OpenCTI
Open cyber threat intelligence platform
OpenCTI ships weekly and is rebuilding its connector catalog into a marketplace.
◆Recent moves
- 20h ago
Weekly release: data sanity stop, SBOM docs, merge performance
A mostly corrective weekly release: data sanity operations can now be stopped, SBOM format is documented, and a merge that hung on entities with large relationship counts because of an O(n×m) scan was fixed. Incremental upkeep on the current line rather than new surface.
View source ↗ - 5d ago
Weekly release: integrations experience and draft approval workflow
Closes the functional gaps in the new integrations experience — config import, works, facets, sorting, next run — and adds a draft approval workflow plus TAXII client errors surfaced in the UI. The XTM Hub connection points and reworked Filigran experience settings in the same release show the commercial layer being wired into the same screens.
View source ↗ - 12d ago
Weekly release: connector catalog becomes a faceted marketplace
The release that reframes the connector catalog as a faceted marketplace, retires the legacy HTML editor and its feature flags, and hardens workflows with full reset and a guard against publishing one that deletes an in-use status. Also adds a configurable webhook URI deny list and admin-forced password changes.
View source ↗ - 18d ago
Weekly release: live stream, groups and widget fixes
A fix-only weekly release covering live streams with advanced-option filters, group detail pages, workbench type selection and dashboard widget periods. No new capability.
View source ↗ - 19d ago
Weekly release: SBOM generation, custom views, ESM frontend
Adds syft-based SBOM configuration, extends custom views with date ranges and attribute widgets, relabels connector support tiers to Supported by Filigran and Supported by Community, and migrates the frontend to ESM. The support-tier rename is small in code and large in positioning.
View source ↗ - 25d ago
LTS 6: security backports and dependency updates
A long-term-support release carrying critical and security fixes — a starlette upgrade for CVE-2026-54282, direct axios, dompurify and graphiql updates, plus playbook enrichment fixes. Confirms the two-track model: enterprises on LTS get security work while the weekly line carries features.
View source ↗