Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
OpenCTI for Elastic Security logo

OpenCTI for Elastic Security

Detection & Response Enablement
A picture of RG9jdW1lbnQ6NTIyNDE0ZmUtOTk4Ni00MjU2LTg1M2QtNzhjZmM3YWJkN2Mx

Overview

The Elastic OpenCTI integration ingests threat intelligence from OpenCTI into Elastic, enriching security events with IOCs (indicators of compromise) and threat context so analysts can detect, investigate, and respond to attacks more effectively.

The Elastic OpenCTI integration enables the ingestion of threat intelligence indicators from an OpenCTI platform into Elastic.

It collects structured IOC data (such as IPs, domains, URLs, file hashes, and certificates) via the OpenCTI GraphQL API and maps them to ECS fields.

These indicators can then be searched, visualized, and used in detection rules to enrich security analysis and identify malicious activity in near real time.

Basic information

Filigran
Nino Rowlands
Third party integrations
Endpoint Detection & Response
August 19, 2026
5.12.24
1

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".