What We’ve Been Building in Q2: XTM Platform, OpenCTI and OpenAEV Updates.
Apparently, not even a FIFA World Cup or sweltering heatwaves can slow the Filigran team down. Unfazed, we stayed in full delivery mode, making sure that our users get contextual, actionable intelligence faster than ever before.
This quarter’s highlight? The launch of XTM One, our Agentic AI orchestration layer that unifies OpenCTI and OpenAEV into a continuous, autonomous threat management workflow. But that’s just the headliner: we also released smarter automation and richer analyst tooling in OpenCTI, expanded simulation capabilities and multi-tenancy support in OpenAEV, and more pre-built content and full roadmap visibility on XTM Hub. Ready to see what’s new? Let’s dive in.
TL;DR
- XTM One launched: our new agentic AI orchestration layer unifies OpenCTI and OpenAEV into one continuous threat management workflow, with a natural language interface and support for bringing your own LLM.
- OpenCTI gets smarter: a new Playbook Library, agentic “Ask Ariane” assistants, event-based automation triggers, custom entity views, direct image paste, OpenAEV simulation results in-platform, and 29 new integrations.
- OpenAEV levels up: multi-tenancy for MSSPs and large organizations, a new Threat Arsenal library for building simulations faster, and a NetExec injector for realistic network attack scenarios.
- XTM Hub expands: a live newsfeed inside OpenCTI, a free 30-day OpenAEV trial, more pre-built content libraries, and full roadmap visibility.
OpenCTI
The OpenCTI team has been busy this quarter: from a curated Playbook Library and powerful new agentic features, to custom entity views, richer simulation visibility, and 29 new integrations. Whether you’re automating threat intelligence workflows or fine-tuning the platform to fit your team’s needs, we think you’re going to like what’s new.
Note that all OpenCTI SaaS instances are updated automatically, but if you’re running air-gapped or private cloud installations, remember to update your instances.
Automate Smarter with the OpenCTI Playbook Library
Available on XTM Hub, the new OpenCTI Playbook Library offers a curated catalog of pre-built playbook templates covering the most common threat intelligence automation use cases: from indicator enrichment and labeling, to routing and blacklist management. Instead of building complex workflows from scratch, Enterprise Edition users can browse ready-to-use playbooks complete with inline documentation and clearly listed dependencies – and deploy with one click.

New Agentic Features for Enhanced Automation
When using XTM One, the OpenCTI chatbot ‘Ask Ariane’ gets agentic capabilities with the addition of specialized agents such as the CTEM Assistant, OpenCTI Assistant, OpenCTI Threat Hunter, and CTI STIX Harvester, ensuring you always have the right agent for the task at hand. Other capabilities include multi-conversation history so you can pick up where you left off, the ability to adjust instructions while a response is generating, and page context awareness so Ariane automatically understands the entity or page you’re viewing. Ariane can also deliver agent-generated files, such as reports and structured exports, directly within the chat interface.

Trigger Automation Based on Real-World Events and Updates
OpenCTI Playbooks can now automatically trigger when an entity changes, for example when a vulnerability is added to the CISA KEV, a status is updated, or any other field is changed. This means you can, for example, automatically kick off a playbook when there‘s evidence that malicious actors are actively exploiting a vulnerability in the wild and then instantly see if it affects any of your assets. You can even trigger workflows based on a property that hasn’t changed within a defined timeframe, unlocking a new level of automation granularity for threat intelligence workflows.
Custom Views: Less Navigating and Faster Decision-Making
OpenCTI’s new custom views bring purpose-built, widget-based layouts directly onto entity pages, so analysts no longer have to navigate across multiple tabs to piece together a complete picture. Whereas custom dashboards provide cross-entity reporting from a standalone page, custom views offer contextual views for a single entity type and appear as additional tabs scoped to whichever entity is being viewed. From a FIMI campaign page surfacing influence channels, targeted countries, and attribution chains, to a vulnerability page tailored for a security engineer’s workflow, custom views let platform administrators shape the intelligence workspace to match the team’s needs.
Directly Insert or Paste Images for Easier Knowledge Sharing
No more uploading images separately and manually linking them: The OpenCTI markdown editor now supports direct image copy/paste and file upload across reports, notes, and any other markdown-enabled content. This makes knowledge capture easier and faster, whether you’re authoring a threat intelligence report or documenting findings during an active incident investigation.
Instantly Know Your Security Gaps With OpenAEV Simulation Data
OpenCTI now gives you a clearer picture of what you’ve actually tested against your threat intelligence. A new results page within the Security Coverage view surfaces aggregated simulation outcomes directly from OpenAEV, showing which entities have been tested, the latest results per simulation, and a breakdown of tested entities by type. Whether your coverage is built manually or through automated simulations, everything is reflected in one place, with a direct link back to OpenAEV for deeper investigation.

Further Streamline Your Workflows with New OpenCTI Integrations
This quarter we added 29 new OpenCTI integrations: 5 developed by Filigran and 24 developed by our community (including PolySwarm, Datadog, CTM360, MokN, and more). The following integrations were added by Filigran:
- Google SecOps SIEM Incidents: Import SIEM alerts as enriched OpenCTI Incidents, complete with related observables and STIX relationships.

- SigmaHQ: Import 3,000+ community-maintained Sigma detection rules into OpenCTI as indicators, and correlate them with your threat intelligence.
- Google Digital Threat Monitoring: Bring your external digital risk intelligence directly into OpenCTI. Ingest Google DTM alerts as structured incidents, enriched with threat context and all associated observables, ready to correlate with your broader threat intelligence.
- ServiceNow OpenCTI Vulnerability Response: Import vulnerabilities from OpenCTI into ServiceNow and enable teams to track them efficiently.
- Recorded Future ASI: Import attack surface findings into OpenCTI as enriched incidents, with linked observables and CVEs, keeping your exposure risks in sync with your threat intelligence.
OpenAEV
OpenAEV had quite the quarter. The team zeroed in on simplifying the management of multiple environments, streamlining simulation building, and making realistic attack scenarios easier to execute.
Note that all OpenAEV SaaS instances are updated automatically, but if you’re running air-gapped or private cloud installations, remember to update your instances.
Here are the highlights:
Multi-Tenancy: Easier Management for MSSPs and Large Organizations
Say goodbye to switching between instances when managing multiple business units or client environments. With new multi-tenancy support, MSSPs and large organizations can now organize and operate multiple tenants from a single deployment: with strict data segregation, per-tenant configuration, and centralized administration all in one place.

Build Simulations Faster with OpenAEV Threat Arsenal
Threat Arsenal is the new core library in OpenAEV, bringing all your attack techniques together in one structured, ready-to-use hub. Every Action – the building block of a simulation scenario – is organized by domain and fully searchable, making it easy to find exactly what you need. Select actions in bulk, spin up atomic tests on the spot, or chain them into full scenarios without ever leaving the page. For example, if your team identifies a weakness on an endpoint, you can filter by domain, select all relevant actions, build a scenario, and run it – all in a single flow.

NetExec Injector: Simulate Real-World Network Attacks
OpenAEV now integrates NetExec, one of the most widely used offensive network tools, directly into your breach and attack simulations. Run realistic network exploitation and enumeration scenarios across nine supported protocols: SMB, LDAP, WinRM, SSH, FTP, MSSQL, RDP, VNC, and WMI. Advanced techniques including Kerberoasting, AS-REP Roasting, share enumeration, and modules such as spider_plus and mssql_priv are all supported out of the box. Results are returned as structured, actionable findings (e.g. exposed credentials, vulnerable accounts, misconfigured shares) so your teams can act on specific insights.

XTM One
This month we launched XTM One, our Agentic AI orchestration layer that connects OpenCTI and OpenAEV into a single, continuous threat management workflow. XTM One consolidates all existing AI capabilities across the platform and adds pre-packaged agents that autonomously handle time-consuming tasks: from threat enrichment and report generation to attack scenario building and remediation guidance.
A natural language interface makes the full platform accessible to every analyst. And here’s the kicker: XTM One’s unique, open architecture lets you bring your own LLMs and build custom agents on top. This is what operationalizing CTEM really looks like.
XTM Hub
This quarter we continued to expand XTM Hub as the central destination for all things Filigran, with expanded single-click deployment libraries, a free OpenAEV trial, a live newsfeed into OpenCTI, and full roadmap visibility all added to the mix. Here’s what’s new:
Stay Informed on New OpenCTI Features and Pre-Built Content
Stay up to date with the latest content published on XTM Hub (such as new playbooks, scenarios, dashboards, and RSS feeds) without ever leaving OpenCTI. The XTM Hub Newsfeed is now integrated directly into the platform, surfacing relevant Hub updates in a dedicated feed. Toast notifications alert users when new notifications arrive, and a simple mark-all-as-read option keeps things tidy. Newsfeed preferences can be managed from user profiles.
OpenAEV 30-Day Trial
Experience the full power of OpenAEV Enterprise Edition with our new free 30-day trial. Simulate attacks, evaluate your defenses, and strengthen your security posture with access to all SaaS-based Enterprise Edition features. Including leveraging your existing EDR agents, automated scenario generation, and AI-powered remediation guidance.

More Pre-Built Content for Faster Time to Value
We’re steadily expanding our libraries of pre-built content so you spend less time configuring and more time getting value. For Enterprise Edition users, everything deploys in a single click:
- OpenCTI Integrations Library
- OpenCTI Playbooks Library
- OpenCTI Custom Dashboards Library
- Open AEV Scenarios Library
…. with more coming!
Know What’s Coming Next with Our XTM Platform Roadmap
The full XTM Platform Roadmap is now available on the XTM Hub, giving you full visibility into what’s being built across OpenCTI and OpenAEV. As well as tracking features currently in development, planned for future releases, and under consideration, you can also easily review updates from the last three months, without having to dig through release notes. More than just a transparency initiative, it’s a direct line into shaping our platform: your feedback and community input actively influence what gets prioritized next.

Conclusion
And that’s a wrap on Q2 2026! From agentic AI and multi-tenancy to new injectors, the Filigran team has been anything but idle. And if you think this quarter was packed, just wait: Q3 is already shaping up to be another big one. Want to make sure you never miss an update? Subscribe to the Filigran newsletter and get the latest product news, release highlights, and platform updates delivered straight to your inbox.
And if you’re not a member yet, join our Slack community channel to ask a question or start a conversation. We love hearing from you!
Read more
Explore related topics and insights