awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OpenCTI-Platform avatar

OpenCTI-Platform/opencti

0
View on GitHub↗
8,812 星标·1,253 分支·TypeScript·other·9 次浏览opencti.io↗

Opencti

OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities.

The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to identify threat patterns and the physical origin of threats.

The system covers broad capability areas including real-time threat streaming, automated data feed generation, and cybersecurity infrastructure orchestration. It also provides access control features such as FIPS compliance enforcement and the configuration of public, unauthenticated data feeds.

Features

  • Threat Entity Relationship Graphs - Maps disparate threat entities through a network of edges to visualize complex attack patterns.
  • Threat Intelligence Platforms - Provides a comprehensive platform for managing and analyzing cyber threat intelligence using STIX and TAXII standards.
  • Threat Intelligence Platforms - Stores technical threat data using standardized schemas to organize intelligence for detailed security analysis.
  • Standardized Threat Intelligence Exports - Serves standardized threat intelligence bundles to external systems via secure TAXII API endpoints.
  • Graph Data Models - Employs a graph-based data model following STIX standards to represent cyber threat intelligence and relationships.
  • Real-Time Data Streaming - Implements real-time data streaming for the delivery of live threat intelligence updates and entity changes.
  • Cyber Threat Intelligence Maps - Converts complex security information into visual diagrams and maps to reveal threat patterns.
  • Security Data Orchestrators - Automates the collection, streaming, and distribution of threat feeds across cloud infrastructure.
  • Standardized Threat Intelligence Exchange - Facilitates the exchange of standardized threat intelligence bundles with external systems via secure APIs.
  • Threat Relationship Visualizations - Converts complex security information into visual diagrams to reveal relationships and patterns between different threat entities.
  • Distributed Document Indexing - Utilizes Elasticsearch for high-performance full-text searching and retrieval of structured intelligence data.
  • Container Orchestrators - Uses container orchestrators to manage the lifecycle and resource allocation of isolated microservices.
  • Container Stack Management - Manages related container services as a single logical unit to simplify resource scaling.
  • Distributed Task Workers - Offloads heavy processing and feed generation to distributed task workers to maintain API responsiveness.
  • Infrastructure Orchestrators - Automates the lifecycle and state management of the security platform's multi-cloud resource stacks.
  • Kubernetes Deployments - Deploys and scales application components using standardized Helm charts on Kubernetes clusters.
  • Real-Time Intelligence Push - Maintains persistent WebSocket connections to push real-time threat intelligence updates to clients.
  • Message Brokers - Implements a Redis-based message broker for asynchronous task queuing and decoupled service communication.
  • Threat Intelligence - Platform for managing cyber threat intelligence.
  • Security Lab Environments - Platform for managing and sharing cyber threat intelligence.

Star 历史

opencti-platform/opencti 的 Star 历史图表opencti-platform/opencti 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

opencti-platform/opencti 是做什么的?

OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities.

opencti-platform/opencti 的主要功能有哪些?

opencti-platform/opencti 的主要功能包括:Threat Entity Relationship Graphs, Threat Intelligence Platforms, Standardized Threat Intelligence Exports, Graph Data Models, Real-Time Data Streaming, Cyber Threat Intelligence Maps, Security Data Orchestrators, Standardized Threat Intelligence Exchange。

opencti-platform/opencti 有哪些开源替代品?

opencti-platform/opencti 的开源替代品包括: misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing… reconurge/flowsint — Flowsint is an open-source intelligence framework and reconnaissance orchestrator used for cybersecurity… telekom-security/tpotce — T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy… tporadowski/redis — Redis is a high-performance in-memory key-value store that functions as a distributed cache, message broker, and NoSQL… pgsty/pigsty — Pigsty is a full-stack orchestration suite for deploying, monitoring, and managing high-availability PostgreSQL… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the…

Opencti 的开源替代方案

相似的开源项目,按与 Opencti 的功能重合度排序。
  • misp/mispMISP 的头像

    MISP/MISP

    6,360在 GitHub 上查看↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    在 GitHub 上查看↗6,360
  • reconurge/flowsintreconurge 的头像

    reconurge/flowsint

    6,979在 GitHub 上查看↗

    Flowsint is an open-source intelligence framework and reconnaissance orchestrator used for cybersecurity investigations. It functions as a containerized tool runner and data mapper, automating the collection of intelligence from open-source providers and APIs to profile targets and map threat intelligence. The platform distinguishes itself through a graph-based investigation interface, where processed raw intelligence is converted into nodes and edges to visualize relationships between entities. It allows for the creation of sequenced pipelines that chain data enrichment tools, enabling the o

    TypeScriptinvestigationosintpython
    在 GitHub 上查看↗6,979
  • telekom-security/tpotcetelekom-security 的头像

    telekom-security/tpotce

    9,298在 GitHub 上查看↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    在 GitHub 上查看↗9,298
  • tporadowski/redistporadowski 的头像

    tporadowski/redis

    9,987在 GitHub 上查看↗

    Redis is a high-performance in-memory key-value store that functions as a distributed cache, message broker, and NoSQL database. It provides sub-millisecond read and write access to data stored in RAM and can operate as a vector database for indexing high-dimensional embeddings. The system supports a wide range of data storage and synchronization primitives, including the management of strings, hashes, lists, sets, and JSON documents. It enables real-time data operations through atomic transactions, hybrid persistence using snapshots and append-only logs, and high-availability configurations

    Credisredis-for-windowsredis-msi-installer
    在 GitHub 上查看↗9,987
查看 Opencti 的所有 30 个替代方案→