OpenCTI
OpenCTI is an open-source threat intelligence platform for storing, analyzing, and sharing structured threat intelligence data in STIX 2.1 format. It supports connectors to external feeds and platforms, including isMalicious, enabling automated enrichment of indicators.
Frequently Asked Questions
What is OpenCTI?
OpenCTI is an open-source threat intelligence platform for storing, analyzing, and sharing structured threat intelligence data in STIX 2.1 format. It supports connectors to external feeds and platforms, including isMalicious, enabling automated enrichment of indicators.
How is OpenCTI related to STIX (Structured Threat Information Expression)?
OpenCTI and STIX (Structured Threat Information Expression) are both key concepts in threat intelligence. STIX is a standardized language for describing cyber threat intelligence in a machine-readable format. It enables organizations to share IOCs, TTPs, and threat actor profiles in a consistent way. STIX is often paired with TAXII for transport.
Related Terms
STIX (Structured Threat Information Expression)
STIX is a standardized language for describing cyber threat intelligence in a machine-readable format. It enables organizations to share IOCs, TTPs, and threat actor profiles in a consistent way. STIX is often paired with TAXII for transport.
TAXII (Trusted Automated eXchange of Intelligence Information)
TAXII is a transport protocol for sharing STIX-formatted threat intelligence between organizations. It defines how threat data is packaged, requested, and delivered. isMalicious provides a TAXII 2.1-compatible endpoint for enterprise consumers.
Threat Feed
A threat feed is a structured, continuously updated stream of IOCs and threat data from a single source or aggregator. Security tools ingest threat feeds to keep blocklists and detection rules current. Examples include Spamhaus DROP, abuse.ch URLhaus, and CISA KEV.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.