On this page
Overview
OpenCTI is a platform for storing and visualizing relationships among cyber threat intelligence, observations, attack techniques, organizations, and sources on a STIX 2 foundation. Its GraphQL API and connectors bring information into analyst workflows.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Manage threat intelligence with relationships and sources
It organizes technical and nontechnical intelligence as a knowledge graph with confidence, first and last seen times, and primary-source relationships. The pinned GraphQL schema defines Query, Mutation, and authorization directives.
Best fit
Fit teams consolidating multiple intelligence sources
It suits organizations combining MISP, TheHive, MITRE ATT&CK, and other inputs for analysis, sharing, and STIX 2 bundle or CSV exchange.
Sources: [1]
Before adoption
Official sources
- [1]OpenCTI README at 7.261002.0(2026-10-05)
- [2]OpenCTI GraphQL schema at 7.261002.0(2026-10-05)
- [3]OpenCTI repository license at 7.261002.0(2026-10-05)
- [4]OpenCTI 7.261002.0 release(2026-10-05)
Supplemental curator note
Before deployment, inventory required Query and Mutation fields and their @auth permissions in the pinned schema, then define source attribution, visibility, and retention for threat intelligence.
Try it in 3 steps
- 1
Fetch the pinned schema
Use Git to fetch 7.261002.0 and continue in opencti-schema-review. No platform service or container is started.
git clone --branch 7.261002.0 --depth 1 https://github.com/OpenCTI-Platform/opencti.git opencti-schema-review && cd opencti-schema-review - 2
Extract Query and Mutation roots
Require the pinned GraphQL schema and extract its root Query and Mutation blocks into opencti-root-operations.graphql.
schema=opencti-platform/opencti-graphql/config/schema/opencti.graphql; test -s "$schema" && sed -n '/^type Query {/,/^}/p; /^type Mutation {/,/^}/p' "$schema" > opencti-root-operations.graphql && test -s opencti-root-operations.graphql - 3
Inspect operations and permissions
Assert the stix Query requiring KNOWLEDGE and uploadImport Mutation requiring KNOWLEDGE_KNASKIMPORT. This inspects the schema and sends no API request to a running deployment.
grep -F 'stix(id: String!): String @auth(for: [KNOWLEDGE])' opencti-root-operations.graphql && grep -F 'uploadImport(file: Upload!' opencti-root-operations.graphql && grep -F '@auth(for: [KNOWLEDGE_KNASKIMPORT])' opencti-root-operations.graphql
Growth
Growth trends · Last 30 days
10,088 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 315
- Open PRs
- 193
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- cyber
- cti
- threat-intelligence
- security
- intelligence
- osint
- cybersecurity
- Stars
- 10,088
- Forks
- 1,468
- Watchers
- 157
- Open issues
- 1,979
- Contributors
- 199
- Owner type
- Organization
- Primary language
- TypeScript
- License
- Not determined
- Repository last updated
- Oct 5, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Directus38,022 Stars
2 shared tag(s) · 1 shared category(s) · Same language
layer APIs, a visual Studio, and AI/MCP on top of SQL databases
TypeScript - Web-Check35,010 Stars
2 shared tag(s) · 1 shared category(s) · Same language
collect a website's public signals, architecture, and attack surface in one view
TypeScript - Sherlock93,251 Stars
2 shared tag(s) · 1 shared category(s)
Check username candidates across more than 400 social networks with an OSINT CLI
Python - Bitcoin Core90,309 Stars
2 shared tag(s) · 1 shared category(s)
Fully validate Bitcoin peer-to-peer blocks and transactions yourself while optionally running wallet and RPC services on the same node
C++ - Vaultwarden68,507 Stars
2 shared tag(s) · 1 shared category(s)
operate a Bitwarden-client-compatible API and web vault as a lightweight self-hosted server
Rust - Keycloak37,134 Stars
2 shared tag(s) · 1 shared category(s)
an IAM server providing authentication and authorization to applications
Java
Report incorrect information
Tell us if any listing information is incorrect or outdated.