OpenCTI
Open cyber threat intelligence platform
OpenCTI ships FIPS-validated base images and a new vulnerability data model, targeting enterprise and government deployments.
◆Recent moves
- 1d ago
7.260914.0 — infra maintenance, STIX segregation patch
7.260914.0 is a maintenance release: dependency bumps, flaky test fixes, development stack migration from MinIO to pgsty/silo, and a configurable keep-alive timeout for ALB deployments. The STIX segregation fix (shared IDs in filtered streams) is the only user-visible correctness improvement — small but meaningful for multi-tenant operators.
View source ↗ - 5d ago
7.260910.0 — Filigran Design System v1 ships, accessibility and stream metrics
7.260910.0 integrates Filigran Design System v1 across the frontend — a significant visual overhaul that ships alongside accessibility improvements and keyboard navigation for the left nav. Stream metrics for S3-offloaded events add observability for large deployments. Design system unification reduces future UI debt and signals that Filigran is consolidating its product family under a single design language.
View source ↗ - 8d ago
7.260907.0 — FIPS 140-3 base image, investigation graph enhancements
7.260907.0 adopts a FIPS 140-3 validated base image for Docker deployments — a requirement for US federal and regulated-sector customers. Investigation graph now allows in-place entity creation. Dynamic filter improvements (CURRENT ENTITY, revoked filter) reduce the number of steps for complex threat correlation queries.
View source ↗ - 12d ago
7.260904.0 — session signature key derived from app encryption key
7.260904.0's main change is deriving the session signature key from the application encryption key, eliminating the need for a separately managed session secret. This is a meaningful security hardening for operators who manage key rotation — fewer secrets to rotate, and the session key is now tied to the same key material as the rest of the app's cryptographic state.
View source ↗ - 13d ago
7.260902.0 — search and export bug fixes
7.260902.0 is a small patch: a search query processing fix, an Arabic CSV export fix, and a range intersection bug in the backend. A merge-users feature sits behind a feature flag — groundwork, not a shipped capability. No user-facing features.
View source ↗ - 14d ago
7.260901.0 — vulnerability module, entity scoring, workflow UI expanded
7.260901.0 adds a new vulnerability module to the data model, extends the scoring field to threat actors, intrusion sets, malware, incidents, and events, and applies the workflow UI to all entity types. These three together — vulnerability entity, entity scores, and unified workflows — expand the platform's automated correlation surface. The Ask Ariane chatbot also received critical crash fixes that blocked graph-view usage.
View source ↗