Elastic Integration
Siem & Analytics
Overview
The Elastic OpenCTI integration ingests threat intelligence from OpenCTI into Elastic, enriching security events with IOCs (indicators of compromise) and threat context so analysts can detect, investigate, and respond to attacks more effectively.
The Elastic OpenCTI integration enables the ingestion of threat intelligence indicators from an OpenCTI platform into Elastic.
It collects structured IOC data (such as IPs, domains, URLs, file hashes, and certificates) via the OpenCTI GraphQL API and maps them to ECS fields.
These indicators can then be searched, visualized, and used in detection rules to enrich security analysis and identify malicious activity in near real time.
Basic information
Filigran
Nino Rowlands
Third party integrations
Detection (SIEM, XDR & EDR)
January 26, 2026
5.12.24
0
0