Threat intelligence EU-developed

OpenCTI

Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors.

By Filigran · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
Filigran
Recorded country
France
Product model
Open core
Deployment
Self-hosted / SaaS
Software license
Mixed: Apache-2.0 Community Edition; OpenCTI Enterprise Edition License
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Designed and developed by French company Filigran; the repository does not establish that every contributor or hosting region is French.

Reported capabilities

  • Stores linked technical and nontechnical threat intelligence with source references.
  • Imports and exports STIX 2 and CSV data and exposes a GraphQL API.
  • Community Edition uses Apache-2.0; Enterprise Edition has a separate license.

Scope and limits

The freely accessible demonstration instance is not the SaaS offer; edition-specific capabilities and hosting location need individual checking.

Inspect the research evidence 6 source observations
  1. identity / origin / capabilities / deployment

    The project README calls OpenCTI a STIX 2 threat intelligence platform, names Filigran as designer and developer, and documents Docker/manual installation, API, import/export and connectors.

    Read source
  2. country

    Filigran's current privacy policy identifies Filigran SAS as its French group entity at 66 avenue des Champs Élysées, Paris.

    Read source
  3. license

    Current upstream license distinguishes Apache-2.0 Community Edition source from separately licensed Enterprise Edition source.

    Read source
  4. deployment

    Filigran offers self-hosted Community and Enterprise editions and a fully managed OpenCTI Enterprise Edition SaaS service, distinct from its live demo and trial.

    Read source
  5. license

    Filigran's current license page links a separate OpenCTI Enterprise Edition agreement and says Community Edition remains Apache-2.0.

    Read source
  6. maintenance

    Upstream release list has current 2026 platform releases.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

TAXII Capability

Exposes filtered intelligence collections through a TAXII 2.1 server; the collections require access credentials.

STIX Capability

Exposes STIX 2.1 data through filtered live streams using HTTP server-sent events. Stream connectors can consume create, update and delete events.

MISP Integration

Optional external-import connector pulls MISP events and attributes into OpenCTI as STIX 2.1 objects. It requires MISP API access; this connector imports in one direction.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs