XTM Hub by Filigran
OpenCTI for Elastic Security logo

OpenCTI for Elastic Security

Detection & Response Enablement
A picture of RG9jdW1lbnQ6NTIyNDE0ZmUtOTk4Ni00MjU2LTg1M2QtNzhjZmM3YWJkN2Mx

Aperçu

The Elastic OpenCTI integration ingests threat intelligence from OpenCTI into Elastic, enriching security events with IOCs (indicators of compromise) and threat context so analysts can detect, investigate, and respond to attacks more effectively.

The Elastic OpenCTI integration enables the ingestion of threat intelligence indicators from an OpenCTI platform into Elastic.

It collects structured IOC data (such as IPs, domains, URLs, file hashes, and certificates) via the OpenCTI GraphQL API and maps them to ECS fields.

These indicators can then be searched, visualized, and used in detection rules to enrich security analysis and identify malicious activity in near real time.

Informations de base

Filigran
Nino Rowlands
Intégrations tierces (bientôt disponible)
Endpoint Detection & Response
19 août 2026
5.12.24
1

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».