Cette page est affichée en anglais. Une traduction française est en cours.
ScriptsJul 20, 2026·3 min de lecture

OpenCTI — Open Source Cyber Threat Intelligence Platform

A unified platform for managing, analyzing, and sharing cyber threat intelligence using STIX2 standards with graph-based knowledge management.

Prêt pour agents

Installation agent prête

Cet actif peut être installé après choix du runtime, vérification du plan et exécution de la commande adaptée.

Native · 98/100Policy : autoriser
Surface agent
Tout agent MCP/CLI
Type
Skill
Installation
Single
Confiance
Confiance : Established
Point d'entrée
OpenCTI Platform
Commande d'installation directe
npx -y tokrepo@latest install 5edefb15-8419-11f1-9bc6-00163e2b0d79 --target codex

À exécuter après confirmation du plan en dry-run.

Introduction

OpenCTI is an open-source platform for managing cyber threat intelligence (CTI). It allows security teams to structure, store, analyze, and share threat data using the STIX2 standard. Built by Filigran, it provides a unified workspace for threat analysts to correlate indicators, track threat actors, and produce intelligence reports.

What OpenCTI Does

  • Stores and organizes threat intelligence as STIX2 objects with relationships
  • Provides a graph-based knowledge view to visualize connections between entities
  • Ingests threat feeds from MITRE ATT&CK, MISP, AlienVault OTX, and other sources via connectors
  • Supports collaborative analysis with workspaces, dashboards, and reporting tools
  • Exposes a GraphQL API for integration with SIEMs, SOARs, and ticketing systems

Architecture Overview

OpenCTI uses an event-driven architecture with Elasticsearch or OpenSearch for full-text indexing, Redis for caching and message brokering, S3-compatible storage for files, and RabbitMQ for connector communication. The backend is a Node.js application exposing a GraphQL API. Data is modeled as a knowledge graph following the STIX2 specification, stored in a combination of Elasticsearch documents and Redis streams.

Self-Hosting & Configuration

  • Deploy with Docker Compose using the official docker repository
  • Requires Elasticsearch or OpenSearch, Redis, RabbitMQ, and MinIO or S3
  • Configure environment variables for admin credentials, connector tokens, and platform URL
  • Install connectors as separate Docker containers that feed data into the platform
  • Production deployments should use dedicated Elasticsearch clusters and persistent volumes

Key Features

  • Native STIX2 data model with full relationship graph visualization
  • 100+ community connectors for automated threat feed ingestion
  • Role-based access control with organization-level data segregation
  • Customizable dashboards, reports, and investigation workspaces
  • GraphQL API and Python client library for automation and integration

Comparison with Similar Tools

  • MISP — focuses on indicator sharing and events; OpenCTI provides a broader knowledge graph approach
  • TheHive — incident response and case management; OpenCTI is CTI-focused with deeper analysis tools
  • Cortex XSOAR — commercial SOAR platform; OpenCTI is open-source and CTI-specialized
  • Yeti — lightweight threat intel repository; OpenCTI offers richer visualization and connector ecosystem
  • ThreatConnect — commercial CTI platform; OpenCTI provides comparable features as open source

FAQ

Q: What data sources can OpenCTI ingest? A: Over 100 connectors exist for MITRE ATT&CK, VirusTotal, AlienVault OTX, MISP, abuse.ch, and many more.

Q: Does OpenCTI support STIX2 import and export? A: Yes. STIX2 bundles can be imported and exported natively as the core data model.

Q: What are the hardware requirements? A: A minimum of 8GB RAM and 4 CPU cores for small deployments; production environments need significantly more for Elasticsearch.

Q: Can OpenCTI integrate with my SIEM? A: Yes. The GraphQL API and connector framework support integration with Splunk, QRadar, Sentinel, and others.

Sources

Fil de discussion

Connectez-vous pour rejoindre la discussion.
Aucun commentaire pour l'instant. Soyez le premier à partager votre avis.

Actifs similaires