OpenCTI
A self-hosted open-source platform for storing, organizing and visualizing cyber threat intelligence.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About OpenCTI
OpenCTI is an open cyber threat intelligence platform that you run yourself and use through a web interface. Security teams use it to collect and structure knowledge about threats and to visualize it.
The repository contains the platform, a worker component and a Python client, and it is under active development with over fourteen thousand commits. It suits organisations with analysts who manage threat intelligence, rather than individuals protecting a single computer.
Strengths
- Structured storage and visualization of threat intelligence
- Includes a Python client for automation
- Large, active open-source project
Limitations
- Needs a server and setup work to run
- Aimed at security teams rather than home users
Details
- Pricing
- FreeFree to self-host from the open-source repository.
- License
- Open source, license not stated
- Developer
- The OpenCTI contributors
- Platforms
- Web, Self-hosted
- How it runs
- Self-hosted
- Best suited for
- Security teams building a shared threat intelligence knowledge base
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to OpenCTI
Compare allSoftware that can replace OpenCTI for an important use case, and what changes if you switch.
MISP
An open-source threat intelligence platform for sharing, storing and correlating indicators of compromise.
MISP is a self-hosted open-source platform focused on sharing and correlating indicators of compromise between communities, with open taxonomies, galaxies and the PyMISP API.
Similar software
Related functionality, not necessarily a direct replacement.
Shuffle
An open-source security orchestration, automation and response (SOAR) platform for building workflows across security tools.
Maltego
Desktop tool for visually mapping relationships in OSINT investigations.
SpiderFoot
Automated open-source intelligence collection with 200 modules.
VirusTotal
Online service that checks a URL or file against many antivirus engines and URL scanners.
YARA
Pattern-matching engine for identifying and classifying malware samples.
DefectDojo
An open source, self-hosted vulnerability management platform that collects and tracks findings from security scanners.