Open CTI
Open-source platform to store, organize, and analyze threat intelligence and cyber observables.
Open the official app on www.opencti.io
This tool is hosted by its maintainers. Click below to open www.opencti.io in a new tab — it's their official demo.
Browse security tools →What's next with Open CTI?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Open CTI?
OpenCTI is an open-source platform designed to help organizations manage and analyze cyber threat intelligence (CTI). It enables security teams to structure, store, organize, and visualize technical and non-technical data about cyber threats, streamlining threat intelligence workflows. The tool is particularly useful for enterprises, government agencies, and cybersecurity professionals who need to prioritize risks and respond to threats effectively. OpenCTI addresses critical challenges in threat management, such as identifying exploitable vulnerabilities, correlating data from disparate sources, and reducing the time spent on non-critical risks. By integrating with tools like OpenAEV and OpenGRC, it supports end-to-end threat management processes, from detection to remediation.
How it works
OpenCTI is a threat intelligence platform developed by Filigran, part of the XTM (eXtended Threat Management) ecosystem. It focuses on unifying threat intelligence, security validation, and remediation to help organizations prioritize and act on the most critical risks. The platform is built on the AGPL-3.0 license, making it accessible for both individual users and enterprises. Its primary purpose is to bridge the gap between raw threat data and actionable insights, enabling security teams to focus on high-impact vulnerabilities. OpenCTI excels in correlating threat data from multiple sources, such as network logs, malware samples, and external feeds. It supports advanced adversary simulation and continuous exposure validation, helping users determine which vulnerabilities are actually exploitable. For example, it can assess whether a known vulnerability in a system is actively being targeted by adversaries.
How to use it
- 1Deploy OpenCTI using Docker or a cloud environment, integrating it with OpenAEV and OpenGRC for full XTM functionality. 2. Import threat intelligence data from internal sources or external feeds like MITRE ATT&CK. 3. Use the platform's correlation engine to identify patterns and prioritize risks based on exploitability. 4. Generate reports and visualize threat landscapes to guide remediation efforts. Practical tips include leveraging the API for automation, configuring custom dashboards, and regularly updating threat intelligence feeds to ensure data accuracy.
What it can do
- threat intelligence platform
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/OpenCTI-Platform/opencti
- license: AGPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Requires significant expertise to configure and integrate with other tools
- Depends on high-quality input data for accurate threat analysis
- Limited out-of-the-box support for proprietary threat intelligence formats
- Scalability challenges for very large datasets without additional infrastructure
Understanding the result
Open-source platform to store, organize, and analyze threat intelligence and cyber observables.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (OpenCTI-Platform/opencti)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with OpenCTI-Platform/opencti. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- AGPL-3.0 License
Upstream project
Frequently asked
What is the primary use case for OpenCTI?
OpenCTI is primarily used to manage and prioritize cyber threat intelligence by identifying exploitable vulnerabilities, correlating data from disparate sources, and enabling rapid response to high-risk threats. It is particularly valuable for organizations needing to integrate threat intelligence with security operations and compliance workflows.
How does OpenCTI handle threat intelligence correlation?
OpenCTI uses its built-in correlation engine to analyze data from internal and external sources, such as network logs, malware samples, and threat feeds. It identifies patterns and relationships between threats, helping users prioritize risks based on factors like exploitability and potential impact. Integration with OpenAEV enhances this by validating whether specific vulnerabilities can be exploited in real-world scenarios.
How do I deploy OpenCTI in a production environment?
Deploy OpenCTI using Docker containers or a cloud infrastructure, ensuring compatibility with OpenAEV and OpenGRC for full XTM functionality. Start by setting up the database, configuring API keys for external feeds, and importing initial threat intelligence datasets. Regularly update the platform and integrate with SIEM tools for continuous monitoring.
How does OpenCTI compare to commercial threat intelligence platforms?
OpenCTI differs from commercial platforms like IBM X-Force or CrowdStrike by offering open-source flexibility and customization. While commercial tools often provide pre-built dashboards and automated workflows, OpenCTI requires more technical expertise to configure. It is ideal for organizations prioritizing cost-effective, customizable solutions over out-of-the-box features.
What should I do if OpenCTI fails to import a threat feed?
Check that the feed format matches OpenCTI's supported standards (e.g., STIX 2.1). Verify API credentials and network connectivity. If the issue persists, consult the OpenCTI documentation or community forums for troubleshooting steps related to specific feed formats or integration issues.