脅威インテリジェンスエージェント型AICTEM敵対的エクスポージャー検証ソフトウェア開発

XTM Platform Q3 2026 updates: OpenCTI, OpenAEV, XTM One, and XTM Hub

11 分で読めます
Title card for the XTM Platform Q3 2026 updates blog, with OpenCTI and OpenAEV dashboards and authors Deborah Galea and Pierre-Loic Kuhn.

As the days get shorter and pumpkin spice returns, we've been busy improving the XTM Platform to help you cut through the noise, prioritize what matters, and automate more of your work, enabling you to better strengthen your defenses. This quarter brings risk-based prioritization with Stakeholder-Specific Vulnerability Categorization (SSVC) in OpenCTI, autonomous Attack Chaining and AI red teaming in OpenAEV, an XTM One desktop app, a new home for it all in XTM Hub, and much more.

Grab a warm drink (pumpkin spice optional, though our intel confirms it's trending) and dive in.

OpenCTI

Patch the riskiest vulnerabilities first with SSVC prioritization

A Common Vulnerability Scoring System (CVSS) score indicates how severe a vulnerability could be, rather than how likely attackers are to exploit it. CISA's Binding Operational Directive (BOD) 26-04 makes SSVC the new standard for prioritizing vulnerabilities in federal agencies, based on real-world risk. The directive is binding only on U.S. federal civilian agencies, but CISA encourages all organizations to adopt it.

OpenCTI now captures SSVC metrics for vulnerabilities: exploitation status, automatability, and technical impact. These metrics help your team prioritize the vulnerabilities that pose the greatest risk.

CVEs in OpenCTI now show SSVC metrics.

Save time by automatically mapping vulnerabilities to your assets

If you don't use an asset management integration like Tenable or Qualys, OpenCTI can now map your exposure for you. Just list your key systems and the software they run, and two new inference rules do the linking:

  • System has vulnerability: If a system uses software that has a vulnerability, OpenCTI marks the system as affected.
  • Infrastructure has vulnerability: If an infrastructure runs software that has a vulnerability, OpenCTI marks the system as affected.

As OpenCTI learns about new vulnerabilities in your software, it updates your exposure automatically, so you get a clearer view of which systems are affected.

Inference rules automatically mark systems and infrastructure affected by vulnerabilities.

Scale exposure validation and tailor it to your priorities

Support for multiple OpenAEV instances: OpenCTI can now integrate with several OpenAEV instances and break down test results by instance. You can compare gaps across environments without switching tools, which is especially useful for managed security service providers (MSSPs) and enterprises with multiple sites.

OpenCTI breaks down OpenAEV test results by instance.

Choose what OpenAEV tests: When you create a security coverage from an intrusion set, campaign, or report, you can now choose the entities you want to cover, such as TTPs, vulnerabilities, domains, and artifacts, and add your own scores to the results. Your coverage assessment then reflects your priorities and judgment.

Customize Fintel reports to fit your audience

Finished intelligence (Fintel) reports in OpenCTI now have more design options, so each report can suit its reader. For a one-page brief to your CISO, leave out the title and back pages. Need a report on a single vulnerability? Export any entity straight to PDF with the Fintel template and design you choose. If a table is too crowded, show only the attributes your readers need. Tables with more than eight columns switch to landscape automatically. Every stakeholder can then get your intelligence in a format that’s easy to consume.

Turn cover and back pages on or off for each Fintel report.

Configure AI agents to ask before they act

You can now require human approval before XTM One agents take sensitive actions. When an agent reaches a tool that needs approval, it pauses and waits for an operator to approve or deny the action. Ask Ariane, the AI assistant in OpenCTI, supports this human-in-the-loop flow. It shows you the approval request right where you work and sends your decision back to the agent. Your agents take on more of the work while you decide which actions run.

Sharpen prioritization with enhanced scores and context

OpenCTI now adds a score for intrusion sets, threat actors, malware, campaigns, incidents, and events. You can filter by score and use scores in the OpenCTI Python client to help you surface the most urgent threats easily.

Observed data now has two new counters, number_seen and max_distinct_count, alongside number_observed. The new counters help you tell one noisy host apart from thousands of endpoints contacting the same domain, a useful distinction when you're checking for beaconing (malware calling home on a regular schedule).

Finally, sightings can now link an indicator to a security platform, so you can see which tool detected it.

New feeds, enrichment, and ways to act on intelligence

This quarter we added 15 new OpenCTI integrations: six built by Filigran and nine by our community. The new integrations include:

  • New feeds: dark web and cybercrime intelligence with Dark Web Informer, Threat Landscape, and the Group-IB Threat Intelligence 2.0 connector; honeypot and pre-triaged feeds with GreedyBear, HoneyLabs, and ScanMalware.
  • Broader enrichment: MACAddress.com, Intel 471 Hunter, ScanMalware, Censys Enrichment API and Lamis Network.
  • Operationalized intelligence: A new stream connector pushes your indicators to Palo Alto Cortex XDR as IOCs.

Deploy the new Palo Alto Cortex XDR Intel connector in one click.

We also enabled one-click deployments for 25 more connectors in Enterprise Edition. All connector images are available for ARM, too.

FIPS and Section 508 compliance support in OpenCTI

  • FIPS 140-3 compliance: OpenCTI's Federal Information Processing Standard (FIPS) images now use an OpenSSL FIPS provider built from FIPS 140-3-validated sources (CMVP certificate #4985). This enables you to deploy OpenCTI in government and regulated environments that require FIPS 140-3, such as U.S. federal agencies.
  • Section 508 accessibility: The OpenCTI user interface now supports screen readers. We fixed every issue found in a full Section 508 scan, so agencies that must buy accessible software can adopt OpenCTI more easily.

Running OpenCTI on-premises, air-gapped, or in a private cloud?

Update your instances to get these features. SaaS instances update automatically.

OpenAEV

Automate red teaming activities with autonomous Attack Chaining

Single techniques don't show how a real attacker moves through your environment. Attack Chaining in OpenAEV links actions to simulate a full attack path, where the output of one step becomes the input of the next. Most breaches come from small weaknesses lined up, not one critical flaw. Attack Chaining shows which ones actually connect into a path to your critical assets, so you can fix what breaks the chain instead of triaging every finding. You can run it in two ways:

  1. Operator-led: You build the conditional logic and control each step. Use this mode when you need precise, repeatable pentesting.
  2. Autonomous: You set an objective and a scope. An orchestrator AI agent, powered by XTM One, plans the path, runs it, and changes course based on what it finds. When the objective calls for social engineering, it can even write phishing emails and landing pages.

Watch attack paths unfold live on the attack graph.

Red and purple teams can scale testing with the people they already have and run complex multistage simulations without needing as much specialized expertise. SOC teams can see whether detections and responses hold up across a full attack sequence.

Measure your resilience in the new Exposure Command Center

The new Exposure Command Center shows your posture across every security domain, along with your latest simulation results and detection coverage mapped to MITRE ATT&CK and ATLAS. SOC leaders get the big picture, while blue, red, and managed detection and response (MDR) teams can go straight to what needs fixing.

The Command Center also displays the new Adversarial Exposure Score, which represents your overall resilience. The score combines posture scores from every main exposure domain, weighted by criticality. You can drill down into failed and breached validations to see where the gaps are. The score updates with every new simulation, so it reflects your latest results.

In addition, you can tag your assets by criticality with the new Asset Criticality feature, so the score automatically adapts to your business. Your critical assets carry more weight in each Asset Posture Score and rise to the top of your findings.

Track your posture and Adversarial Exposure Score from one dashboard.

Turn simulation results into actionable reports in a few clicks

Instead of pulling data from several tools and reformatting it by hand, let OpenAEV’s new automated reporting feature do the work. It combines your simulation, exposure, and posture data into a structured report for compliance teams, leadership, and the board.

Validate your AI posture with AI red teaming

As you roll out AI agents, you can validate them like any other part of your attack surface. OpenAEV now includes native AI Red Team injectors in the Threat Arsenal, based on the MITRE ATLAS framework. You can test LLMs and AI agents for:

  • Prompt injection and jailbreaks
  • Excessive agency and tool abuse
  • Model Context Protocol (MCP) tool poisoning

These injectors use engines like NVIDIA Garak, Microsoft PyRIT, and Promptfoo, and they map to MITRE ATLAS. With the new Artificial Intelligence domain, you can track your AI exposure alongside the rest of your environment, using the same findings, scoring, and Command Center.

Test LLMs and AI agents with AI Red Team injectors.

Automate exposure validation tasks with XTM One agents

XTM One now brings a library of ready-made AI agents to OpenAEV. Each one handles a specific part of exposure validation, so your team can spend less time on routine tasks and more time closing gaps:

  • Scenario orchestration: Plan and run scenarios, either plan-based or as attack chains.
  • Assistance: Get plain-language help running OpenAEV and your Continuous Threat Exposure Management (CTEM) program.
  • Analysis: Turn simulation results into briefings, mobilization plans, and remediation guidance.
  • Remediation: Get suggested actions and detection rules to fix what you find.
  • Social engineering: Create phishing emails and landing pages for your simulations.

Prepackaged agents cover the full loop, from intelligence to validation to remediation.

You can also bring your own LLM, customize the built-in agents, or build your own.

Running OpenAEV on-premises, air-gapped, or in a private cloud?

Update your instances to get these features. SaaS instances update automatically.

XTM One

Run XTM One agents right on your desktop, with you in control

XTM One now runs as a native desktop app, so agents can work directly on your machine while you stay in control. Sign in through your browser with single sign-on (SSO), approve sensitive commands in the chat, and watch each action live with its output one click away. Signed installs and updates, plus a single view of every enrolled machine, help admins deploy the app across the team.

Connect agents to more of your tools and files

XTM One agents can now read files from every integration and chat channel, from Microsoft, Google, HR, CRM, and security tools to WhatsApp, Google Chat, Telegram, and the public chat widget. New integrations include Recorded Future MCP, security stack MCP presets, GitHub security advisories, Nova prompt safety, SpaceXAI (Grok), and XTM One over MCP.

Improve your agents, control costs, and set up faster

Rate your agents' work with a thumbs-up or thumbs-down, and they’ll improve in steps a human approves. If quality drops, changes roll back automatically. Spending limits per run and per agent keep costs under control, and a backup model takes over when a budget runs out. Create agents from templates or import them with automatic checks, then @mention several at once in chat to have each one answer in turn.

Get presentation-ready decks from your agents

Your agents can now build decks you'd actually present, making sharing information super fast and easy. Each deck uses your themes, templates, and brand assets, so it looks on-brand from the first draft. Charts, dashboards, and interactive diagrams help make your data easy to follow. Speaker views keep your notes and timing in front of you. To share the deck, export it to PDF or PowerPoint. If something needs changing, edit it right on the slide, with undo and redo, so you don't have to start over.

XTM One agents build on-brand decks you can export to PDF or PowerPoint.

Put your agents to work together, in flows you design

Build workflows by drag and drop with the new Visual Flow Builder, and watch each step run live. Flows can also start automatically when an agent learns something new. Through the open Agent-to-Agent (A2A) standard, XTM One agents can now exchange work with partner agents. Worksets let agents summarize, group, and search your internal data within spending limits you set, and Workspaces organize everything by project.

Running XTM One on-premises, air-gapped, or in a private cloud?

Update your instances to get these features. SaaS instances update automatically.

XTM Hub

Get to everything in the XTM Platform from one place

XTM Hub is now the place to get more out of your Filigran products. XTM Hub 2.0 has a cleaner, simpler interface, so you no longer have to move between the website, the docs, and each product to find what you need. From the redesigned homepage, you can start a trial, connect your products, browse ready-to-use content, and follow the XTM Platform Roadmap.

Try the XTM Platform free for 30 days

You can now try the XTM Platform, including OpenCTI, OpenAEV, and XTM One, free for 30 days through XTM Hub. You get full access to every Enterprise Edition feature, and there's nothing to install because the trial is fully SaaS.

Focus on the risks that matter

This quarter's updates help you spend less time on manual work. With OpenCTI, you can prioritize which vulnerabilities to patch first. OpenAEV shows you how attackers could get in, including through your AI agents and LLMs. XTM One agents can handle more of the heavy lifting, and XTM Hub brings everything together.

See the updates for yourself:

Your pumpkin spice latte will still be warm by the time you're up and running.

続きを読む

関連トピックとインサイトをご覧ください