NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Python API client for OpenCTI.
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
455 releases · first in 2019
#### Enhancements: - #5265 [DASHBOARD] Entity statuses on the dashboard #### Bug Fixes: - #5297 Too many software displayed on vulnerabilities targeti
#### Bug Fixes: - #5296 Messages number is 0 even if the queue is filled with messages in connectors screen - #5294 Entity unknown in Content mapping
One column per quarter.
[frontend] Fix interface bugs on data import page by @Goumies in https://github.com/OpenCTI-Platform/opencti/pull/5144
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.9...5.12.10
[backend] Improve observable merging to support multi operations (#5247) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pull/5248
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.8...5.12.9
[backend] Too many files in minio can prevent correct migration execution (#5244) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pu
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.7...5.12.8
[backend] Improve indices upgrade to prevent merging mapping problems by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pull/5242
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.6...5.12.7
[frontend] Fix error when creating Software from Vulnerability (#5198) by @SouadHadjiat in https://github.com/OpenCTI-Platform/opencti/pull/5213
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.5...5.12.6
[backend] do not convert empty filter group into null in elastic query by @labo-flg in https://github.com/OpenCTI-Platform/opencti/pull/5146
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.4...5.12.5
Bump vite from 5.0.4 to 5.0.5 in /opencti-platform/opencti-graphql by @dependabot in https://github.com/OpenCTI-Platform/opencti/pull/5121
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.3...5.12.4
[backend] sanitize dates coming from RSS feed by @labo-flg in https://github.com/OpenCTI-Platform/opencti/pull/5086
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.2...5.12.3
#### Bug Fixes: - #5088 In some special conditions, the Elastic / OpenSearch settings is not corresponding to the prefix which prevent migration - #50
#### Bug Fixes: - #5085 Trying to update to 5.12, error in migration Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.0...5.12
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.12.0...5.12.1
> ⚠️Breaking change in the list filters system in the API (and the Python library) ⚠️
Dear community, we're delighted to announce the release of OpenCTI 5.12.0 🥳! This milestone marks a turning point for the platform, both in terms of the new features it brings and the bugs it fixes, as well as the improvements in system resource utilization and performance 🚀.
⚠️Breaking change in the list filters system in the API (and the Python library) ⚠️
First of all, in order to support more complex search and filtering use cases such as grouping, this version introduces a major breaking change in the way list filters are built 🔍. If you have specific integrations that use the Python library or the GraphQL API, please read the migration documentation carefully 👁️🗨️.
This filters enhancement will continue in future versions, but now allows you to switch logical operators (AND and OR) between two groups or within a group. Also, on several text fields it is now possible to use new modes such as "starts with / ends with" 🎉. The new filter syntax unlocks the most advanced uses of knowledge retrieval, including the ability, for example, to filter threats according to country AND sector (targeting both) 🧬.
OpenCTI 5.12 also introduces the import / export of dashboards and widgets within dashboards, as well as the export of audit logs in CSV format🗄️. Generally speaking, the data export experience has been greatly enhanced, with the introduction of several buttons to make it more fluid. You can easily convert a graph into an investigation and vice-versa, add entities to a report with their relationships, and so on 🗜️.
In OpenCTI Enterprise Edition, a new feature now enables direct indexing of raw documents (PDF, HTML, DOCX, etc.), whose content becomes immediately accessible in the global search 🚄. This is a long awaited feature which definitely solves multiple challenges if the data is not correctly extracted / modelized. It also paves the way for the platform's future integrated NLP system 🎊.
We also have started to introduce a new ACL system at the entity level (like in dashboards and investigations) for Feedback and will expand it in the future to all STIX objects. Finally, this version contains various user experience enhancement on colors usage, light theme and overall navigation. We will carry on the hard work to make the platform more accessible and user friendly all over the upcoming releases ✈️.
Last but not least many connectors have been developed and enhanced in 5.12, especially HarfangLab, Tanium, Microsoft Sentinel, Mandiant and Recorded Future but also a bunch of community additions. Thank you everyone for your help, your feedback and your great contributions 🙏.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.14...5.12.0
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.13...5.12.0
#### Bug Fixes: - #4881 Can't download exports from a list Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.13...5.11.14
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.13...5.11.14
[frontend] Status filter display (#4800) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/4810
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.12...5.11.13
Bump crypto-js from 4.1.1 to 4.2.0 in /opencti-platform/opencti-front by @dependabot in https://github.com/OpenCTI-Platform/opencti/pull/4763
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.11...5.11.12
[frontend] open feeds, streams and taxii in new tabs by @labo-flg in https://github.com/OpenCTI-Platform/opencti/pull/4669
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.10...5.11.11
[backend] Prevent stream too_many_clauses error in query builder (#4743) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/pull/4744
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.9...5.11.10
Update dependency babel-plugin-relay to v16 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/4688
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.8...5.11.9
#### Enhancements: - #4707 Improve CSV mapper to handle empty lines and boolean #### Bug Fixes: - #4706 Improve RabbitMQ consume to prevent error on n
[backend] Fix the built RabbitMQ consumer for CSV import by @SamuelHassine in https://github.com/OpenCTI-Platform/opencti/pull/4699
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.6...5.11.7
Update dependency react-force-graph-2d to v1.25.2 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/4675
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.5...5.11.6
[frontend] Add has and targets relationships between Tool and Vulnerability by @yassine-ouaamou in https://github.com/OpenCTI-Platform/opencti/pull/46…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.4...5.11.5
#### Bug Fixes: - #4641 Sessions not refreshed lead to undefined references when starting a connector - #4640 Relationship export with filter toId not
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.3...5.11.4
Update dependency remark-gfm to v4 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/4444
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.2...5.11.3
[front] Fix for indicators by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/4618
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.1...5.11.2
[front] Refactor for drawer by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/4607
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.11.0...5.11.1
Dear community, we're thrilled to announce the release of OpenCTI version 5.11.0 🥳! In this version, we've focused on enhancing the platform with majo
Dear community, we're thrilled to announce the release of OpenCTI version 5.11.0 🥳! In this version, we've focused on enhancing the platform with major new features and squashing pesky bugs to ensure the platform continues to meet your evolving needs 💡.
First of all, we have finally implemented a built-in CSV import, with very flexible mapping configuration, allowing teams to import almost any format including relationships in columns. This mapper also supports to have multiple entities and/or relationship in a single column such as a list of sectors 🚀.
Within OpenCTI Entreprise Edition, the automation engine is now generally available. Administrators are able to create powerful playbooks and scenarios to manipulate, enrich, duplicate and process the data in the platform, based on any type of events. For instance, it is now possible to trigger the hygiene connector and, depending on the result, send the indicator to detection 🪄.
It is now possible to make all types of feeds (CSV, TAXII, etc.) public and not only OpenCTI streams. The platform will kept only one type of marking (the highest) instead of cumulating marking definitions of the same type 🧼. From an investigation, an analyst can now quickly create a container such as a report or a grouping. Also in investigations, the number of available entities to be extended in displayed on the graph 🧬.
Thank you for your continued support and valuable feedback. Stay tuned for more exciting updates from the Filigran team as we continue to evolve OpenCTI to meet your threat intelligence requirements 🎉.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.10.3...5.11.0
Update docker.elastic.co/elasticsearch/elasticsearch Docker tag to v8.10.0 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/4319
modified and updated_at fields for ReportsFilterFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.10.2...5.10.3
[frontend] Fix entity alias edition field in graphs (#4217) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/4218
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.10.1...5.10.2
[frontend] fix error when deleting a file (#4182) by @SouadHadjiat in https://github.com/OpenCTI-Platform/opencti/pull/4184
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.10.0...5.10.1
🌟 OpenCTI v5.10.0 Release Notes 🌟
🌟 OpenCTI v5.10.0 Release Notes 🌟
🚀 Enhancements: The Filigran team is proud to bring you another packed release! For organizations, v5.10.0 introduces a host of features designed to streamline your experience:
🐛 Key Bug Fixes: Our developers have also been hard at work squashing those pesky bugs:
💬 Wrap-up: This release is a culmination of feedback, dedication, and the persistent effort by the Filigran team. Every enhancement and fix is geared towards making OpenCTI a more powerful and user-friendly platform. Remember, while we've highlighted only a few, many more fixes and tweaks are included in this version to optimize your experience.
🙌 A massive thank you to our user community for your continued support and feedback. Keep those suggestions coming, and let's together make OpenCTI even better!
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.6...5.10.0
#### Bug Fixes: - #3810 25 rows is still exists! Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.5...5.9.6
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.5...5.9.6
Update dependency eslint to v8.45.0 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/3805
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.4...5.9.5
Update dependency opentelemetry-api to v1.19.0 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/3771
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.3...5.9.4
Update dependency formik to v2.4.2 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/3684
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.2...5.9.3
[frontend] Add missing import by @RomuDeuxfois in https://github.com/OpenCTI-Platform/opencti/pull/3756
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.1...5.9.2
Update dependency @ckeditor/ckeditor5-dev-translations to v38.1.1 by @renovate in https://github.com/OpenCTI-Platform/opencti/pull/3709
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.9.0...5.9.1
Dear community, OpenCTI 5.9.0 has been released 🥳! This new major version is full of new features and enhancements 🎉. First of all, it is now possible
Dear community, OpenCTI 5.9.0 has been released 🥳! This new major version is full of new features and enhancements 🎉. First of all, it is now possible to customize the experience of groups, defining default dashboards and default notifications triggers for each of them 🎨. Also, users with the proper permissions are able to create custom widgets and custom statistics based on the audit log and activity monitoring as well as create notifications triggers based on this activity in the settings of the platform 📊.
A new icon has been added in the overview of entities to be able to quickly subscribe to any new activity regarding this entity (new reports, relationships, etc.) 📡. Furthermore, the opinion custom vocabulary is now supported in all opinion radars and threat actors have been divided into two sub entities: groups and individuals 🔥. Investigations can now be downloaded as a STIX report and re-imported anywhere. In the future, it will be possible to turn an investigation into a report (and vice-versa) 📥.
Last but not least, it is now possible to create platform announcements, add custom headers / footers but also create analyst workbenches directly in the entity data tab 💬. Moreover, if you start a new OpenCTI platform from 5.9.0, the ElasticSearch / OpenSearch rollover policies to optimize indices size is now automatically created and enabled 🪄.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.7...5.9.0
#### Enhancements: - #3592 Take into account the selected text in the creation of observables #### Bug Fixes: - #3593 Timeseries by day (widget) is di
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.6...5.8.7
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.5...5.8.6
[backend] Listing with search criteria prevent pagination usage with cursor (#3578) by @richard-julien in https://github.com/OpenCTI-Platform/opencti/
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.4...5.8.5
[frontend] Warning popup before browsing a link (3481) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/3482
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.3...5.8.4
[frontend] display Notes abstract in Reports-->Entities (#3557) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/3559
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.2...5.8.3
#### Bug Fixes: - #3552 Export of bulk search is broken Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.1...5.8.2
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.1...5.8.2
[frontend/backend] add associated file to Malware Analysis by @yassine-ouaamou in https://github.com/OpenCTI-Platform/opencti/pull/3548
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.8.0...5.8.1
Dear community, we are so proud to announce that OpenCTI 5.8.0 is out :partying_face:! This release is full of major enhancements in the product and f
Dear community, we are so proud to announce that OpenCTI 5.8.0 is out :partying_face:! This release is full of major enhancements in the product and fixes all known bugs in the core platform. Here is the list of the features implemented :bulb::
Also, 26 bugs have been fixed and multiple new connectors have been created, including ThreatFox, Recorded Future enrichment and QRadar integration :muscle:. The OpenCTI Ecosystem market place have been updated and enhanced :rocket:.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.6...5.8.0
#### Enhancements: - #3355 Enhance display of security generic settings Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.5...5.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.5...5.7.6
[frontend] Fix on TimelineView filters (#3281) by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/3283
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.4...5.7.5
[frontend] Fix malwares, tools and vulnerabilitites knowledge relationships entities view (#3253) by @SouadHadjiat in https://github.com/OpenCTI-Platf…
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.3...5.7.4
[frontend/backend] Add Case Rfi and Case Rft Entities (#issue/2977) by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/3145
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.2...5.7.3
[backend] Fixes for separate case migration (#3202) by @Kedae in https://github.com/OpenCTI-Platform/opencti/pull/3203
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.1...5.7.2
[frontend] Kill chain phases display in the overview of a STIX Core Relationship (#3141) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/5.7.0...5.7.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →