OpenCTI: Open-Source Cyber Threat Intelligence Platform

OpenCTI is an open-source platform designed to help organizations manage their cyber threat intelligence (CTI) data and observables.

The platform, developed by Filigran, builds its data using a knowledge schema built on the STIX2 standards. It features a modern web application architecture with a GraphQL API and a user-friendly front end.

OpenCTI incorporates with other tools and applications, such as MISPTheHiveMITRE ATT&CK, etc. increasing its capability to serve as a central hub for cyber threat intelligence management.

The objective is to develop a comprehensive tool that facilitates users to effectively capitalize on technical (such as TTPs and observables) and non-technical information (such as suggested attribution, victimology etc.) hence ensuring that every piece of information is traceable back to its source.

Significant features include interlinking data points, tracking first and last-seen dates, assessing confidence levels, and other. It has been created in order to structure, store, organize and visualize technical and non-technical information about cyber threats. This empowers users to extract valuable insights and leverage meaningful knowledge from the raw data.

OpenCTI not only allows imports but also exports of data under diverse formats (CSV, STIX2 bundles, etc.). Connectors are presently developed to accelerate interactions between the tool and other platforms.

Also Read: How Blockchain Enhances Contract Security and Integrity in CLM Systems?

Editions of the Platform

OpenCTI platform has 2 different editions: Community (CE) and Enterprise (EE). The purpose of the Enterprise Edition is to provide additional and powerful features which require particular investments in research and development. You can enable the Enterprise Edition directly in the settings of the platform.

To understand what OpenCTI Enterprise Edition brings in terms of features, just check the Enterprise Editions page on the Filigran website. You can also try this edition by enabling it in the settings of the platform.

Use Cases of OpenCTI

The platform can be used in numerous contexts to handle threats management use cases from a technical to a more strategic level. OpenCTI has been designed as a knowledge graph, taking inputs (threat intelligence feeds, sightings & alerts, vulnerabilities, assets, artifacts, etc.) and generating outputs based on built-in capabilities and / or connectors.

Also Read: How AI Revolutionizes Backup, Recovery & Cybersecurity in IT?

Below are some examples of use cases:

  • Cyber Threat Intelligence knowledge base
  • Detection as code feeds for XDR, EDR, SIEMs, firewalls, proxies, etc.
  • Incident response artifacts & cases management
  • Vulnerabilities management
  • Reporting, alerting and dashboarding on a subset of data

Image Credit:  https://docs.opencti.io/latest/usage/getting-started/

Welcome Dashboard

The welcome page gives any visitor on the OpenCTI platform an overview of what’s happening on the platform. It can be replaced by a custom dashboard, created by a user (or the default dashboard set up in a role, a group or an organization).

Indicators in the Dashboard

Numbers

ComponentDescription
Intrusion setsNumber of intrusion sets.
MalwareNumber of malware.
ReportsNumber of reports.
IndicatorsNumber of indicators.

Charts & lists

ComponentDescription
Most active threats (3 last months)Top active threats (threat actor, intrusion set and campaign) during the last 3 months.
Most targeted victims (3 last months)Intensity of the targeting tied to the number of relations targets for a given entities (organization, sector, location, etc.) during the last 3 months.
Relationships createdVolume of relationships created over the past 12 months.
Most active malware (3 last months)Top active malware during the last 3 months.
Most active vulnerabilities (3 last months)List of the vulnerabilities with the greatest number of relations over the last 3 months.
Targeted countries (3 last months)Intensity of the targeting tied to the number of relations targets for a given country over the past 3 months.
Latest reportsLast reports ingested in the platform.
Most active labels (3 last months)Top labels given to entities during the last 3 months.

Installation

All you need to install the OpenCTI platform can be found in the official documentation. For installation, you can:

Download

OpenCTI is available for free on GitHub. Entire components are shipped as Docker images and manual installation packages. For a production deployment, the developers recommend deploying all components in containers, containing dependencies, using native cloud services or orchestration systems such as Kubernetes.

References

https://github.com/OpenCTI-Platform/opencti

https://docs.opencti.io/latest

https://docs.opencti.io/latest/usage/getting-started

Sehrish Shahid

Sehrish Shahid is Experienced technical content writer and marketing manager with a proven track record of delivering engaging and informative content in the tech industry. As a former computer science educator, she brings a unique blend of technical expertise and communication skills to effectively translate complex concepts into compelling narratives. Currently serving as the Marketing Manager at TechWrix, she excels in crafting content that resonates with both technical and non-technical audiences, driving brand awareness and engagement.

Recent Posts

Top Tech Conferences in March 2025

Success in the tech industry requires continuous learning, networking and staying updated with the latest…

5 days ago

Hackers Exploit VMware: Three Critical Zero-Days Found

Broadcom issued a warning today regarding three newly discovered VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, and…

6 days ago

Microsoft Unveils Dragon Copilot to Revolutionize Clinical Workflows with AI Voice Assistant for Healthcare

Microsoft has announced Dragon Copilot to revolutionize clinical workflows with AI voice assistant for healthcare.…

6 days ago

11 Emerging Trends in Multi-Cloud and Hybrid Cloud Strategies for 2025

Cloud computing continues to evolve, and businesses increasingly adopt multi-cloud and hybrid cloud strategies to…

1 week ago

Top 32 Linux Interview Questions and Answers

Every technology era brings new developments and breakthroughs, and Linux is no exception. Linux is…

1 week ago

Building a Robust Digital Infrastructure: The Role of SASE in Today’s Networking Landscape

Gartner introduced SASE, or Secure Access Service Edge, to revolutionize networking by integrating connectivity and…

1 week ago