TAXII Capability
Exposes filtered intelligence collections through a TAXII 2.1 server; the collections require access credentials.
An independent tool index
for incident response teams
Threat intelligence EU-developed
Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors.
By Filigran · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Designed and developed by French company Filigran; the repository does not establish that every contributor or hosting region is French.
The freely accessible demonstration instance is not the SaaS offer; edition-specific capabilities and hosting location need individual checking.
identity / origin / capabilities / deployment
The project README calls OpenCTI a STIX 2 threat intelligence platform, names Filigran as designer and developer, and documents Docker/manual installation, API, import/export and connectors.
Read sourcecountry
Filigran's current privacy policy identifies Filigran SAS as its French group entity at 66 avenue des Champs Élysées, Paris.
Read sourcelicense
Current upstream license distinguishes Apache-2.0 Community Edition source from separately licensed Enterprise Edition source.
Read sourcedeployment
Filigran offers self-hosted Community and Enterprise editions and a fully managed OpenCTI Enterprise Edition SaaS service, distinct from its live demo and trial.
Read sourcelicense
Filigran's current license page links a separate OpenCTI Enterprise Edition agreement and says Community Edition remains Apache-2.0.
Read sourcemaintenance
Upstream release list has current 2026 platform releases.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Exposes filtered intelligence collections through a TAXII 2.1 server; the collections require access credentials.
Exposes STIX 2.1 data through filtered live streams using HTTP server-sent events. Stream connectors can consume create, update and delete events.
Optional external-import connector pulls MISP events and attributes into OpenCTI as STIX 2.1 objects. It requires MISP API access; this connector imports in one direction.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs