Integration

Populate your OpenCTI graph with linked entities, not loose indicators

Point your OpenCTI instance at our native live stream and new intelligence arrives as we publish it, every indicator linked to the malware and campaign it belongs to and merged by stable STIX ID.

  • Native OpenCTI live stream, no polling
  • STIX 2.1 objects with relationships intact
  • 15-day evaluation with setup help

Relationships arrive with the data

PrecisionSec intelligence arrives in OpenCTI as STIX 2.1 objects with the relationships already built: each indicator tied to the malware it detects and the campaign it belongs to, with phishing and C2 observables linked into the same clusters.

Your analysts open an entity and see its connections straight away, ready to pivot across the related malware, campaigns and indicators without rebuilding the links by hand.

PrecisionSec intelligence ingested as entities in the OpenCTI dashboard

Live stream, not scheduled pulls

Connect as a native OpenCTI live stream and your instance syncs continuously with ours. New STIX 2.1 objects land as we publish them, so your analysts work from current intelligence instead of whatever the last scheduled pull happened to catch.

Setup is a synchronizer under Data → Ingestion → OpenCTI Streams: paste the stream URL and token, verify, and start it. The setup guide covers every field, and our team helps if anything looks off.

You can also pull the same intelligence as a TAXII2 collection if you would rather poll. Either way, stable STIX IDs mean updates merge into the entities you already have rather than spawning duplicates on every refresh.

OpenCTI feed statistics for the PrecisionSec stream

Tune what you ingest, at any volume

Pull the full stream or filter it down by malware family and confidence, so your graph stays focused on what your team acts on rather than everything we publish.

As your deployment grows, the stream keeps pace: new objects arrive with their relationships intact, without you re-tuning the pipeline.

IOC counts ingested into OpenCTI from the PrecisionSec feed

What you get with the OpenCTI integration

Relationships, not just indicators

Each indicator ships linked to the malware and campaign it belongs to, so your graph fills with connected entities instead of orphaned observables.

Merges, doesn't duplicate

Stable STIX IDs mean every update resolves against your existing entities, keeping relationships intact across refreshes.

Live stream, set up with you

We walk you through creating the synchronizer, setting your ingestion filters and confirming objects resolve cleanly in your graph. TAXII2 is there if you would rather poll a collection.

Ready to connect? The OpenCTI Live Stream Integration Guide walks through creating the synchronizer step by step, from the stream URL and token through verifying and starting it.

Prefer to poll a collection? The same curated, connected intelligence is available over STIX/TAXII, so it flows into OpenCTI and any other TAXII-compatible tool without losing its relationships. The STIX/TAXII Integration Guide has the connection details.

Frequently asked questions

OpenCTI feed coverage, delivery and trial access

What is the OpenCTI live stream?

It is a native synchronizer. Your OpenCTI instance connects to the PrecisionSec OpenCTI platform and receives STIX 2.1 objects with their relationships already built. There is no scheduled job to run and nothing to import by hand.

Should I use the live stream or TAXII2?

If you run OpenCTI, use the live stream. It is the native path, relationships stay intact and updates arrive continuously. The same intelligence is available as a TAXII2 collection if you prefer to poll, or if you want to deliver the feed to another tool as well.

How do I connect the live stream?

Create a synchronizer under Data → Ingestion → OpenCTI Streams using the stream URL and token we provide, then verify and start it. The OpenCTI Live Stream Integration Guide linked from this page walks every field with screenshots, and our team helps if anything looks off.

Will streamed objects duplicate what I already have?

No. Stable STIX IDs mean each update merges into the entities you already have. Deletion handling can also remove objects that drop off the stream, unless another source imported them first.

Get started

Start a OpenCTI evaluation

Tell us about your OpenCTI deployment and ingestion requirements. We'll help you connect the native OpenCTI live stream to your instance, or set up the TAXII2 collection if you would rather poll, delivering PrecisionSec intelligence as continuously updated STIX 2.1 bundles.

We review every request and follow up as quickly as we can. Trials go to work email addresses. We can’t provision free accounts (Gmail, Outlook, and similar).

By submitting, you agree that PrecisionSec may contact you about this request. See our Privacy Policy.