Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by FiligranSign In
Splunk SOAR  logo

Splunk SOAR

Detection & Response Enablement
Incident Response & Ticketing
A picture of U2hhcmVhYmxlUmVzb3VyY2VJbWFnZTpjYmIyYjg4ZC03YWUzLTQzMzMtYTY4Ni1lMWQ1MmRmYTZhNjA=

Overview

Integrates OpenCTI Threat Intelligence Platform with Splunk SOAR for threat intelligence management and incident response

The OpenCTI Integration for Splunk SOAR bridges OpenCTI's threat intelligence platform with your security orchestration workflows. It enables analysts to enrich artifacts (IPs, domains, hashes, URLs), search and create STIX observables and indicators, manage threat entities (threat actors, malware, intrusion sets, campaigns, vulnerabilities), and handle cases (Incident, RFI, RFT) — all without leaving Splunk SOAR. Bulk operations and relationship creation keep your OpenCTI knowledge base in sync with active investigations.

Basic information

Filigran
Romain Guignard
Third party integrations
Orchestration (SOAR)
April 23, 2026
6.9.0
0
    Splunk SOAR | OpenCTI Integrations Library | XTM Hub by Filigran