F

Filigran XTM One

by Filigran

Governance & SecurityAI Agents & OrchestrationAutomation & Workflows

An AI agent layer that runs threat exposure management across OpenCTI and OpenAEV as one loop

Free · Subscription · Contact for pricing·Added Aug 10, 2026·Updated Aug 10, 2026
Share:
THE DAILY BRIEF
Filigran XTM One

by Filigran

Governance & SecurityAI Agents & OrchestrationAutomation & Workflows

An AI agent layer that runs threat exposure management across OpenCTI and OpenAEV as one loop

Free · Subscription · Contact for pricing

Filigran XTM One is an AI orchestration layer that connects the company's OpenCTI threat intelligence platform and OpenAEV exposure validation tool into a continuous, agent-driven workflow. It is built for security operations and threat intelligence teams already running Filigran's open-source stack who want ingestion, summarisation, attack simulation and remediation guidance handled by coordinated agents rather than manual handoffs.

At a Glance

Category
Governance & Security
Pricing
Free, Subscription, Contact for pricing
Target Market
CISOs, Threat Intelligence Analysts, Security Operations Leads, CTOs, Government Security Teams
Deployment
Open-source, Self-hosted, Cloud-first, Hybrid
Founded
2022
Headquarters
Paris, France
Customers
6,000+ organisations using Filigran products

Key Features

  • Pre-packaged agent library
  • Continuous CTEM loop
  • Bring your own LLM
  • On-premises deployment
  • OpenCTI threat intelligence foundation
  • 230+ single-click integrations
  • Open-source MCP server

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Automated intelligence enrichment
  • Intel-driven adversary emulation
  • Executive threat reporting
  • Control validation after an advisory
  • Sovereign deployment for government teams

Ideal For

Best For

  • Automating threat intelligence ingestion, enrichment and summarisation at scale
  • Generating and validating adversary emulation scenarios from live threat intelligence
  • Running continuous threat exposure management as one workflow rather than disconnected tools
  • Sovereign or regulated environments needing on-premises deployment and bring-your-own-LLM
  • Teams standardising on STIX2 and MITRE ATT&CK with an open-source foundation they can inspect

Not Ideal For

  • Organisations not already invested in OpenCTI and OpenAEV — XTM One orchestrates those products and delivers little value standalone
  • Small security teams without the operational capacity to run a self-hosted STIX2 threat intelligence stack
  • Buyers who need independently verified performance data, since the headline speed gains are vendor-reported early benchmarks
  • Teams wanting a fully managed SOC outcome rather than an orchestration layer they configure and operate themselves

Market Analysis

Open-sourceEnterprise-gradeSovereign-ready

Pros

  • Genuine open-source foundation lets teams inspect, self-host and extend the stack rather than trusting a black box
  • Well funded for its age, with over $100M raised in three years including a $58M Series C led by Eurazeo
  • Serious enterprise and public sector references including Bouygues Telecom, Capgemini, EDF, Rivian and Swiss federal government
  • SOC 2 Type 2 and ISO 27001:2022 certified, with on-premises and bring-your-own-LLM options for sovereignty requirements
  • 230+ verified integrations materially reduce the connector work that usually sinks threat intelligence deployments

Cons

  • XTM One only launched in June 2026, so there is no independent production track record and no third-party benchmark yet
  • The headline figures — 70% faster threat detection cycles, 80% less offensive testing preparation — are vendor-reported early benchmarks, not verified results
  • Value is largely contingent on already running OpenCTI and OpenAEV; it is an orchestration layer, not a standalone product
  • The OpenCTI repository carries roughly 1,900 open issues, which is a real signal of operational overhead for self-hosting teams
  • Custom agents and workflow orchestration require separate licensing on top of Enterprise Edition, so the 'included at no extra cost' framing only covers the pre-packaged set
  • No published list pricing for either commercial tier

Pricing

Open source

$0

  • OpenCTI and OpenAEV community editions
  • Free MCP server
  • Apache 2.0 community licence

Enterprise Edition

Contact for pricing

  • Pre-packaged XTM One agents at no additional cost
  • Enterprise editions of OpenCTI and OpenAEV
  • Support and Filigran Academy training

Custom

Contact for pricing

  • Custom agents
  • Workflow orchestration
  • Separately licensed

There is a genuine free path: OpenCTI and OpenAEV community editions are open source under Apache 2.0 and the XTM One MCP server is free. Pre-packaged XTM One agents are bundled at no additional cost for existing Enterprise Edition customers, which makes the upgrade cheap if you already pay for Filigran; custom agents and workflow orchestration sit in a separately licensed custom tier. No list prices are published for either commercial tier, so enterprise cost requires a sales conversation.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Filigran XTM One is an AI orchestration layer that connects the company's OpenCTI threat intelligence platform and OpenAEV exposure validation tool into a continuous, agent-driven workflow. It is built for security operations and threat intelligence teams already running Filigran's open-source stack who want ingestion, summarisation, attack simulation and remediation guidance handled by coordinated agents rather than manual handoffs.

Filigran XTM One, launched in June 2026, is an AI orchestration layer — the company calls it an AI-native cockpit — that sits above Filigran's existing eXtended Threat Management suite and automates continuous threat exposure management end to end. Rather than embedding an assistant inside each individual tool, XTM One coordinates pre-packaged agents across the full lifecycle: intelligence ingestion and enrichment, threat summarisation and reporting, attack scenario generation and validation, and remediation guidance. Those agents interact as a continuous loop, so a team can identify a threat in OpenCTI, generate and run an emulation of it through OpenAEV, and validate whether existing defences hold, all from one interface. The underlying products are substantial open-source projects in their own right: OpenCTI structures, stores and visualises technical and non-technical threat data on the STIX2 standard behind a GraphQL API, carries roughly 9,800 GitHub stars under an Apache 2.0 community licence, and integrates with MISP, TheHive and MITRE ATT&CK; OpenAEV, formerly OpenBAS, handles adversary emulation and security validation. Filigran reports over 6,000 organisations using its products, including Bouygues Telecom, Capgemini, EDF, Rivian and the Swiss federal foreign affairs department, with more than 230 verified single-click integrations covering SentinelOne, CrowdStrike, Recorded Future and Mandiant. Commercially, pre-packaged agents are included at no extra cost for Enterprise Edition customers, custom agents and workflow orchestration are separately licensed, and a free open-source MCP server is available. The platform supports bring-your-own-LLM and on-premises deployment. Filigran was founded in October 2022 in Paris and raised a $58 million Series C in October 2025.

Ideal Buyer

A threat intelligence or SecOps lead already running OpenCTI and OpenAEV who wants the manual handoffs between intel, emulation and validation automated by agents.

Key Benefit

One continuous loop from threat identified to exploitability tested to defence validated, with agents doing the ingestion, summarisation and scenario building in between.

At a Glance

Category
Governance & Security
Pricing
Free, Subscription, Contact for pricing
Target Market
CISOs, Threat Intelligence Analysts, Security Operations Leads, CTOs, Government Security Teams
Deployment
Open-source, Self-hosted, Cloud-first, Hybrid
Founded
2022
Headquarters
Paris, France
Customers
6,000+ organisations using Filigran products

Key Features

  • Pre-packaged agent library

    Ready-made agents cover intelligence ingestion, enrichment, summarisation, scenario generation, validation and remediation guidance out of the box.

  • Continuous CTEM loop

    Agents interact so threat identification, exploitability testing and defence validation run as one cycle rather than sequential manual handoffs.

  • Bring your own LLM

    Teams can use Filigran's models or plug in their own, which matters for sovereignty and data-residency-constrained buyers.

  • On-premises deployment

    The stack can be self-hosted rather than consumed as SaaS, supporting air-gapped and regulated government environments.

  • OpenCTI threat intelligence foundation

    STIX2-native storage and visualisation with a GraphQL API, roughly 9,800 GitHub stars and an Apache 2.0 community licence.

  • 230+ single-click integrations

    Verified connectors for SentinelOne, CrowdStrike, Recorded Future, Mandiant, MISP, TheHive and MITRE ATT&CK reduce integration effort.

  • Open-source MCP server

    A free Model Context Protocol server lets external agent frameworks query the threat management stack directly.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Automated intelligence enrichment

    Ingestion agents pull and enrich feeds continuously so analysts start from structured, contextualised intelligence rather than raw reports.

  • Intel-driven adversary emulation

    A threat surfaced in OpenCTI is turned into an OpenAEV attack scenario automatically, closing the gap between knowing and testing.

  • Executive threat reporting

    Summarisation agents draft threat reports from underlying intelligence, cutting the manual writing load on senior analysts.

  • Control validation after an advisory

    When a new advisory lands, agents generate the matching scenario and validate whether current defences actually stop it.

  • Sovereign deployment for government teams

    On-premises hosting with a customer-supplied LLM lets public sector bodies run agentic CTEM without sending data to a vendor cloud.

Ideal For

Best For

  • Automating threat intelligence ingestion, enrichment and summarisation at scale
  • Generating and validating adversary emulation scenarios from live threat intelligence
  • Running continuous threat exposure management as one workflow rather than disconnected tools
  • Sovereign or regulated environments needing on-premises deployment and bring-your-own-LLM
  • Teams standardising on STIX2 and MITRE ATT&CK with an open-source foundation they can inspect

Not Ideal For

  • Organisations not already invested in OpenCTI and OpenAEV — XTM One orchestrates those products and delivers little value standalone
  • Small security teams without the operational capacity to run a self-hosted STIX2 threat intelligence stack
  • Buyers who need independently verified performance data, since the headline speed gains are vendor-reported early benchmarks
  • Teams wanting a fully managed SOC outcome rather than an orchestration layer they configure and operate themselves

Integrations

SDK Available
SDK:PythonJavaScriptTypeScript

Deployment

On-Premise

Market & Ratings

Estimated Customers

6,000+ organisations using Filigran products

Market Analysis

Open-sourceEnterprise-gradeSovereign-ready

Pros

  • Genuine open-source foundation lets teams inspect, self-host and extend the stack rather than trusting a black box
  • Well funded for its age, with over $100M raised in three years including a $58M Series C led by Eurazeo
  • Serious enterprise and public sector references including Bouygues Telecom, Capgemini, EDF, Rivian and Swiss federal government
  • SOC 2 Type 2 and ISO 27001:2022 certified, with on-premises and bring-your-own-LLM options for sovereignty requirements
  • 230+ verified integrations materially reduce the connector work that usually sinks threat intelligence deployments

Cons

  • XTM One only launched in June 2026, so there is no independent production track record and no third-party benchmark yet
  • The headline figures — 70% faster threat detection cycles, 80% less offensive testing preparation — are vendor-reported early benchmarks, not verified results
  • Value is largely contingent on already running OpenCTI and OpenAEV; it is an orchestration layer, not a standalone product
  • The OpenCTI repository carries roughly 1,900 open issues, which is a real signal of operational overhead for self-hosting teams
  • Custom agents and workflow orchestration require separate licensing on top of Enterprise Edition, so the 'included at no extra cost' framing only covers the pre-packaged set
  • No published list pricing for either commercial tier

Pricing

Open source

$0

  • OpenCTI and OpenAEV community editions
  • Free MCP server
  • Apache 2.0 community licence

Enterprise Edition

Contact for pricing

  • Pre-packaged XTM One agents at no additional cost
  • Enterprise editions of OpenCTI and OpenAEV
  • Support and Filigran Academy training

Custom

Contact for pricing

  • Custom agents
  • Workflow orchestration
  • Separately licensed

There is a genuine free path: OpenCTI and OpenAEV community editions are open source under Apache 2.0 and the XTM One MCP server is free. Pre-packaged XTM One agents are bundled at no additional cost for existing Enterprise Edition customers, which makes the upgrade cheap if you already pay for Filigran; custom agents and workflow orchestration sit in a separately licensed custom tier. No list prices are published for either commercial tier, so enterprise cost requires a sales conversation.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Connect

Sources

This page was written from 5 sources, 3 on domains other than filigran.io.

  1. 1.filigran.iofiligran.iovendor
  2. 2.filigran.iofiligran announces a new 58 million funding round to accelervendor
  3. 3.siliconangle.comfiligran launches xtm one automate threat exposure managemen
  4. 4.securityweek.comfiligran raises 58 million in series c funding
  5. 5.github.comopencti
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe