NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Python API client for OpenCTI.
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
455 releases · first in 2019
[CI] Feature branch on staging by @efaure in https://github.com/OpenCTI-Platform/opencti/pull/11108
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.13...6.6.14
One column per quarter.
[frontend] Stix core object history lines (#10965) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/11042
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.12...6.6.13
[frontend] Add a description to countries (#10087) by @SarahBocognano in https://github.com/OpenCTI-Platform/opencti/pull/10959
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.11...6.6.12
[frontend] Fix validation errors on changes in creation forms by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/10728
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.10...6.6.11
[frontend] Fix Search in Add locations of Threat Actor Individuals (#10794) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/10887
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.9...6.6.10
Update redis Docker tag to v7.4.3 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/10844
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.8...6.6.9
[backend] fix cron playbook node filter saving (#9646) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/10810
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.7...6.6.8
[backend] remove status update if status is not in entity statuses configuration (#9071) by @JeremyCloarec in https://github.com/OpenCTI-Platform/open
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.6...6.6.7
[frontend/backend] enable adding relationships as representation entity targets (#9395) by @JeremyCloarec in https://github.com/OpenCTI-Platform/openc
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.5...6.6.6
[frontend] Avoid URI filters repercussion in Knowledge screens (#8511) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/9066
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.4...6.6.5
[frontend] Fix init zoom on graphs (#10580) by @lndrtrbn in https://github.com/OpenCTI-Platform/opencti/pull/10595
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.3...6.6.4
[frontend] Fix bulk search result panel (#10518) by @SouadHadjiat in https://github.com/OpenCTI-Platform/opencti/pull/10532
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.2...6.6.3
[frontend] Trying to get vite running faster (#9869) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/9799
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.1...6.6.2
#### Bug Fixes: - #10094 Incomplete search for Observable User Account entities Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.6.0...6.6.1
Given that the DRAFT feature has been released, Workbench will be deprecated within approximatively 6 months from this release. As a result, we strong…
Dear community, we're excited to announce the launch of OpenCTI 6.6.0! 🥳
This release focuses on solving key pain points and unlocking new use cases:
OpenCTI offers lots of functionalities & various ways to see and collect information. However, sometimes, especially for new users, understand where and how to find the information can be a struggle.
We hope that 6.6 will relieve you from this pain, thanks to the introduction of our new AI functionality: the Natural Language Query powered by Arianne AI 💫. This Entreprise Edition feature allows you, from the top search bar, to ask questions to the platform! Your question will be translated into a set of filters and the corresponding results will be displayed as usual, letting you narrow down your search if needed 🔍.
This capability will fully rely on our filters and solely provide results about entities ⚠️ : as a result, any questions that would lead to filters that do not exists or a combination of filter not available in the app won’t provide you the expected results. In addition, the scope of the questions are restricted to entities. For more information regarding this functionality, please go to the dedicated documentation page https://docs.opencti.io/latest/usage/ask-ai/#assistance-for-finding-specific-entities-natural-language-query.
We are eager to hear your feedback for this functionality which is a first step towards making Arianne AI a real assistant in your daily life on OpenCTI.
Finding intelligence first requires ingesting it into the platform. We have worked hard to be able to revamp our import workflow and introduce two major features: a full rework of the import from files workflow ↖️ and the Draft feature 🎨.
First regarding the import workflow: you are now able to import multiple files at once 💡, and create a single draft out of it. As a result, this should make you win quite some time while gathering all information in a single place for validation purpose.
The second feature that comes along the import is the Draft 🎨. Draft workspaces aims to replace workbenches on the long run.
Basically, Drafts will provide the same capabilities than a workbench: the ability to view what has been extracted from the file & validate it before import. But that is not all: all the functionalities available in the application will also be available within a Draft workspace! For this first release, you will be able to enrich in Draft, apply bulk operation (mass create, edit…)💥. Switching your platform to a Draft “mode” will allow you to still browse your data, manipulate it, without impacting the main database.
You will also be able to convert your existing workbenches to Drafts.
As a result, the new import workflow coupled with the Draft functionality will enable you to better control your ingestion from files, ensuring that only high quality data is ingested for real in your OpenCTI instance.
We are keen to get feedback on this functionality that has required quite some work, therefore, feel free to try out & let us know what you think. More information on: https://docs.opencti.io/latest/usage/draftWorkspaces
We have spent some time to improve features around Case Management. We have introduced two new filters: the “@Me” filter 🤝 & the ability to filter on relative date range ⏱️. This way, you will be able to create query like “show me all cases created within the last week” ⏱️. This should improve your operational efficiency.
OpenCTI’s complex and multi-layered ACL allows organizations to implement their own data segregation, each teams having their scope of responsibility, with need-to-know based sharing. This kind of process have impact on collaboration efficiency, and it is not rare that a teamA works on a correlated case handled by teamB without knowing it. Now in OpenCTI, with the Request Access feature (EE) 🧐 teamA is able to request access to the corelated case and thus, with respect to need-to-know basis, collaborate further with teams working already on it. Basically, in the context of a platform configured to segregate data per Organizations, if an entity, having a marking accessible to user exists in the platform, but not shared to the user’s organization, upon manual creation of entity, the user will have the ability to request access to this entity. It will result in a creation of an RFI that only a specific group of user pertaining to the correct organization could approve or reject, providing full control over data to users of the platform. Try it out!
We have also improved the playbooks to be able to filter on any container sub type 🎊 (incident response type, report type, request for information type…). Therefore, you will be able to automate with more granularity the automation of your cases. All together, these filtering capabilities should help you improve the operational efficiency of your teams working on cases.
Filtering has not only be improved in the context of containers, but globally within the application. All entities having a knowledge view can now benefit from a new view, the All view 🔥, which gathers all entities and all relations without any filters at all. This is a known pain point that has been raised since a while, since you were not able to easily see all linked entity with the one you’re looking at. This view will be used to also improve the current diamond model view 💎, since the various views of the diamond model will now redirect to a view All, with some predefined filters matching your view!
Some of your cases, container or even investigations can be huge and difficult to handle by our current front-end graph engine. This is one of the reason we have heavily reworked our graphs within the platform 📈, to ensure we are able to load large graphs. To do so, we have introduced a pagination when loading your graph, avoiding your platform to crash when you attempt to load a large graph. On the top of this, we have also clarified the select & search behavior to find more easily the information you are looking for. Dedicated documentation is available here : https://docs.opencti.io/latest/usage/pivoting/?h=pivoting. This technical rework opens the path to further improvements in our graph with objective to help users perform in-graph intelligence analysis and correlation.
A few other improvements have also been provided:
Regarding connectors and integrations, this milestone brought several new connectors and integrations like:
Last but not least, we are excited to introduce our new AI-powered import-document 💫 connector. This connector allows Enterprise Edition organizations to feed information from document to OpenCTI, with more extraction capabilities than regular Import Document connector. Go to the readme of the connector to understand how to use it and its scope: https://github.com/OpenCTI-Platform/connectors/tree/master/internal-import-file/import-document-ai
⚠️ Deprecation notes:
Given that the DRAFT feature has been released, Workbench will be deprecated within approximatively 6 months from this release. As a result, we strongly encourage you to have a look at the draft functionality, to try it out, and already highlight us any issue or feature existing in workbench that you do not find in Drafts.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.11...6.6.0
chore(deps): update dependency vite to v5.4.15 [security] by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/10390
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.10...6.5.11
[frontend] large spacing on vulnerability details (#10118) by @ValentinBouzinFiligran in https://github.com/OpenCTI-Platform/opencti/pull/10262
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.9...6.5.10
[frontend] add marking icon in definiton column (#10074) by @marieflorescontact in https://github.com/OpenCTI-Platform/opencti/pull/10144
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.8...6.5.9
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.7...6.5.8
[frontend] feat: Hide XTM Hub CTA button if platform_xtmhub_url variable is empty by @jbanety in https://github.com/OpenCTI-Platform/opencti/pull/1022
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.6...6.5.7
[frontend] vulnerability detail grid updated (#10118) by @ValentinBouzinFiligran in https://github.com/OpenCTI-Platform/opencti/pull/10158
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.5...6.5.6
[frontend] Bad margin/padding on some pages with an information section (#10053) by @SarahBocognano in https://github.com/OpenCTI-Platform/opencti/pul
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.4...6.5.5
[frontend] Only accessible markings visible in filters (#10006) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/10010
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.3...6.5.4
[backend/frontend] Fix generation scenario from threat and victime entities (#9987) by @savacano28 in https://github.com/OpenCTI-Platform/opencti/pull
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.2...6.5.3
Update dependency dompurify to v3.2.4 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/9850
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.1...6.5.2
[frontend] add 'search' filter operator translation (#9772) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/9802
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.5.0...6.5.1
…simulations from OpenCTI. This includes a deprecation, detailed below.
Dear community, we're excited to announce the launch of OpenCTI 6.5.0! 🥳
This release focuses on solving key pain points and unlocking new use cases:
ℹ️ Enterprise Edition Activation Changes
[!NOTE] As you know, in June 2023 we introduced an “Enterprise Edition” of the platform. As we explained at the time, this was in no way a reneging on our commitment to open source software, which has been part of our DNA since the very first day of our adventure. We are convinced that we have honored this promise perfectly, continuing to invest heavily in the features of the community version and innovating for all our communities.
Access to the Enterprise Edition, subject to a special license and annual subscription, has remained for almost two years based on the good faith of the platform's users, with acceptance of the license requiring a simple checkbox in the platform settings.
To promote transparency and fair use of our products, OpenCTI 6.5.0 introduces a license key system to control activation of the Enterprise Edition. All Filigran customers and non-governmental charity organizations using EE in accordance with the terms of the license have already received their license key(s).
As a consequence, upgrading a platform with EE activated and without a valid license key will result in the full de-activation of all EE features. Of course, for organizations wishing to access the associated features for testing and development purposes, trial license keys can be generated automatically and independently from our website. Please, don't hesitate to reach out to us if you have any question or concern about this new license key system.
Analysts spend significant time working on incidents and reports to identify threats and create knowledge that improves their organization's security posture.
However, transforming this information into standardized, easily disseminated finished intelligence documents often proves challenging.
This is why we introduced the ability to create your own finished intelligence template 📜 (Enterprise Edition). From the container's customization page, you can now define templates that use variables of your container and the entities and relations present in your container. These predefined templates will reuse the intelligence contained in your container. Your analysts can simply generate finished intelligence from these templates to initialize documents pre-populated with relevant data. This significantly reduces the time needed to produce any kind of reports.
Better yet, these templates can be imported and exported 💡, allowing you to reuse them across different platforms!
In addition, we've added the capability to manage dissemination lists & leverage them to send PDF documents via email (Enterprise Edition) 📨. Once administrators define email distribution lists, analysts can use them to send Finished Intelligence documents directly to their dissemination circles. This gives non-OpenCTI users easy access to analyst-produced documents.
In certain circumstances, intelligence access needs to be more restricted—for instance, during critical incidents or when handling sensitive threat reports. To address this, we've added the ability to restrict access to a container with our authorized member mechanism 🔒(Enterprise Edition). Even with shared containers, enabling access restriction limits visibility to specifically authorized users, groups, or organizations. These authorized members receive only the access rights you grant them (view, edit, manage), helping you maintain data confidentiality.
To ensure restricted data remains manageable if an entity manager leaves your organization, administrators can access a restriction management panel 🔓 to remove restrictions on entities when needed.
Minimizing false positives is essential for improving the accuracy and effectiveness of threat detection. To support this, we've introduced exclusion lists ⛔ in OpenCTI. This feature lets you create exclusion lists to prevent specific IOCs, such as internal IPs or trusted domains, from being ingested into the platform. By preventing the ingestion of these non-malicious IOCs, you ensure they are not propagated to your external detection solutions (ex: SIEM), reducing noise and enhancing detection accuracy.
AI should enhance analysts' daily work, which is why we've revamped our AI module ✨ (Enterprise Edition). Now available across all platform entities, it supports analysts in their daily tasks. From any entity, such as a threat, analysts can quickly view latest activity, get summaries from recent reports, and see activity logs—putting useful information at their fingertips!
Understanding and presenting data effectively is crucial in CTI. This is why we have worked on the following features.
Our OpenBAS :openbas: integration has been redesigned to support choosing the correct architecture when running simulations from OpenCTI. This includes a deprecation, detailed below.
In terms of data ingestion, OpenCTI now provides the capability to expose TAXII 2.1 data collections for pushing STIX-formatted data. Available under Data/Ingestion, the TAXII Push ingester enables users and external systems to import STIX 2.1 objects into OpenCTI through an exposed TAXII collection, ensuring full compliance with the 'Add objects' section of the TAXII 2.1 specification.
We’ve also updated and integrated a new GraphQL playground to enhance your development experience by making it easier to test and interact with our GraphQL API 😎.
Finally, we've improved performance for large dataset operations ⚡ through two backend enhancements: improved worker thread pool and relocated lock mechanism to a separate process. This means faster background task processing and more efficient operations on shared entities, resulting in fewer errors.
Regarding connectors and integrations, this milestone brought several new connectors and integrations like:
But also to enhance some connectors :
We deeply want to thank our Partner & Community for their contributions:
Finally, we have made efforts to expand the availability of our Docker containers. In addition to being hosted on Docker Hub, all OpenCTI containers are now also accessible via [GitHub Container Registry](https://github.com/orgs/OpenCTI-Platform/packages).
We hope this release will please you! Feel free to drop us a note about anything. We’re always happy to get feedback about our product usage, whether it’s to hear that everything works perfectly or to get some improvement ideas to.
All the details about what has been released for which repo is available here:
⚠️ Deprecation
Deprecation Notice: GenerationScenario Mutations in OpenCTI - OpenBAS
The following three mutations related to GenerationScenario have been deprecated due to changes in their signature and response format:
Key Changes in new version : + WithInjectPlaceholders
New Signature Object: SimulationConfig
New Response Object: GenerationResponse
For more information about the deprecation duration, please refer to our documentation: https://docs.opencti.io/latest/deployment/breaking-changes/.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.11...6.5.0
[backend] Fix reindex error on deleting old objects (#9270) by @SouadHadjiat in https://github.com/OpenCTI-Platform/opencti/pull/9742
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.10...6.4.11
[frontend] In Observable / Indicators composed with this observable view, fix the css(#9279) by @Gwendoline-FAVRE-FELIX in https://github.com/OpenCTI-
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.9...6.4.10
[frontend] refacto how we get apex chart context (#9299) by @lndrtrbn in https://github.com/OpenCTI-Platform/opencti/pull/9633
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.8...6.4.9
[backend] keep increasing back pressure delay if queue size keeps increasing (#9358) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.7...6.4.8
[frontend] display creators in Intrusion set list (#9534) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/9535
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.6...6.4.7
Update dependency react-apexcharts to v1.7.0 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/9352
Unknown in workbenchTask/Report/Grouping/Malware Analysis name are Unknown in knowledge related entitiesNetwork-Traffic name in workbench observables list (#9506) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/9507Task/Report/Grouping/Malware Analysis in knowledge > related entities (#9497) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/9498Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.5...6.4.6
[backend] fix version of path-to-regexp for CVE-2024-52798 by @labo-flg in https://github.com/OpenCTI-Platform/opencti/pull/9286
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.4...6.4.5
Update dependency amqplib to v0.10.5 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/9180
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.3...6.4.4
[backend] fix possible undefined fileMarkings (#9149) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/9178
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.2...6.4.3
[backend] Domain observable with hyphen/dash is incorrectly rejected V2 (#8927) by @SarahBocognano in https://github.com/OpenCTI-Platform/opencti/pull
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.1...6.4.2
[frontend] Members ordering in Group edition form (#8984) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/9061
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.4.0...6.4.1
Vulnerability management, by developing additional integrations
Dear community, we're excited to announce the launch of OpenCTI 6.4! 🥳
This release has been mainly focused on solving the following pain points & unlocking the below use cases:
If our platform is flexible, sometimes this flexibility can be harmful when it some new users to the platforms perform some actions which can have a negative on their experience, such as remove the Enterprise Edition, changing the platform organisation, updating some built-in roles & groups.
This is the reason why we introduced the concept of Danger Zone 🚸.
**From the moment you will upgrade, certain area of the platform will be protected. This means you will not be able to edit them without having a new specific role capability. For more information regarding this feature, please go to the dedicated documentation
Quick and efficient incident response is essential for many organizations, yet managing participant assignments and case updates can often be time-consuming, slowing down response times.
To streamline incident management, we’ve introduced direct in-UI options for assigning participants and assignees, removing the need to open the modification panel. Additionally, we now support bulk operations for updating fields like creator, assignee, priority, severity, and type🖊️ directly from the list view.
These enhancements enable faster, more flexible incident management, giving teams the ability to quickly assign resources and update cases at scale.
To complement on this topic, one great feature added this release is also the ability to enroll a specific entity within the playbook 🤖: starting from 6.4, you can create a playbook with the first step being “Available for manual enrollment / trigger”. By creating this step without any filter & the rest of your workflow, you can now, when navigating to a container, “enroll this entity in a playbook” to have an automation running on this specific entity. This will unlock lots of use cases, for instance to apply specific measures to a particular entity that you need to follow.
Users frequently need to work with knowledge graphs to manipulate information within containers. However, adding entities to an established knowledge graph has been a challenge, as forces were automatically reapplied, disrupting the graph's layout and usability. So as creating a large number of relationships with a single entity led to problems of timeout.
In this release, we’ve refined the knowledge graph experience to support smoother interactions. Now, if you disable forces on your graph, it will maintain its layout when new entities are added 📈, preserving your custom configurations.
Additionally, with valuable input from the community, we’ve enhanced relationship management within reports. Users can now select all relationships linked to a node or choose to isolate either parent or child relationships 💡—simplifying bulk actions, such as removing relationships from a container.
Investigation graphs have also been reworked to improved the representation of file objects (observable).
Knowledge ingestion through CSV files offers flexibility, but handling custom formats can be challenging. Users need efficient ways to create mappers and manage conditional data.
To enhance CSV ingestion, we’ve introduced two key improvements to CSV mappers.
Firstly, we’ve added a duplication feature for CSV mappers (and feeds) 📁across both ingestion and data sharing, simplifying the mapper creation process.
Secondly, the new Conditional Mapping 🧪functionality allows users to map columns based on specific conditions—particularly useful when a single column contains multiple entity types. For instance, users can configure the mapper to recognize whether a row is an IP address or URL based on values in a separate column, streamlining entity classification.
Ingestion have also been improved with the ability to map a confidence level information on our score notion (x_opencti_score) when ingesting Indicators/Observables from a TAXII Feed.
Few releases back we have started our work towards unlocking some vulnerability management capabilities within the app.
This is why we have now introduced the Tenable Vulnerability Management connector. Thanks to this connector, you can now monitor your assets using our system entity within OpenCTI & get some corresponding vulnerabilities.
Additionally, systems now have a knowledge view 🪟 to see their related vulnerabilities & a new relationship type “system has vulnerability” 🔗 has been introduced too. Thanks to the work already done to add EPSS, KEV & connectors already built, in addition to these fields being supported in the playbooks, vulnerability management within OpenCTI becomes doable to a certain extent within the platform 🔥
Connectors are essential for data ingestion, yet diagnosing errors within connectors can be challenging and time-consuming. Clear error insights are crucial for efficient troubleshooting and to maintain data flow continuity.
To simplify error resolution, we’ve enhanced the error logging for connectors 💬. Now, within the error tab, users can view errors categorized under Critical, Warning, and All, allowing for immediate prioritization. Each error entry includes an improved, human-readable explanation along with a unique error code. This code links directly to documentation that provides specific troubleshooting steps, helping users quickly identify and address issues.
When it comes to troubleshooting, you also need to understand which are the users who have taken a given action, in order to be able to trace back & understand what did happen. Our logging have been improve thanks to the introduction of a filter on the “system” user. 👥
Outside of these use cases, we have tackled some additional various issues.
In addition to Tenable connectors addition, two new enrichment connectors have also been added:
We have also made a number of improvements to the Microsoft Sentinel, Tanium and Harfanglab connectors. The export of indicators and the import of incidents are now separated into two different connectors (stream & external-import).
On a finish note, we would like to thank you for your contributions 🙏 to our product, that helps making our product better: guillaumededrie, stefan1anuby, Bonsai8863, animedbz16, daimoyo007, cert-orangecyberdefense, polakovicp, DNRRomero, stefanbulof, annoyingapt, uTomasAnderson, bradchiapetta, brett-fitz, akhanafeer, mmolenda, initstring, Darkheir, WolfBytnner, Mathieu4141, DinkoReversingLabs, basvanschaik, curiouspython1.
Of course, a huge thank you to all for your contributions 🥇
We hope this release will please you! Feel free to drop us a note about anything. We’re always happy to get feedback about our product usage, whether it’s to hear that everything works perfectly or to get some improvement ideas to.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.13...6.4.0
#### Bug Fixes: - #9136 ImportDoc connector Will not Automatically Create a Workbench When Uploading a PDF on the Data page of an Observable and Artif
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.13...6.3.14
#### Bug Fixes: - #9042 Organization mapping is not working with Microsoft when "." is present in path - #9026 PDF viewer is broken everywhere Full Ch
[frontend] Improve error message notification in the UI (#8923) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pull/8924
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.11...6.3.12
[frontend] Fix data tables interactions between selected elements and filters (#8571) by @lndrtrbn in https://github.com/OpenCTI-Platform/opencti/pull
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.10...6.3.11
Permissions from External Auth Server Not Mapped to OpenCTI Platform Groups When Logging in via loginFromProvider by @savannah030 in https://github.co
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.9...6.3.10
[frontend] UI fix scrollbar useless in custom dashboard (#8282) by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/8823
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.8...6.3.9
[frontend] Fix enrichment button (#8825) by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/8828
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.7...6.3.8
[frontend] Bad icons replaced in connector overview(#8225) by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/8669
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.6...6.3.7
[frontend + backend] added vulnerabilitties tab and 'has' relationship by @stefan1anuby in https://github.com/OpenCTI-Platform/opencti/pull/8458
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.5...6.3.6
Update docker.elastic.co/kibana/kibana Docker tag to v8.15.2 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/8543
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.4...6.3.5
Bump rollup from 4.21.3 to 4.22.4 in /opencti-platform/opencti-graphql by @dependabot in https://github.com/OpenCTI-Platform/opencti/pull/8461
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.3...6.3.4
[frontend] Fix ctrl+click on DataTable (#8394) by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/8402
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.1...6.3.3
Nothing published for this version
#### Bug Fixes: - #8395 In some very rare cases when a bundle is too large, sending to the queue can end up with "Blocked connection timeout expired."
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.3.0...6.3.1
manipulate data and initiating work toward vulnerability management.
Dear community, we're excited to announce the launch of OpenCTI 6.3! 🥳
This released has been focused on solving well known pains 🎯 :
Clarity & control over the ingestion process is a must. Hence the introduction of our feature Integrated feeds Ingestion 🧠. More and more of you are ingesting data via “integrated” feeds (TAXII, RSS, CSV), and we've worked to give you greater visibility over the data ingestion flow by representing these feeds in the form of a dedicated connector and by allocating dedicated RabbitMQ queues per ingestion configurations in place of common queues (see our depreciation announcements).
Thanks to this enhancement, you'll be able to identify bottlenecks more quickly and gain real-time insights into your data ingestion flow. 💡
Following up on this pain of providing more control to admins over the ingestion, we have introduced a new capability: bypass custom mandatory fields.
The problem is that your connectors providing you data do no always have a a specific field that you want your analyst to provide, which results in failing the creation of entity. ❌ As a result, thanks to this new capability, you will be able to enforce this custom mandatory attribute only for specific groups of users (your analysts), while allowing others (your connectors) to be able to create data without a specific field. 🔥
As mentioned in introduction, we focused on usability. This is why we introduced a new feature: bulk creation 🥇
Together, these features are designed to save you time and enhance your productivity, enabling you to focus on more critical tasks.
Improving app usability means better identification of the data that matters to you 💡
Every organization has unique data needs, even within different entities of the same company. To meet this, we introduce the new Custom Overview per Entity Type feature.
This allows users to customize each entity’s layout, selecting key information "blocks" to prioritize and adjust their size. It makes it easier to quickly spot and focus on critical data.
Usability also comes from having similar functionalities in similar screens across the app.
First of all, we have introduced List views for Threat Actors, Intrusion Sets, Campaigns & Malware, on the top of the existing card view 🪪. This will tremendously help the management of these entities without the need to go in data/entities to manage them.
Massive operations have also been added to all Arsenal entities (Malware, Channels, Tools, Vulnerability), Narratives and Attack Patterns! In this way, the consistency of operations across the application is greatly enhanced.
Last but not least, you will notice one last update that has been heavily worked in order to improve our application usability: New data tables 🎉
When upgrading to our new version, you’ll notice that data table look different: we have upgraded them. As a result, you’ll notice that:
As some of you may be aware, we would like to make easier the vulnerability management process in OpenCTI.
The first step to achieve this goal was to extend our Vulnerability model to support EPSS and CISA KEV attributes. Support of these two information were highly requested by the community🔥. Regarding EPSS, an enrichment connector to fill the data has been created too, see below.
Having these fields was not enough, we also added the ability to use them (like other vulnerability fields) in playbook components to help you build your own vulnerability decision tree 🪄.
While files and workbenches are essential, they can contribute to performance issues over time, since documents are piling up in the platform. ❌
Retention Rules for Files and Workbenches: We’ve added configurable retention rules, which are not set by default but can be easily customized. For example, you can implement a one-year policy to automatically delete any file or workbench created over a year ago. This helps prevent outdated data from accumulating and improves overall platform performance. 💯
Administrators have also been heard with an additional feature, or rather a UX improvement. To ease management of dashboard we have also introduce a new tab in the dashboard menu, to be able to view only the public dashboards as list without needing to enter in each dashboard to view the corresponding dashboards.
In terms of integrations, lots of effort has been put to deliver new connectors & improvements of existing connectors.
We already announced it on slack, but during this release, we delivered a new Splunk app 🔥, aiming to:
With the OpenCTI Add-on for Splunk, you can leverage comprehensive threat information, improving your ability to detect and respond to security incidents more effectively. More info can be found on : https://splunkbase.splunk.com/app/7485.
To provide more support to our community, we completely refactored the Qradar connector to become an official Filigran support connector. This means that we will be able to provide support on this connector if a bug arise. The refactor has also fixed some known bugs, which are listed in the below list of issues.
Being open source also means ensuring that everybody has the capacity to contribute to our codebase. However, in the past, our readmes & guidelines to contribute in our connector repository were not up to date. We’ve made some effort to update it so that all the documentation is up to date, allowing everybody to bring their own contribution more easily 💪!
As mentioned earlier, we have worked towards helping analysts to perform vulnerability management with OpenCTI. To cater this need, we built an enrichment connector to provide values for EPSS 🤘This connector integrates with the organisation “FIRST” API, aiming to retrieve EPSS values about a specific vulnerability. This enrichment connector is of course playbook compatible 🚀
Some connectors have also been reworked (namely Sekoia, Crowdstrike, Mandiant, AlienVault, Recorded Future, CISA KEV) to support our new scheduling and auto-pausing feature that will pause your connector when its queue gets full. You’ll see in these connectors new variables "duration_period" & "queue_threshold" that you need to define to enable these features. More details can be found in the respective connector pages.
We also improved the Mandiant connector by providing an option to import aliases of malwares & improve campaigns import. Campaigns import improvement provide more details regarding TTPs (labels, relation with intrusion sets, start & stop time & addition of description). In essence, we’ve made sure that we import as much data as we can.
To list them all, here are all the new connectors delivered in the milestone: Jira, Infloblox, Cisco SMA, Group IB, Cofense. The detailed list of connectors & improvement is available here: ****https://github.com/OpenCTI-Platform/connectors/releases?page=1
On a finish note, we would like to thank you for your contributions 🙏 to our product, that helps making our product better: shmztk, Bonsai8863, Fhwang0926, ParamConstructor, VerboseCat, WolfByttner, brett-fitz, mmolenda, Mathieu4141, annoyingapt, DNRRomero, DinkoReversingLabs, pietrocapece, sari3l, bradchiappetta, debelyoo, uTomasAnderson, leitosama, XGREENi3, sudesh0sudesh, cert-orangecyberdefense, cmandich, obideuce, sda06407, Obdam, piolug93, daemitus, polakovicp, julienloizelet, khalidelborai, Renizmy, curiouspython1!
Of course, a huge thank you to all for your contributions 🥇
We hope this release will please you! Feel free to drop us a note about anything. We’re always happy to get feedback about our product usage, whether it’s to hear that everything works perfectly or to get some improvement ideas to.
Depreciation announcements
The RabbitMQ “push_sync”, “listen_sync”, “listen_playbook” and “push_playbook” queues are no longer used by our product and will be considered deprecated once empty. These queues will be permanently removed in version 6.6.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.18...6.3.0
#### Bug Fixes: - #8512 [livestream] update and removal are not done anymore on destination Full Changelog: https://github.com/OpenCTI-Platform/openct
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.18...6.2.19
#### Bug Fixes: - #8129 User overview light theme hidden entities tiles - #8116 [CSV Mapper] When having error, "Create" button is disabled - #7964 Bu
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.17...6.2.18
#### Bug Fixes: - #8205 app.base_path configuration is not working anymore (default empty works fine) - #8011 When a user is administrator of an organ
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.16...6.2.17
#### Bug Fixes: - #8182 Order of kill chain phases are lost after dataset is updated - #8150 [Retention policy] Entities are not deleted - #8013 Error
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.15...6.2.16
[backend] Fix migration timestamp (#6509) by @lndrtrbn in https://github.com/OpenCTI-Platform/opencti/pull/8112
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.14...6.2.15
[backend] Trial for improving import page by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/8031
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.2.13...6.2.14
Your coding agent can read these notes before it upgrades. Set up the MCP server →