Explore the full potential of OpenCTI Enterprise Edition, start your 30 days free trial.Learn more
XTM Hub by FiligranSign In
Elastic Integration logo

Elastic Integration

Siem & Analytics

Overview

The Elastic OpenCTI integration ingests threat intelligence from OpenCTI into Elastic, enriching security events with IOCs (indicators of compromise) and threat context so analysts can detect, investigate, and respond to attacks more effectively.

The Elastic OpenCTI integration enables the ingestion of threat intelligence indicators from an OpenCTI platform into Elastic.

It collects structured IOC data (such as IPs, domains, URLs, file hashes, and certificates) via the OpenCTI GraphQL API and maps them to ECS fields.

These indicators can then be searched, visualized, and used in detection rules to enrich security analysis and identify malicious activity in near real time.

Basic information

Filigran
Nino Rowlands
Third party integrations
Detection (SIEM, XDR & EDR)
January 26, 2026
5.12.24
0
0