Understand Your Threat Landscape and Act Decisively
Unify, operationalize and prioritize threat intelligence to make your SecOps better with our open-source threat intelligence platform – the intelligence pillar of CTEM and threat-informed defense.

Collect, correlate and leverage
Operationalize threat intelligence like never before. Share it timely across your security teams and build threat-informed defense.
Unify Threat Intelligence with 300+ one-click integrations
Standardize all your threat intelligence, from commercial feeds, open source, industry groups or internal security tools, using a consistent STIX 2.1 data model, powerful visualizations and custom dashboards.
Combat alert fatigue, elevate your impact
Benefit from advanced automation and agentic AI for faster processing of the entire threat management life cycle so you focus on activities that matter. Generate finished TI reports in minutes, not hours or days.
Operationalize threat intelligence across SecOps
Share prioritized intelligence with your executives to take informed decisions. Feed it into your SecOps for improved detection and response. Scale your threat hunting capacity and validate your security posture, continuously.
Streamline incident response
Use OpenCTI case management for incident-related data and accelerate your investigations, including threat hunting. Improve your triage, containment and remediation capabilities.
Sign up for your 30-day free trial
Explore full OpenCTI Enterprise Edition features such as automated playbooks, priority intelligence requirements (PIRs), FINTEL, as well as AI-powered file imports, report generation and natural language search.
Trusted by intelligence teams worldwide
Threat-informed defense with OpenCTI
Operationalize threat intelligence across your security stack: feed SIEM and SOAR for automated detection, enrich EDR alerts with context, prioritize vulnerabilities, and enable threat-informed defense at scale.
Input
Threat feeds
Commercial / open source
Contextual data
300+ integrations
Other sources
Emails, documents, MISP
Processing
Output
- Share CTI: strategic, operational, tactical
- Feed streamlined intelligence into SIEM & SOAR to improve detection & response
- Scale threat hunting & incident response capacity
Cyber Threat Intelligence Platform
Manage and operationalize your cyber threat intelligence efficiently and effectively.
A GUI built for threat intelligence practitioners
Modern and intuitive dashboards with a STIX-structured knowledge hypergraph: pivot across actors, malware, TTPs and indicators with visual graphs, timelines and ATT&CK mappings.

Filigran Browser Extension
Turn your web browser into a threat intelligence workstation. With a single click, scan any web page into a structured threat report, launch investigations or generate attack scenarios. Seamlessly integrated with both OpenCTI and OpenAEV.

Adapt the platform to your requirements
Customize your dashboards depending on your use case: threat monitoring, threat hunting, incident response, disinformation and more. Benefit from the Filigran and community-built dashboard library.

Work faster and analyze better with AI
Make AI your companion at every step: threat feed imports, search, insights and summaries, up to finished deliverables with the template and tone of your targeted audience.

Automate scenarios and playbooks
Integrate both technical and non-technical information into a unified system, linking each piece of threat intelligence to its original source for a complete analytical perspective. Based on this information, take action through automation.
Role-based access control (RBAC)
Segregate data access and centralize access management via the authorized members and organizations mechanism. Particularly useful for threat intel sharing in large organizations with regional offices, or for managed service providers.
Centralized case management
Enhance threat detection and response by centralizing incident-related data, fostering real-time collaboration, and improving efficiency through automated workflows.
Join the OpenCTI community
Connect with fellow Filigran community members, focused on threat intelligence analysis and adversary simulation.
GitHub
Your gateway to exploring, contributing, and shaping the future of threat intelligence.
Access OpenCTI Community EditionProduct integrations
Discover a list of all resources available to complete your OpenCTI journey.
Explore OpenCTI connectorsDocumentation
Find all documents to get started, release notes and presentations about the threat intelligence platform.
Access OpenCTI documentationSlack
Stay informed about platform developments and engage in broader discussions.
Join the Filigran communityThreat management that scales with you
On-premise community edition, SaaS-based enterprise edition or support for air-gapped deployments: we have a model that works for you.
Community Edition
Get started with OpenCTI CE on-premise using the open source releases, with help available through Filigran support packages.
- Complete STIX 2.1 knowledge graph
- All open source connectors
- Community support on Slack
Enterprise Edition
Commercial, licensed upgrade with advanced AI and automation capabilities plus dedicated support by the Filigran technical team.
- AI-powered imports, summaries and insights
- Automated playbooks and PIRs
- Advanced RBAC, SSO and audit trails
- Vendor support with SLAs
SaaS hosting
A fully managed OpenCTI Enterprise Edition hosted by Filigran with self-service provisioning; air-gapped deployment also available.
- Hosted and operated by Filigran
- Enterprise Edition included
- Self-service provisioning
Discover the ecosystem
Our eXtended Threat Management (XTM) suite is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.
OpenAEV
Use threat intelligence to validate your security controls and improve your security posture, continuously.
Discover OpenAEVXTM Hub
The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.
Discover XTM HubExplore OpenCTI possibilities
Discover our diverse range of use cases to see how OpenCTI can operationalize your threat intelligence.
Elevating Threat Intelligence
Organizations must continuously monitor their threat landscape and take remedial action. A full-featured enterprise TIP such as OpenCTI lets cybersecurity teams turn raw data into actionable, strategic intelligence.
Read the competitive brief
OpenCTI becomes Controlware’s engine for scalable threat hunting
OpenCTI empowers SOC teams to conduct security operations driven by intelligence from internal and external sources, enabling them to save valuable time.
Read the customer storyThe Intelligence Gap: What’s Missing in Your Cyber Strategy
How continuous threat management helps CISOs stay ahead by prioritizing what really matters.
Download the white paperReady to see OpenCTI in action?
Try our free live demo or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.

