← Back to all sparks
O

OpenCTI

ANALYTICS
Velocity6.3

Open cyber threat intelligence platform

OpenCTI ships FIPS-validated base images and a new vulnerability data model, targeting enterprise and government deployments.

fips-compliancethreat-intelligenceai-analysisdata-modelaccessibilityenterprise
Current state
OpenCTI is in a high-cadence operational hardening phase, releasing every 2–4 days. The recent window shows three parallel tracks: enterprise compliance (FIPS 140-3 validated Python/Node base image), platform-wide design unification (Filigran Design System v1 rollout), and data model expansion (new vulnerability module, score fields on threat actor and malware entities). The AI chatbot 'Ask Ariane' received multiple crash fixes, and a prior release added human-in-the-loop tool approval — signs that the AI analysis layer is maturing from experimental to production-grade.
Where it's heading
The combination of FIPS compliance, accessibility hardening, and enterprise-grade session key management signals a deliberate push toward government and regulated-sector deployments. The vulnerability module and inference rules that propagate vulnerability data across the knowledge graph suggest OpenCTI is building toward a more automated threat-correlation engine rather than just a data store.
Prediction
Ask Ariane's human-in-the-loop approval will likely move from opt-in to default as the team gains confidence in the AI tool set. Watch for more inference rules that auto-link threat entities, and for the vulnerability module to grow into a first-class surface with dedicated views and reporting.

Recent moves

  1. 1d ago

    7.260914.0 — infra maintenance, STIX segregation patch

    7.260914.0 is a maintenance release: dependency bumps, flaky test fixes, development stack migration from MinIO to pgsty/silo, and a configurable keep-alive timeout for ALB deployments. The STIX segregation fix (shared IDs in filtered streams) is the only user-visible correctness improvement — small but meaningful for multi-tenant operators.

    View source ↗
  2. 5d ago

    7.260910.0 — Filigran Design System v1 ships, accessibility and stream metrics

    7.260910.0 integrates Filigran Design System v1 across the frontend — a significant visual overhaul that ships alongside accessibility improvements and keyboard navigation for the left nav. Stream metrics for S3-offloaded events add observability for large deployments. Design system unification reduces future UI debt and signals that Filigran is consolidating its product family under a single design language.

    View source ↗
  3. 8d ago

    7.260907.0 — FIPS 140-3 base image, investigation graph enhancements

    7.260907.0 adopts a FIPS 140-3 validated base image for Docker deployments — a requirement for US federal and regulated-sector customers. Investigation graph now allows in-place entity creation. Dynamic filter improvements (CURRENT ENTITY, revoked filter) reduce the number of steps for complex threat correlation queries.

    View source ↗
  4. 12d ago

    7.260904.0 — session signature key derived from app encryption key

    7.260904.0's main change is deriving the session signature key from the application encryption key, eliminating the need for a separately managed session secret. This is a meaningful security hardening for operators who manage key rotation — fewer secrets to rotate, and the session key is now tied to the same key material as the rest of the app's cryptographic state.

    View source ↗
  5. 13d ago

    7.260902.0 — search and export bug fixes

    7.260902.0 is a small patch: a search query processing fix, an Arabic CSV export fix, and a range intersection bug in the backend. A merge-users feature sits behind a feature flag — groundwork, not a shipped capability. No user-facing features.

    View source ↗
  6. 14d ago

    7.260901.0 — vulnerability module, entity scoring, workflow UI expanded

    7.260901.0 adds a new vulnerability module to the data model, extends the scoring field to threat actors, intrusion sets, malware, incidents, and events, and applies the workflow UI to all entity types. These three together — vulnerability entity, entity scores, and unified workflows — expand the platform's automated correlation surface. The Ask Ariane chatbot also received critical crash fixes that blocked graph-view usage.

    View source ↗