it also means we’re not burdened by the technical debt that slows legacy vendors down.

Our position has always been that we’d rather build the best open, interoperable intelligence platform in the world – one that connects to best-in-class specialized tools – than rush to build ‘good enough’ versions of every adjacent capability. That said, we hear the feedback. Our roadmap reflects a continued push toward deeper native capabilities, including integrating digital risk protection (DRPS) and brand intelligence – we’ll have more to share on that soon.

What Comes Next

This recognition is meaningful, but we’re not stopping here. In an industry where product roadmaps are typically the most closely guarded internal documents, we decided to make a different choice. As an open-source-first company, transparency is not a marketing position. It’s a design principle.

So we’ve published our full XTM Platform Roadmap, including OpenCTI and OpenAEV, accessible to anyone, at any time, with no strings attached. Every feature in active development, every capability planned for future releases, and every item under strong consideration, visible to our 6,500+ member community and to anyone evaluating the platform. Because we believe that you get the best out of our platform by knowing exactly where we’re going.


About Filigran

Filigran is the cybersecurity company behind OpenCTI, OpenAEV (OpenBAS), and OpenGRC – an open-source eXtended Threat Management (XTM) suite that helps organizations understand their threat environment, anticipate and detect incidents, and continuously validate their defenses. Trusted by organizations including the FBI, the European Commission, and leading enterprises across financial services, defense, and critical infrastructure, Filigran has raised over $100 million from investors including Eurazeo, Accel, Insight Partners, and Deutsche Telekom.

Read the full GigaOm Radar for Threat Intelligence Platforms v3 to see how OpenCTI compares across all decision criteria — or contact our team to see the platform in action.

Ready to see what operationalized threat intelligence actually looks like? Start a free trial or book a demo.

Stay up to date with everything at Filigran

Sign up for our newsletter and get bi-monthly updates of Filigran major events: product updates, upcoming events, latest content and more.