OpenCTI Threat Intelligence Platform Overview | C3SA

KB-Filigran-001 — Overview of OpenCTI Threat Intelligence Platform

Purpose

This article provides a high-level overview of the OpenCTI Threat Intelligence Platform to support customer understanding of its role in cyber threat intelligence (CTI) operations, analysis, and sharing.

Overview

OpenCTI is an open-source threat intelligence platform developed by Filigran. It is designed to support the collection, structuring, analysis, and sharing of cyber threat intelligence across security, risk, and cyber defence functions.

The platform enables organizations to centralize threat intelligence using a standardized data model, supporting correlation across indicators, threat actors, campaigns, techniques, and observed activity.

Scope

This article provides conceptual and reference information only. Configuration, deployment, integrations, and operational workflows are environment-specific and governed by organizational policies and agreements.

This article does not provide:

  • Deployment or configuration instructions

  • Detection logic or automation workflows

  • Operational playbooks or procedures

Authoritative Documentation

Official Filigran documentation for OpenCTI is available at:

  1. https://docs.opencti.io/latest/

Support & Escalation

For advisory, integration, or service-related assistance, submit a support request through this portal.

C3SA Service Context

C3SA supports OpenCTI through advisory and integration services, including threat intelligence program design, use-case alignment, architecture guidance, and governance support.
C3SA does not operate OpenCTI as a managed service unless explicitly defined in a contractual agreement.

Compliance & Control Alignment (Informative)

This knowledge base article supports organizational awareness, documentation, and operational understanding related to threat intelligence and security operations. It may contribute to regulatory and compliance objectives depending on system design, deployment scope, and control implementation.
  • ITSG-33 (Canada – GC / PBMM): PL-2, SA-9, SI-4, IR-1 / IR-4, AU-2 / AU-6

  • CMMC (United States – DoD): SI.L2-3.14.1, IR.L2-3.6.1, AU.L2-3.3.1, RM.L2-3.11.1, CA.L2-3.12.1

  • ISO/IEC 27001:2022: A.5.1, A.5.19, A.5.23, A.5.24, A.8.16

  • FedRAMP (Moderate / High – Informative): PL-2, SA-9, SI-4, IR-4, AU-6

  • NIS2 (EU): Article 21(2)(a), (b), (d), (e)

  • DORA (EU – Financial Sector): Articles 5, 6, 10, 28

InfoImportant Note
This article does not constitute evidence of compliance, certification, authorization, or accreditation. Compliance outcomes depend on implemented controls, governance processes, and independent assessment results.