OpenCTI integration

OpenCTI threat intelligence from Q-Feeds

OpenCTI already holds your knowledge graph. Add Q-Feeds and it fills up with curated indicators your analysts can search, relate and share.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and OpenCTI integration?

OpenCTI is only as good as the intelligence you put in it. Q-Feeds adds more than 2,500 commercial, OSINT and governmental sources as one curated stream, so your analysts work through a single prioritised set of indicators instead of stitching together free lists of unknown quality.

Everything arrives through the TAXII ingestion that OpenCTI already ships with, so there is nothing to build and nothing to keep running. Q-Feeds indicators stay attributed to their own source, which means you can filter on them, report on them and remove them again without touching the rest of your knowledge.

Malicious IP addresses, domains, URLs and file hashes arrive with their category and MITRE ATT&CK mapping, refreshed every 20 minutes. TAXII is part of the Enterprise licence; on Community, Plus and Premium you ingest the IP and domain lists as a feed instead, with malicious URLs on Premium.

TAXII 2.1

The full stream on Enterprise

Q-Feeds delivers STIX 2.1 indicators with the context analysts need to triage: category, MITRE ATT&CK mapping and geographic data. OpenCTI collects them on the schedule you choose and relates each one to what it already knows.

  • Category, MITRE ATT&CK and geo context per indicator
  • Collected on the schedule you set
Feeds

Or start on any licence

Community, Plus and Premium users ingest the same malicious IP and domain lists as an OpenCTI feed, and Premium adds the malicious URL list. It is the quickest way to prove the value in your own environment before you commit.

  • Malicious IPs and domains, URLs on Premium
  • Free Community edition to test with
Features

What we offer

Always ahead

Intelligence that updates every 20 minutes, so you are always ahead of the attackers.

Automatic response

Trust automated response actions and reduce the manual work needed to stop the latest threats.

Categories

Focus on what matters most, phishing, botnets, dark web and more crafted categories.

Knowledge

Knowledge is power when fighting threats. We take the knowledge part off your hands.

Easy implementation

You never did an implementation this easy. Follow our concise implementation guide and you are good to go.

Fewer false positives

We filter out false positives, so you never waste valuable resources chasing noise.

How it works

Add Q-Feeds to OpenCTI in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal, pick the collections that match your risk, and your credentials are waiting for you there.

  2. Add the feed in OpenCTI

    OpenCTI ingests TAXII out of the box. Your administrator pastes the Q-Feeds credentials, picks a collection and saves. There is no connector to install.

  3. Keep the source recognisable

    Assign a dedicated user to the feed so Q-Feeds objects stay separate from your own research, and you can filter or withdraw them in one action.

  4. Investigate with context

    Indicators appear in Knowledge within minutes and stay current, ready to relate to the incidents, reports and cases your team already works on.

FAQ

Frequently asked questions about the OpenCTI integration

What does Q-Feeds add to OpenCTI?

Intelligence worth investigating. OpenCTI gives you the graph, Q-Feeds fills it with prioritised indicators from more than 2,500 commercial, OSINT and governmental sources, filtered for false positives and refreshed every 20 minutes.

Do we have to build a connector?

No. OpenCTI ingests Q-Feeds with the TAXII function it already ships with, so there is no custom connector, nothing to host and nothing extra to keep up to date.

Which indicators do we get?

Malicious IP addresses, domains, URLs and file hashes, each with its category and MITRE ATT&CK mapping. Q-Feeds is an indicator feed, so it complements the actor and campaign research your analysts do in OpenCTI.

Which licence do we need?

TAXII is part of the Enterprise licence. On Community, Plus and Premium you ingest the IP and domain lists as an OpenCTI feed, with malicious URLs on Premium, so you can start on the free Community edition and upgrade when it proves its worth.

Where are the setup steps?

In the OpenCTI setup guide in our knowledge base. It covers every field and both routes, so you can hand it straight to whoever administers your platform.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access