NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Python API client for OpenCTI.
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
455 releases · first in 2019
[doc] openaev : correct link to openaev documentation by @MarineLeM in https://github.com/OpenCTI-Platform/opencti/pull/14118
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.15...6.9.16
One column per quarter.
[backend] Delete workbenches as other files when deleting an entity (#14301) by @SamuelHassine in https://github.com/OpenCTI-Platform/opencti/pull/143
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.14...6.9.15
[deps] Update dependency axios to v1.13.3 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/14250
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.13...6.9.14
[backend] Optimize JSON mapper memory usage and performance by @OctaveLaventure in https://github.com/OpenCTI-Platform/opencti/pull/14042
update_linked and delete_linked to draft (#14027) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/14028Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.12...6.9.13
[frontend] - (streams) Add 1 click deploy #14171 by @carinelebas in https://github.com/OpenCTI-Platform/opencti/pull/14208
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.11...6.9.12
This release introduces an issue: creating observables from the UI is no longer possible for several observable types. We advise to skip this version.
This release introduces an issue: creating observables from the UI is no longer possible for several observable types. We advise to skip this version.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.10...6.9.11
[frontend] Softwares list in Vulnerability details (#14139) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/14151
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.9...6.9.10
[backend] fix post filtering in elPaginate (#12701) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/13582
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.8...6.9.9
[deps] Update dependency body-parser to v2.2.2 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/13963
h1 size for fintel template preview (#13445) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/13998Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.7...6.9.8
[frontend] - (XTMHub - FreeTrials) Change redirection URL on learn more #13933 by @hervyt in https://github.com/OpenCTI-Platform/opencti/pull/13934
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.6...6.9.7
[frontend] Add has-label in relationship type filter values for knowledge widgets (#13837) by @Archidoit in https://github.com/OpenCTI-Platform/openct
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.5...6.9.6
[backend] Fix default dashboard for a group not taken into account (#11811) by @marieflorescontact in https://github.com/OpenCTI-Platform/opencti/pull
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.4...6.9.5
[backend] add stream type managers state tracking & state recovery (#13254) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/1325
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.3...6.9.4
[docs] Move github pages configuration (#13720) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/13722
nx to octi/opencti repo (#13767) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/13743Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.2...6.9.3
[backend] Allow Array function in platform notifier (#13641) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/13655
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.1...6.9.2
[client] remove entirely deprecated methods (#13521) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/13617
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.0...6.9.1
Selective processing of entities (indicators, vulnerabilities, etc.) linked to specific PIR threats
Dear community, we're excited to announce the launch of OpenCTI 6.9.0! 🥳
This release focuses on solving key pain points and unlocking new use cases:
🌟 Make Priority Intelligence Requirements actionable (EE)
This allows teams to move beyond static threat lists and automatically respond to prioritized threats. Playbooks now execute targeted actions on the threats that matter most to your organization, reducing noise and accelerating response times to high-priority threats.
🤖 CTI driven assessment by integrating OpenCTI & OpenAEV (CE)
Security assessments can now be initiated from threat intelligence in OpenCTI, executed as simulations in OpenAEV, and results automatically imported back into OpenCTI as actionable gap analyses, within a new entity type Security coverage. Additionally, the creation and generation of security coverages can now be fully automated through our playbook engine. This capability, combined with the ability to trigger playbooks based on PIR events, enables you to automatically test your defense posture against threats identified as relevant for your organization.
This first implementation lays the foundation for transforming security assessments from manual processes into automated, threat-driven continuous validation
See details in our documentation.
💡 Draft Authorize members, to protect from unwanted modification or approval & Service Account bypass (CE)
To get an approval workflow for draft, the first step has been for us to enable Authorize Members on Drafts.
This way, when creating a draft manually or via file upload, you will be able to define authorized members at draft creation. This will ensure no user will be able to validate your draft on your behalf or even modify it without your consent.
This change required us to introduce another related change: Service Account now bypasses Authorize Members. The rationale behind this behavior is that Service Accounts should be able to enrich observables within a Draft, even if the draft has some Authorize Members enabled. To be clear: even if Service Accounts are not added as Authorized Members, they will get the Edit permission on the entity (draft, containers). This bypass is a default behavior that cannot be changed.
👤 Avoid some IOC to decay by introducing Decay Exclusion Rules (CE)
Some IOCs should never expire: for instance, Yara rules (or any detection rules) should never be revoked, to avoid having any tools like your SIEM, XDR, EDR… failing to detect a malicious IOC.
This is the purpose of Decay Exclusion Rules: you can filter on some IOC attributes to avoid having the matching IOCs fall under a decay rule. Ultimately, it prevents your IOCs from being automatically revoked.
Please be careful with the decay exclusion rules:
This feature should also help you if you use sources that also manage the lifecycle of your IOCs to avoid having 2 automated lifecycle management applied to your IOCs.
See details in our documentation.
🛡️ Framework to import data in the platform via Form Intake (CE)
Creating data in the platform can be a complex task, especially because:
As a result, we’re proud to introduce the Form Intake, to streamline the collection of threat intelligence data from external sources and stakeholders through structured forms.
Form intakes allow Administrators to define a form to specify which entities should be created and their needed mandatory fields. Also, Administrators can decide to automatically create relationships between entities created via the form and to create them as a draft or not. Additionally, the administrator can also label the entity or a specific field with a non-STIX label: this helps users not familiar with the platform and/or STIX to easily enter information in the platform.
This feature has proven (since available from 6.8.X) to be useful in the FIMI context, sharing communities such as ISACs or even Incident reporting.
Please provide as much feedback as possible on this feature, which should help you consolidate your database with consistent data.
🎨 UI & UX improvements (CE)
We keep working on the UI & UX part to provide a better experience to users.
💡 Many other improvements (new capa for playbooks, pattern matching for IOC…)
New observable to model SSH keys (CE): a new observable type, SSH key, has been introduced to help the modelization of SSH keys.
Email notifier improvements (CE): In the current implementation of our platform's mailer notifier, the content is generated in HTML format. However, the description field of an entity is formatted in Markdown by default. We introduce a solution for converting Markdown-formatted content to HTML to ensure consistency and proper rendering in the mail notifications.
Pattern matching filter (CE/EE): now also available for indicators in playbook, Live streams, CSV Feeds, and TAXII Collection.
Composer configuration (EE): for configuring a global HTTP/HTTPS proxy for connector network connectivity.
Change the capability linked to playbooks (EE): Playbook capability has been split into two capabilities:
This should help administrators in managing the RBAC with a fine-grained approach. See details in our documentation.
Change of capability for Delete & Merge knowledge (CE): After some feedback from the community, we have decided to change the capability to merge & delete, to ensure that that now merge and delete are now two specific capabilities.
Add original value in the logs (CE): Understanding the changes on an entity in detail is key in Cybersecurity. Therefore, we have improved data traceability by allowing users to view the detailed changes about an entity. Now, each line of the history of an entity is clickable, to give you more details about the initial value and the new one.
Send to template in playbook (EE): a new box “Send email from template has been introduced”, allowing you to send email using the templates defined in parameters/security. The end goal is to send an email to users, leveraging the HTML capabilities of the Email template Editor. This template only supports user-related variables and not entity-related variables. Additionally, this capability supports some dynamic variables, such as selecting “dynamic objects from the object in bundle” (organization), to extract directly the users from the organization triggering the playbook. More info on our documentation page.
Introduction of an onboarding email template (EE): for new platforms, an email template for user onboarding will be prepopulated, to help administrators save time in setting up their platform.
Support of CVSS 3.0 vector strings (CE): until now, platform only supported CVSS 3.1, but is now able to also support CVSS 3.0 vector strings.
🔗 Connectors & Integrations (CE)
Regarding connectors and integrations, this milestone brought several new connectors.
Import Connectors
Enrichment Connectors
Stream Connectors
Multiple connectors were added to the OpenCTI catalog, enabling one-click deployment (Feedly, Google TI, Recorded Future, CrowdStrike, VirusTotal, Mandiant)
[deps] Update vitest monorepo to v4 (major) by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/12940
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.16...6.8.17
[client] deprecate methods no longer working following removal of cache_index (#13521) by @JeremyCloarec in https://github.com/OpenCTI-Platform/openct…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.15...6.8.16
[backend] Introduce option to restrict the capacity to change the platform sender email (#13214) by @richard-julien in https://github.com/OpenCTI-Plat
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.14...6.8.15
[deps] Update rabbitmq Docker tag to v4.2.0 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/13159
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.13...6.8.14
[deps] Update dependency @graphql-codegen/typescript-resolvers to v5.1.2 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/13203
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.12...6.8.13
[frontend] Allow immediate deletion of managed connectors after stop request (#12474) by @maelv-filigran in https://github.com/OpenCTI-Platform/openct
yarn build fails with error TS2740, missing propertiesFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.11...6.8.12
[backend] change SSO absolute redirection (#13011) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/13012
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.10...6.8.11
[backend] improve update message (#12051) by @marieflorescontact in https://github.com/OpenCTI-Platform/opencti/pull/12978
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.9...6.8.10
Update aws-sdk-js-v3 monorepo to v3.913.0 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/10907
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.8...6.8.9
Update react monorepo by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/10918
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.7...6.8.8
⚠️ This release introduces an issue that can prevent the use of several connectors, please use 6.8.8 in that case.⚠️
⚠️ This release introduces an issue that can prevent the use of several connectors, please use 6.8.8 in that case.⚠️
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.6...6.8.7
Update dependency source-map to v0.7.6 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/12768
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.5...6.8.6
[frontend] enhance catalog UI (#12652) by @esrevi in https://github.com/OpenCTI-Platform/opencti/pull/12686
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.4...6.8.5
[backend] add initial score on vulnerabilities updates function (#12544) by @ValentinBouzinFiligran in https://github.com/OpenCTI-Platform/opencti/pul…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.3...6.8.4
[frontend] connector instance name (#12572) by @esrevi in https://github.com/OpenCTI-Platform/opencti/pull/12608
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.2...6.8.3
[frontend] Fix default dashboard access warning (#11556) by @MTorbay-Filigran in https://github.com/OpenCTI-Platform/opencti/pull/12554
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.1...6.8.2
[backend] add entity type verification by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/12502
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.8.0...6.8.1
The vulnerability and software models have been enhanced with additional attributes, specifically “first seen active” for Vulnerability and “product”…
Dear community, we're excited to announce the launch of OpenCTI 6.8.0! 🥳
This release focuses on solving key pain points and unlocking new use cases:
🌟 Priority Intelligence Requirements (PIR) (EE)
We are thrilled to introduce the first implementation of PIR (Priority Intelligence Requirement), a powerful feature that enables users to concentrate only on the threats that matter most to them. This enhancement is designed to help users navigate and prioritize among the vast data within the platform more effectively.
With PIR, users can define the specific criteria such as their organization's industry, locations they operate in, or any sectors and regions they wish to monitor. By setting these criteria, the platform will automatically flag relevant threats with an associated relevance score and highlight priority reports to review. This initial version focuses on helping you identify threats relevant to your organization. Future releases will enable you to operationalize PIR-identified threats in your daily workflows. We welcome your feedback on how to make this most valuable for you.
⚙️ Connector Catalog and Manager (EE)
We are excited to introduce the connector catalog and manager, a feature designed to streamline the deployment and configuration of connectors directly from the user interface.
To achieve this, we've added a connector catalog in the platform's ingestion section, listing connectors currently available for deployment through the interface. This catalog initially features a first selection of "Verified" connectors, with plans to expand the collection over time. From this catalog, users have now the possibility to view details, deploy, and configure these connectors directly within the interface.
We've also enhanced the connector view with new management capabilities. Users can now easily start and stop “managed connectors” and access their logs directly, significantly improving troubleshooting efficiency.
For on-premise deployments, this feature requires adding a new component called "xtm-composer" to the OpenCTI technology stack. This component connects your OpenCTI platform to major container orchestration systems and handles the deployment and lifecycle management of your connectors. More info on: https://github.com/FiligranHQ/xtm-composer
🤖 Chatbot/AI assistant (EE)
You have a CTI question? Ask Ariane!
We are launching the first iteration of Ariane, our brand new Agentic AI assistant, an interface that will change the way users interact with Cyber Threat Intelligence! Ariane is designed to understand complex questions related to the CTI and will leverage all the structured knowledge stored in your platform and also all the OpenCTI documentation.
With this initial release, users will have the ability to ask questions to their OpenCTI platform in natural language! Thanks to Ariane, you don’t need to know the arcane of STIX and OpenCTI to get answers anymore! It greatly lower the barrier of entry for new user and also reduce the time to create reports from structured CTI. Future iterations will further enhance its capability to deliver even deeper insights and will allow to take action on retrieve Intel, like creating a Objects or using features of the platform.
Mind that it is a Preview feature. Usage is limited at the moment. Try it and, if you want more, just reach out to us and we’ll work together on the next step!
If you’re curious on what’s happening under the hood, this feature leverages a dedicated set of tools bundled in an MCP server, publicly available here https://github.com/FiligranHQ/xtm-mcp. The main challenge to tackle was being able to translate a natural language question into a query in graphQL, the technology running the OpenCTI database. Because this is not something easy, we decided to share this capabilities through the standard Model Context Protocol, so that the largest number of OpenCTI users can keep on their AI journey.
💡 Import AI document (EE)
This release features significant improvements to our entity extraction service, accessible through our AI Import Document connector. The service now recognizes a broader range of entities (Organization, Sector, Channel, Tool, Individual, Region). Beyond this expanded recognition capability, the service can now identify and establish relationships (Uses, Targets, Located-at, Exploits, Originates-from) between detected entities.
👤 User management (CE and EE)
The user management part has been enhanced with three new capabilities that improve administrative efficiency:
🛡️ Data Quality & Security Enhancements (CE and EE)
As part of our ongoing commitment to data excellence and security, we're pleased to introduce several enhancements designed to strengthen data quality, improve reliability, and reinforce the protection of your information across our platform.
🎨 UI & UX improvements (CE)
We are aware that the UI & UX of the platform can sometimes be difficult to grasp. We are working towards improving this part.
🔄 Some other improvements have also been provided:
:opencti: XTM HUB: One click deploy (CE)
During the 6.8, XTM hub has released the ability to enroll your platform onto XTM hub. From an added value perspective from OpenCTI, this means that you can also use the newly deployed feature “One Click Deploy”, to easily deploy Dashboard & CSV feeds directly from the Hub.
Directly browse, from your OpenCTI platform the service you need on XTM Hub and within one click, get it into your OpenCTI platform!
🔗 Connectors & Integrations (CE)
Regarding connectors and integrations, this milestone brought several new connectors.
[backend] Simplify version get (#12287) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pull/12365
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.19...6.7.20
[backend/frontend] refactor: use new query parameter namings by @Kroustille in https://github.com/OpenCTI-Platform/opencti/pull/12244
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.18...6.7.19
[frontend] New shared Organisations drawer (#11246) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/11653
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.17...6.7.18
[frontend] Fix issue with dissemination list EE icon (#12148) by @SarahBocognano in https://github.com/OpenCTI-Platform/opencti/pull/12184
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.16...6.7.17
Update dependency filigran-icon to v0.18.1 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/11691
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.15...6.7.16
[backend] fix provisioning numbers (#11668) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/11981
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.14...6.7.15
[frontend] fix delete stix ref relationship (#11631) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/12086
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.13...6.7.14
[frontend] feat: use hub platform token during 1 click deploy by @Kroustille in https://github.com/OpenCTI-Platform/opencti/pull/12020
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.12...6.7.13
[frontend] fix several hover layout in Techniques by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/11960
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.11...6.7.12
[frontend] chip in list default style (#11830) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/11959
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.10...6.7.11
backendVulnerabilities: support "_" & "-" in CVSS values by @maelv-filigran in https://github.com/OpenCTI-Platform/opencti/pull/11799
/Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.9...6.7.10
[frontend] add attributes in widget column selection for Vulnerabilities and Organizations (#11546) by @Archidoit in https://github.com/OpenCTI-Platfo…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.8...6.7.9
[frontend] fix missing name for target based-on relationships (#11600) by @marieflorescontact in https://github.com/OpenCTI-Platform/opencti/pull/1165
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.7...6.7.8
[frontend] prevent backdrop interaction when filter popover is open (#11594) by @maelv-filigran in https://github.com/OpenCTI-Platform/opencti/pull/11
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.6...6.7.7
Introduce fields product on software and first_seen_active on vulnerability by @SamuelHassine in https://github.com/OpenCTI-Platform/opencti/pull/1170…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.5...6.7.6
[frontend] Fix workspace duplication dialog closing unexpectedly on internal clicks (#11010) by @maelv-filigran in https://github.com/OpenCTI-Platform
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.4...6.7.5
[frontend/backend] fintel template variable name checker should allow - and _ (#11392) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pu
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.3...6.7.4
[backend] Add check in identifier for potential deduplication by @SarahBocognano in https://github.com/OpenCTI-Platform/opencti/pull/11555
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.2...6.7.3
[backend] Fix missing neighbours when adding to container (#11478) by @marieflorescontact in https://github.com/OpenCTI-Platform/opencti/pull/11500
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.1...6.7.2
[backend] Compute totals to have less counter updates on changes (#11251) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/11161
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.7.0...6.7.1
Vulnerability Management & Data model
Dear community, we're excited to announce the launch of OpenCTI 6.7.0! 🥳
This release focuses on solving key pain points and unlocking new use cases:
🔔 Notifications Spamming (CE)
Notifications have been improved to avoid spamming users. Starting from 6.7, all platforms will have a buffer enabled by default for all notifications coming from OpenCTI.
Practically, if a single edit matching a live trigger is made on an entity, notification for this single change will remain real time. However, if multiple edits matching a live trigger are made on a single entity which would result in multiple notifications, only a single one will be send (To be clear, you will receive one notification per trigger). By default, the timer is set to 60 seconds.
This behavior will affect all notifications type (email, in-app, webhook) and will be enabled by default for all platforms (behavior set at affecting platform level, therefore affecting all users of the platform).
You can both disable this feature or change the timer duration, through configuration parameters PUBLISHER_MANAGER__ENABLE_BUFFERING and PUBLISHER_MANAGER__BUFFERING_SECONDS. See documentation
💾 Saved Filters & Dynamic filtering (CE)
We are also enhancing our filtering capabilities with the introduction of Saved Filters. Users can create filters tailored to their specific needs and save them for future use. These filters can be quickly accessed, removing the need to re-enter search criteria for frequent queries. Furthermore, users have the flexibility to update their saved filters as their analysis requirements change.
Dynamic filtering is also a new addition to our release: the concept of dynamic filtering is the same than the pre-queries in dashboards. It aims to identify a subset of entities/relations matching your dynamic filtering & then apply the rest of the filter on the data found through this dynamic filtering. On relationship screen, two filters Dynamic From & Dynamic To allow you to filter on each side of the relation, to get more precise results. At entity level, In regards of (dynamic) will let you be more specific in your “in regards of filters”, by applying additional filters (and not only filtering on the specific entity). Therefore, you will be able to perform queries such as “list all victims of malwares having the type ransomware”.
🖥️ UI & UX Improvements (CE)
We are aware that the UI & UX of the platform can sometimes be difficult to grasp. We are working towards improving this part. This is why we have made several changes to enhance accessibility and overall user experience. The change include:
We have also revamped the "Data/Import" view to better organize resources. Now, all uploaded files, workbenches, and drafts are centralized in one place for enhanced accessibility and simplified organization. As a result, the "Draft" menu has been relocated to this view.
🛡️Security Posture & MITRE ATTACK Sub Techniques (CE)
Gaining insight into your cyber defense coverage in relation to the techniques used by threats is essential for identifying detection gaps and improving your security posture. To support this goal, we have introduced a new entity "Security Platform" which allows you to manually map the techniques your detection tools are intended to cover (should-cover relationship) and compare them with actual threat techniques. To facilitate this process, the MITRE ATT&CK Matrix view has been enhanced, enabling easy comparison between the techniques theoretically covered by your security tools and those used by threats. By leveraging this feature, organizations can achieve improved alignment of their security strategies with real-world threats, facilitating proactive defense measures and strategic improvements over time.
In addition to this new capability, we have enhanced the "MITRE ATT&CK Matrix" view by adding support for sub-techniques. It is now easy to see the number of sub-techniques used by a threat via a badge. Additionally, you can expand a parent technique to display its associated sub-techniques, providing greater visibility into the details of the tactics employed by threats.
🎨 Fintel PDF Export Branding Customization (EE)
To ensure that report exports reflect your corporate identity, we have introduced new customization options for Fintel PDF exports, providing a more personalized and tailored presentation. Beginning with version 6.7.0, you can configure a Fintel design by uploading your company logo and choosing custom colors to be applied throughout your Fintel PDF reports. This update guarantees that your exported documents are in line with your organization's branding, maintaining a consistent visual identity.
🔐 Reset Password (CE)
We are excited to introduce the new Reset Password feature in this release. This enhancement addresses a key requirement from our user community for better password management and improved security. Users can now initiate a password reset process directly from the login page. Upon request, a secure code will be sent to the registered email address, allowing users to set a new password.
🚀 JSON Mapper/Feed (CE)
In addition to our CSV Feed/Mapper capability, we are pleased to announce the new JSON Feed/Mapper feature, which enables seamless ingestion of JSON-formatted files and feeds. With this enhancement, you can effortlessly import, parse, and map both simple and complex JSON data structures, offering greater flexibility for integrating diverse cyber threat intelligence sources.
We’ve also improved the scheduling of our built-in Feed ingesters. You can now configure a specific fetching interval for each ingester (JSON, RSS, CSV). This enhancement allows you to better comply with external data source constraints and optimize your data ingestion processes.
📓 Apply Case Templates via Playbooks (EE)
Across all 6.X.X releases, we have always tried to improve our case management capabilities based on various feedback we received from the community. In this regard, we are glad to announce that, from 6.7, within playbooks, when wrapping elements into a Case container, you can now also apply a case template directly from the playbook. This should help you improve your case management, by enabling more automation, based for instance on the cases types filters in playbooks introduced last release.
🧰 Vulnerability Management & Data model (CE)
Our vulnerability model now includes comprehensive data and metrics for CVSSV2 and CVSSV4, alongside the full attributes for CVSS V3, enhancing our assessment capabilities. We have also introduced a native capability to parse CVSS vector strings, which automatically populates respective metrics directly within our platform. This feature enhances efficiency by allowing users to input a vector string and instantly see the corresponding metrics filled in.
Finally, we've also introduced a "remediates" relationship to link software versions to specific vulnerabilities they fix, providing clearer remediation pathways. These updates deliver more detailed and actionable insights, helping users manage vulnerabilities more effectively.
In 6.7, we also extended our data model:
🔧 Background tasks processed by workers (CE)
We have enhanced our background task management system to improve performance and prevent platform lock-ups during extensive background tasks. The task execution logic has been moved to asynchronous workers, allowing for better distribution of processing across different workers. Tasks are now provisioned into worker queues and executed by these workers. The tasks view has been updated to reflect these changes, allowing you to monitor the provisioning step followed by the execution step.
🔗 Connectors & Integrations
Regarding connectors and integrations, this milestone brought several new connectors and integrations.
We would like to extend our sincere thanks to our partners and community for their valuable contributions to our connector ecosystem. Thanks to your efforts, new connectors such as Dogesec CTI Butler, Dogesec Vulmatch, Dogesec Stixify, Dogesec Obstracts and a new connector for MalwareBazaar have been added. Additionally, several existing connectors including Sekoia, Intel471, Group-IB, IBM XTI, GreyNoize Feed, MISP Feed, TheHive, and VirusTotal enrichment have been significantly improved. Your collaborations are instrumental in driving our platform forward and providing even greater possibilities to all our users. Thank you all!
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.18...6.7.0
Update quay.io/keycloak/keycloak Docker tag to v26.2.5 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/11289
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.17...6.6.18
This release deactivate the migration introduced with OpenCTI 6.6.16, cleaning up activity logs in the database. Please see the 6.6.16 release note fo
This release deactivate the migration introduced with OpenCTI 6.6.16, cleaning up activity logs in the database. Please see the 6.6.16 release note for more details.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.16...6.6.17
Release 6.6.16 includes a migration script that cleans up the database following resolution of #10777. Purpose of the migration is to add missing grou
Release 6.6.16 includes a migration script that cleans up the database following resolution of #10777. Purpose of the migration is to add missing group information on activity logs that were incorrectly generated, and make possible searching and filtering activity logs consistently with respect to the group criteria. The impacted activity logs are those generated by the platform between 6.6.0 and 6.6.16. On large platforms with millions of impacted activity records, this migration can take several hours.
We disabled this migration in OpenCTI 6.6.17.
For those who do not need to repair the activity logs and prefer skipping this heavy migration, you can update your platform from 6.6.15 (or a prior release) to 6.6.17 directly. For those who wants to repair their database this way, you might want to update your platform to 6.6.16 and then to the latest version.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.15...6.6.16
[frontend] Add Italian language support (#10434) by @rpfontana in https://github.com/OpenCTI-Platform/opencti/pull/11000
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.14...6.6.15
Your coding agent can read these notes before it upgrades. Set up the MCP server →