Custom Views in OpenCTI: Get to the Right Intelligence Faster
Getting to the right threat intelligence faster has tangible business impact: it compresses investigation timelines, reduces dwell time, and helps teams make higher-confidence decisions under pressure. When analysts can immediately see the most relevant signals they’re looking for, such as key relationships, recent reports, infrastructure, TTPs, and attribution, they can quickly focus on what matters – making the right call, faster.
This why, in addition to custom dashboards, we’ve introduced custom views in OpenCTI. Whereas custom dashboards are standalone, cross-entity reporting pages to understand the big picture, custom views are contextual, entity-specific widget tabs embedded directly on an entity page for a focused deep dive. The result: less navigating, faster decisions, and analysts who can trust what they’re acting on.
TL;DR
- Custom Views bring the most relevant, entity-specific intelligence directly onto OpenCTI entity pages, so teams get context faster.
- They complement (not replace) custom dashboards: dashboards show cross-entity ‘big picture’ reporting, while custom views enable entity-level deep dives.
- The RRN/Doppelgänger example shows how a dedicated FIMI view can surface key signals (channels, accounts, targets, infrastructure, TTPs, attribution) in one place.
- Business impact: less navigation, faster triage and investigations, and higher-confidence decisions under pressure.
The Problem with One-Size-Fits-All Entity Pages
OpenCTI’s entity pages, whether you’re looking at a Threat Actor, a Malware, a Campaign, or a Vulnerability, come with a default set of tabs and information panels. For most users, most of the time, this default layout is a reasonable starting point.
But threat intelligence teams are not monolithic. A SOC analyst triaging an intrusion set cares about different signals than a CTI manager reviewing the same entity. A CISO consuming a vulnerability report has entirely different questions than the analyst who wrote it. And in large organizations, multiple teams with distinct workflows share the same OpenCTI instance.
Until now, adapting what an entity page shows, beyond what the platform provides out of the box, required either building standalone custom dashboards (which live outside the entity context) or accepting that some relevant information would always require extra navigation steps.
Custom Views close that gap.
What Custom Views Are and What They’re Not
Custom Views are widget-based layouts that appear as additional tabs directly on entity pages. They’re contextual by design: a Custom View defined for Threat Actors will appear on every Threat Actor page, automatically scoped to the entity being viewed.
This makes them fundamentally different from Custom Dashboards, which are standalone pages used for cross-entity reporting. Custom Dashboards are great for the big picture. Custom Views are great for the entity-level deep dive.
Think of it this way: if a Custom Dashboard is your intelligence command center, a Custom View is the specialized instrument panel that pops up the moment you open a specific entity.
A Real-World Use Case: Tracking the RRN / Doppelgänger FIMI Campaign
To make this tangible, let’s walk through a real-world scenario of an analyst investigating RRN (also known as Doppelgänger), one of the most documented Foreign Information Manipulation and Influence (FIMI) campaigns of recent years.
The Campaign in Brief
RRN is a large-scale, coordinated pro-Russian influence operation. It operates through a network of fake news websites impersonating legitimate media outlets — cloning domains such as bild.pics, ukraina.ru, or franceete… — to spread disinformation across Europe and the United States. The campaign is attributed to Russian organizations.
At the time of the investigation in OpenCTI, the RRN campaign entity showed:
- 608 channels tracked across the network
- 304 Twitter/X accounts linked to the operation
- Targeted countries spanning Western Europe (France, Germany, Belgium, Italy), Ukraine, and the United States
- 5 known domain names flagged and disabled
- 5 MITRE ATT&CK for FIMI techniques in use, including T0086, T0061, T0049, T0023, and T0017
- Two key intelligence reports: “Portal Kombat: A structured and coordinated pro-Russian propaganda network” (VIGINUM, February 2024) and “RRN: A complex and persistent information manipulation campaign” (August 2023)
The Problem Without Custom Views
All of this intelligence existed in OpenCTI — but it was scattered. An analyst opening the RRN campaign page would land on the standard Overview or Knowledge tabs, which surface generic relationship graphs and entity metadata. To get to the FIMI-specific picture — channels, Twitter accounts, targeted countries, domain infrastructure, TTPs, attributions — they would have to navigate across multiple tabs and manually cross-reference data.
For a campaign type as specific as FIMI, where the relevant signals (influence channels, impersonated domains, narrative targets, attribution chains) are fundamentally different from a traditional malware campaign or intrusion set, the default layout simply doesn’t fit.
The Solution: A Dedicated FIMI Custom View
With Custom Views, a platform administrator can create a dedicated “Foreign Information Manipulation & Influence” tab that appears on every Campaign entity page — and surfaces exactly the intelligence that matters for this type of threat:
- Entities count widgets showing the number of channels and social media accounts tracked in real time
- A geographic heat map of targeted countries, giving instant situational awareness of the campaign’s geopolitical scope
- A domain name list with processing status, labels, and TLP markings — so analysts can immediately see which infrastructure has been identified and actioned
- A TTPs list surfacing the MITRE ATT&CK for FIMI techniques in use, with creation dates and markings
- An attribution block listing the organizations behind the campaign, with their labels and data provenance
- A “Last Reports” timeline showing the most recent intelligence publications linked to this campaign entity
The result is visible directly in the screenshots below: the “Foreign Information Manipulation & Influence” tab on the RRN campaign page becomes a purpose-built intelligence instrument panel. Everything an analyst needs to assess the campaign’s scale, infrastructure, targets, and attribution is available in a single, contextual view — without a single extra click.



Why This Matters
The RRN example illustrates the core value proposition of Custom Views: the same platform, adapted to the threat type.
A SOC analyst investigating a ransomware intrusion set needs a very different entity page than a FIMI analyst tracking a state-sponsored influence campaign. Custom Views let your platform reflect that reality — without forking your data model, building separate tools, or asking analysts to mentally reassemble intelligence that the platform already holds.
“The FIMI view doesn’t add new data to OpenCTI. It makes the right data visible, in the right place, at the right moment.”
This is what it means to shape your intelligence workspace.
See how custom views work for a specified campaign
How Does it Work?
The Platform Administrator: Creating and Managing Views
Custom Views are managed from the Custom views tab on each Settings > Customization > [Entity type] page. This area is accessible to users holding the Manage customization capability.

From there, administrators can create a new Custom View, provide a name and a description, and edit its content using the same widget types available in Custom Dashboards (lists, timelines, distribution charts, heat maps, etc.).
Please note that Custom Views need to be enabled to become visible by end users.
By default, when adding a widget to a Custom View it comes pre-configured with the special current entity filter value to reference the entity currently being viewed. This is the key mechanism that makes Custom Views contextual. For example, a “Related Reports” list widget can be filtered by in regards of = current entity, meaning it will automatically display the reports linked to whichever Threat Actor or Malware page the analyst happens to be on.
Additionally, a convenient preview feature lets the administrator select an existing entity of the relevant type to see how the widgets will look once the Custom View is published.

An administrator can mark a Custom View as the default view for a given entity type. When set, this view becomes the landing tab when any user navigates to an entity of that type — replacing the standard Overview tab as the first thing they see. There can be at most one default view at any time for a given type.
Lastly, Custom Views can be exported as JSON definition files and imported into another OpenCTI instance. This makes it straightforward to share best-practice view templates across teams, between instances, or with the community.
The Analyst: Using Custom Views
From an analyst’s perspective, Custom Views are transparent and frictionless. There is nothing to configure: the views appear automatically as additional tabs on the relevant entity pages.
When navigating to a Threat Actor page, for example, an analyst may see a set of tabs like Overview, Knowledge, Analyses, Sightings, Files, History — and, if a Custom View has been defined and is visible to them, one or more additional tabs with names defined by the administrator.

Clicking on a Custom View tab loads the widget layout configured by the admin, with all widgets already scoped to the current entity via the current entity filter. The analyst doesn’t need to apply filters or navigate elsewhere — the relevant intelligence is surfaced in context.
This is particularly powerful for recurring workflows. If an analyst regularly needs to check the related TTPs, recent reports, and associated infrastructure every time they open a Threat Actor entity, a Custom View can bundle all of that into a single tab, eliminating repetitive navigation.
Availability
Custom Views are available in OpenCTI starting from version 7.260520.0, released in May 2026, under the Community Edition license. You’ll find more information about the feature in our official docs.
What’s Next
Custom Views are a first step toward a more composable, role-aware intelligence workspace in OpenCTI. Combined with Custom Dashboards, Priority Intelligence Requirements (PIRs), and the platform’s existing RBAC model, they give platform administrators fine-grained control over what each team sees — and give analysts a faster, more focused experience when working with entities day to day.
We’d love to hear how you’re using Custom Views. Share your configurations and feedback with the community on our Slack or open a discussion on GitHub.
Read more
Explore related topics and insights