Agentic AI
CTEM

Introducing XTM One: Intelligence to Validation, Closing the Loop with Agentic AI

Jun 9, 2026 8 min read

Security teams have spent years assembling powerful stacks. According to Gartner*, organizations have, on average, 45 security tools that often work in silos and across different teams like threat intelligence, SOC, incident response, red teams etc. There is a mountain of security data available, but its disparate, redundant and too noisy. What security teams really need is to be able to consolidate and contextualize this data to prioritize signal over noise. They need to close the loop between intelligence and validation.

How do you run that loop autonomously, continuously, and at machine speed? With the rapid advancements in frontier AI models, like Claude Mythos, we can expect the discovery-to-exploit time to shrink significantly. And we as defenders would need to match the adversary’s speed and for this, we are going to need an agentic layer- one that connects and acts in real time.

That’s exactly what Filigran is introducing today. XTM One is a dedicated AI layer of XTM platform that connects OpenCTI and OpenAEV into end-to-end workflows, from raw threat intelligence to validated defensive action. Not AI as a feature bolted onto existing tools, but AI as the operating system for threat management. Security teams no longer have to choose between speed and control.


TL;DR

  • XTM One is the agentic AI layer of the Filigran XTM Platform, purpose-built to orchestrate the full Continuous Threat Exposure Management (CTEM) lifecycle from threat ingestion to validated remediation.
  • XTM One consolidates all AI capabilities available within OpenCTI and OpenAEV and adds pre-packaged, dedicated agents to take on the most time-consuming analyst workflows autonomously: threat enrichment and hunting, report generation, attack scenario building, and remediation guidance.
  • A natural language interface makes the full power of OpenCTI and OpenAEV accessible to every analyst on your team, regardless of experience level.
  • Open agent architecture means XTM One fits your environment. You can bring your own LLM, build your own agents, and set your own rules – making it easier to integrate with your own AI stack.

The Convergence Point: why Agentic AI and CTEM are colliding right now

Agentic AI has crossed the line from experimental to production-ready. Multi-step, autonomous AI workflows are no longer a research paper or a roadmap item. They are available, deployable, and already running in live security environments.

At the same time, Continuous Threat Exposure Management (CTEM) is moving from a framework to a mandate. Organizations are no longer asking whether to operationalize CTEM end-to-end. They are asking how. Security teams need a way to continuously connect threat intelligence to exposure validation, close the gaps their controls leave open, and report on posture with evidence rather than estimates.

And there is one more shift worth naming directly: security teams are developing their own AI strategies. These defenders are choosing vendors who can meet them where they are, support their existing infrastructure, and give them real flexibility. Not another closed system with a proprietary model and a vendor lock-in clause buried in the contract.

XTM One has been built with this exact mandate.

What CTEM actually requires

Continuous Threat Exposure Management (CTEM) is simple in principle: measure your security posture against the threats actually targeting you, continuously, not quarterly. The hard part is execution.

Intelligence and validation still sit in separate tools, run by different teams on different timelines. A threat report gets enriched in a CTI platform, then eventually turns into scenarios in a red team or Breach and Attack Simulation (BAS) workflow. Findings come back, priorities get mapped, and weeks disappear in handoffs.

Closing that gap takes more than better integrations. It takes an automation layer that runs intelligence and validation as one continuous loop, without waiting on manual handoffs.

Learn more about the CTEM framework and how Filigran approaches threat-informed defense.

Read our eBook.

Introducing XTM One

XTM One Product Display

We designed XTM One as a programmable orchestration layer that unifies OpenCTI and OpenAEV by consolidating all existing AI capabilities while adding pre-packaged agents for autonomous threat management. This orchestration layer is a key building block for agentic AI transformation, helping break down the traditional silos between proactive security (threat-informed validation and remediation) and reactive security (threat detection and response).

The result is not a faster version of the same manual workflow. It is a fundamentally different operating model for security teams.

Core capabilities

Agentic AI across the full CTEM lifecycle

Don’t just map threats but stop them proactively. XTM One packs a powerful CTEM Assistant that enables threat exposure assessment, prioritization and validation in one single workflow, making continuous threat exposure management a reality, at scale! CTEM Assistant uses multiple agents and orchestrates them across the full threat management lifecycle, so the output of one step automatically becomes the input of the next.

Speed is on essence here and with XTM One, you can run this full CTEM loop in minutes, not hours or days.

Flatten the learning curve

Analysts interact with OpenCTI and OpenAEV in plain English. No data model to learn. No complex navigation. For junior analysts and new team members, this dramatically reduces the learning curve. Senior analysts get their time back. Teams scale their output with more consistent, senior-quality output.

Lower the expertise barrier so every analyst can deliver value from day one.

Bring your own LLMs, build your own agents

XTM One is a programmable automation layer, not a closed system. Teams can customize existing agents, build new agents and configure flows, skills, prompts, MCP servers, and tool integrations. If your team has specific workflows, data sources, or automation requirements, XTM One supports them. No vendor dependency on the AI layer.

Connect and enhance XTM One with your own AI capabilities.

Have stricter policies? We have got them covered!

Providing flexibility to the customers is crucial for Filigran and with XTM One, we are providing customers ability to deploy the whole solution on-premise, within their own infrastructure, instead of relying on a fully managed SaaS model.

Beneficial for the government and critical infrastructure organizations.

Threat Management at Scale: Introducing Agentic CTEM

Join our upcoming webinar to see how XTM One brings together threat intelligence, adversarial validation, and agentic AI to support a mature, intelligence-driven CTEM program.

Register now: NA/EMEA Session | APJ Session.

XTM One in practice

XTM One’s unique differentiator is ‘context’. As XTM One is an orchestrating layer, all of our agents have the knowledge and the context across OpenCTI and OpenAEV to pull out the right information and apply the right reasoning. Compared to the general-purpose AI agents, the output you get from XTM One agents will be more relevant and contextual.

XTM One Interactive Demo

Intelligence ingestion and normalization

A new threat report arrives, whether it’s a PDF advisory, a raw feed, or a structured report from a sharing community. XTM One springs to action and ingests it automatically, converts unstructured content into fully enriched STIX 2.1 intelligence graphs, and makes it immediately actionable inside OpenCTI. No manual parsing. No analyst hours spent on normalization.

CTI analysis and dissemination

Once ingested, agents handle enrichment, generate threat summaries, create dashboards, and produce reports across OpenCTI. The intelligence is ready to act on, not just ready to read.

Attack scenario building

XTM One translates the enriched intelligence from OpenCTI directly into adversary-aligned attack scenarios inside OpenAEV. The scenarios reflect the specific TTPs, vulnerabilities, and behaviors associated with the threat, not generic templates.

Exposure validation and remediation

Scenarios run against live environments. XTM One identifies control gaps, maps them to the threat, and surfaces prioritized remediation guidance. The output is not a list of findings. It is a ranked, evidence-backed action plan.

The continuous loop

Validation results feed back into intelligence prioritization. New threats trigger new scenarios. The loop runs continuously, and every cycle makes the next one sharper.

This is what it means to operationalize CTEM. Not as a quarterly exercise, but as a live, automated, evidence-generating program.

Get started with XTM One

Book a demo.


Conclusion: Evidence, Not Assumptions

The CTEM promise has always been straightforward: know which threats are targeting you, validate whether your controls hold, and close the gaps continuously. The challenge has been execution.

XTM One makes that execution possible at machine speed. It connects the intelligence you collect in OpenCTI to the validation you run in OpenAEV, automates the steps in between, and gives every analyst on your team the tools to contribute from day one. General-purpose AI is powerful, but it wasn’t built for security. And context is important here. XTM One is purpose-built for CTEM and threat management, trained on real threat intelligence, adversary behaviors, and security workflows. The output isn’t just smarter, it’s actionable, validated, and security-specific.

XTM One is available from today, talk to us about your requirements and be part of our early adopter program.

Be a part of our Slack community channel  and ask any questions.

Resources:

  • *Gartner Report: Tech FutureSight: Protect the Global Attack Surface With an Autonomous Cyber Defense System. Access.

Stay up to date with everything at Filigran

Sign up for our newsletter and get bi-monthly updates of Filigran major events: product updates, upcoming events, latest content and more.