97% of security teams cannot tell if their exposures are exploitable. Are you one of them?Read the report
Filigran
OpenCTI logo

Understand Your Threat Landscape and Act Decisively

Unify, operationalize and prioritize threat intelligence to make your SecOps better with our open-source threat intelligence platform – the intelligence pillar of CTEM and threat-informed defense.

G2 Leader - Threat Intelligence
G2 Users Love Us
G2 Europe Regional Leader - Threat Intelligence
G2 EMEA Regional Leader - Threat Intelligence
G2 High Performer - System Security
OpenCTI dashboard - automotive threat landscape monitoring
80%
faster threat detection and response
50%
fewer threat hunting investigations
<15 min
detection alert deployment time
Seconds
not hours or days for CTI enrichment

Collect, correlate and leverage

Operationalize threat intelligence like never before. Share it timely across your security teams and build threat-informed defense.

Unify Threat Intelligence with 300+ one-click integrations

Standardize all your threat intelligence, from commercial feeds, open source, industry groups or internal security tools, using a consistent STIX 2.1 data model, powerful visualizations and custom dashboards.

Combat alert fatigue, elevate your impact

Benefit from advanced automation and agentic AI for faster processing of the entire threat management life cycle so you focus on activities that matter. Generate finished TI reports in minutes, not hours or days.

Operationalize threat intelligence across SecOps

Share prioritized intelligence with your executives to take informed decisions. Feed it into your SecOps for improved detection and response. Scale your threat hunting capacity and validate your security posture, continuously.

Streamline incident response

Use OpenCTI case management for incident-related data and accelerate your investigations, including threat hunting. Improve your triage, containment and remediation capabilities.

Sign up for your 30-day free trial

Explore full OpenCTI Enterprise Edition features such as automated playbooks, priority intelligence requirements (PIRs), FINTEL, as well as AI-powered file imports, report generation and natural language search.

Trusted by intelligence teams worldwide

Rather than adding more tools or operational overhead, their model focuses on measurable outcomes. That’s what practical CTEM should look like — outcome-driven, integrated and scalable.
Chris Novak
Chris Novak
Cybersecurity Executive
As a Threat Intelligence Platform, OpenCTI offers valuable capabilities for managing cyber threat intelligence, particularly across tactical, technical, and strategic intelligence layers.
G2 reviews logo
Kevin G.
Head of CTI, Mid-Market (51-1000 emp.), on G2
One major success came from the PDF backdoor campaign. Using OpenCTI + HuntingGrid, we identified infections in 12 customers, none of which were detected by their XDR solutions. We detected the backdoor before it downloaded malware. This is our biggest win to date.
Controlware logo
Dominik de Groot
Dominik Degroot
Senior Cyber Security Analyst, Controlware GmbH
Filigran handles threat intelligence better than many of the market’s biggest players. Having opted for an Enterprise account, we have very regular discussions with their highly qualified CSM team. The support team is very responsive and assists us on many issues.
G2 reviews logo
Verified user in IT and Services
Enterprise (>1,000 emp.), on G2
OpenCTI is one of the few, if not the only, open-source solutions that fully leverages STIX 2.1 almost in its entirety. Beyond the data format, its integrations and architecture are state-of-the-art: microservices, scalability, security.
G2 reviews logo
Verified user in Telecommunications
Enterprise (>1,000 emp.), on G2

Threat-informed defense with OpenCTI

Operationalize threat intelligence across your security stack: feed SIEM and SOAR for automated detection, enrich EDR alerts with context, prioritize vulnerabilities, and enable threat-informed defense at scale.

Input

Threat feeds

Commercial / open source

Contextual data

300+ integrations

Other sources

Emails, documents, MISP

Processing

STIX 2.1
OpenCTI logo
Cyber Threat Intelligence
OpenCTI icon
Aggregate and automate using no-code playbooks
OpenCTI icon
AI-powered threat analysis and report generation
OpenCTI icon
Use case and incident management
OpenCTI icon
Create and track PIRs
OpenCTI icon
Granular RBAC and data segregation

Output

  • Share CTI: strategic, operational, tactical
  • Feed streamlined intelligence into SIEM & SOAR to improve detection & response
  • Scale threat hunting & incident response capacity

Cyber Threat Intelligence Platform

Manage and operationalize your cyber threat intelligence efficiently and effectively.

A GUI built for threat intelligence practitioners

Modern and intuitive dashboards with a STIX-structured knowledge hypergraph: pivot across actors, malware, TTPs and indicators with visual graphs, timelines and ATT&CK mappings.

OpenCTI dashboard

Filigran Browser Extension

New

Turn your web browser into a threat intelligence workstation. With a single click, scan any web page into a structured threat report, launch investigations or generate attack scenarios. Seamlessly integrated with both OpenCTI and OpenAEV.

Filigran browser extension - interactive demo

Adapt the platform to your requirements

Customize your dashboards depending on your use case: threat monitoring, threat hunting, incident response, disinformation and more. Benefit from the Filigran and community-built dashboard library.

OpenCTI custom dashboards - interactive demo

Work faster and analyze better with AI

Make AI your companion at every step: threat feed imports, search, insights and summaries, up to finished deliverables with the template and tone of your targeted audience.

OpenCTI AI insights - interactive demo

Automate scenarios and playbooks

Integrate both technical and non-technical information into a unified system, linking each piece of threat intelligence to its original source for a complete analytical perspective. Based on this information, take action through automation.

OpenCTI automation playbook

Role-based access control (RBAC)

Segregate data access and centralize access management via the authorized members and organizations mechanism. Particularly useful for threat intel sharing in large organizations with regional offices, or for managed service providers.

OpenCTI role-based access control

Centralized case management

Enhance threat detection and response by centralizing incident-related data, fostering real-time collaboration, and improving efficiency through automated workflows.

OpenCTI centralized case management

Threat management that scales with you

On-premise community edition, SaaS-based enterprise edition or support for air-gapped deployments: we have a model that works for you.

Free forever

Community Edition

Get started with OpenCTI CE on-premise using the open source releases, with help available through Filigran support packages.

  • Complete STIX 2.1 knowledge graph
  • All open source connectors
  • Community support on Slack
Contact us

Enterprise Edition

Commercial, licensed upgrade with advanced AI and automation capabilities plus dedicated support by the Filigran technical team.

  • AI-powered imports, summaries and insights
  • Automated playbooks and PIRs
  • Advanced RBAC, SSO and audit trails
  • Vendor support with SLAs
Contact us

SaaS hosting

A fully managed OpenCTI Enterprise Edition hosted by Filigran with self-service provisioning; air-gapped deployment also available.

  • Hosted and operated by Filigran
  • Enterprise Edition included
  • Self-service provisioning

Discover the ecosystem

Our eXtended Threat Management (XTM) suite is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.

OpenAEV logo

OpenAEV

Use threat intelligence to validate your security controls and improve your security posture, continuously.

Discover OpenAEV
XTM Hub

XTM Hub

The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.

Discover XTM Hub

Ready to see OpenCTI in action?

Try our free live demo or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.