OSS TanbouSign in with GitHub

Connect threat intelligence and observations as sourced knowledge

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
10,088
Primary language
TypeScript
License
Not determined
Repository last updated
Oct 5, 2026
On this page

Overview

OpenCTI is a platform for storing and visualizing relationships among cyber threat intelligence, observations, attack techniques, organizations, and sources on a STIX 2 foundation. Its GraphQL API and connectors bring information into analyst workflows.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Manage threat intelligence with relationships and sources

It organizes technical and nontechnical intelligence as a knowledge graph with confidence, first and last seen times, and primary-source relationships. The pinned GraphQL schema defines Query, Mutation, and authorization directives.

Sources: [1][2]

Best fit

Fit teams consolidating multiple intelligence sources

It suits organizations combining MISP, TheHive, MITRE ATT&CK, and other inputs for analysis, sharing, and STIX 2 bundle or CSV exchange.

Sources: [1]

Before adoption

Review release, permissions, components, and license boundaries

Production requires databases, search, messaging, storage, and secret management. Community and Enterprise editions use different licenses, with source headers indicating which terms apply.

Sources: [1][3]

Official sources

  1. [1]OpenCTI README at 7.261002.0(2026-10-05)
  2. [2]OpenCTI GraphQL schema at 7.261002.0(2026-10-05)
  3. [3]OpenCTI repository license at 7.261002.0(2026-10-05)
  4. [4]OpenCTI 7.261002.0 release(2026-10-05)
Supplemental curator note

Before deployment, inventory required Query and Mutation fields and their @auth permissions in the pinned schema, then define source attribution, visibility, and retention for threat intelligence.

Try it in 3 steps

  1. 1

    Fetch the pinned schema

    Use Git to fetch 7.261002.0 and continue in opencti-schema-review. No platform service or container is started.

    git clone --branch 7.261002.0 --depth 1 https://github.com/OpenCTI-Platform/opencti.git opencti-schema-review && cd opencti-schema-review
  2. 2

    Extract Query and Mutation roots

    Require the pinned GraphQL schema and extract its root Query and Mutation blocks into opencti-root-operations.graphql.

    schema=opencti-platform/opencti-graphql/config/schema/opencti.graphql; test -s "$schema" && sed -n '/^type Query {/,/^}/p; /^type Mutation {/,/^}/p' "$schema" > opencti-root-operations.graphql && test -s opencti-root-operations.graphql
  3. 3

    Inspect operations and permissions

    Assert the stix Query requiring KNOWLEDGE and uploadImport Mutation requiring KNOWLEDGE_KNASKIMPORT. This inspects the schema and sends no API request to a running deployment.

    grep -F 'stix(id: String!): String @auth(for: [KNOWLEDGE])' opencti-root-operations.graphql && grep -F 'uploadImport(file: Upload!' opencti-root-operations.graphql && grep -F '@auth(for: [KNOWLEDGE_KNASKIMPORT])' opencti-root-operations.graphql
Check the official README

Growth

Growth trends · Last 30 days

10,088 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
315
Open PRs
193

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • cyber
  • cti
  • threat-intelligence
  • security
  • intelligence
  • osint
  • cybersecurity
Stars
10,088
Forks
1,468
Watchers
157
Open issues
1,979
Contributors
199
Owner type
Organization
Primary language
TypeScript
License
Not determined
Repository last updated
Oct 5, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?