OpenCTI-Platform/opencti
Open Cyber Threat Intelligence Platform
About the project
Open source platform for managing cyber threat intelligence knowledge: structures, stores and visualizes technical and non-technical information about cyber threats using a STIX2-based schema. Aimed at threat intelligence analysts and cybersecurity practitioners.
Useful for
- Build a knowledge base of TTPs, observables and threat attribution linked to sources
- Connect OpenCTI with MISP, TheHive and MITRE ATT&CK via connectors for data exchange
- Export data as STIX2 bundles or CSV for reports and integrations
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 0 stars so far today, about 1 expected by the end of the day.
- GitHub Trending TypeScript today: #12, +6 stars.
- Recent forks include notable developers: @yeyintminthuhtut (1,146 followers).
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 10,064
- Today
- 0 · ≈ 1 by evening
- Forks
- 1,463
- Issues and pull requests
- 18,164
- Watchers
- 160
- Language
- TypeScript
- Latest release
- 7.260928.1 · September 28, 2026
- Created
- December 17, 2018
- Last push
- September 29, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 29, 2026GitHub Trending TypeScript today: #12, +6 stars
More in this category
-
6.8
JoasASantos/Offensive-Security-AI-Models
A curated list of open-weight uncensored LLMs fine-tuned for cybersecurity tasks such as red teaming, penetration testing and security research. Each entry lists base model, size, context, VRAM and uncensoring method.
-
4.8
SecFathy/xss-specialist
Research prototype for XSS discovery: an offline study on specializing a small LLM via KEV-gated continual learning plus a live authorized assessment system where findings are confirmed only by execution in a headless…
-
4.7
angusdevgo/Seep-Reverse-Lab
Agent-native reverse engineering workbench for binaries and CWE-602 client-side authorization auditing: unifies Radare2, JADX, Apktool, Frida and IDA via 23 MCP tools with automatic task routing.
-
4.5
dagowda/notRDP
A Havoc C2 plugin that creates a hidden alternate Windows desktop, streams it to a browser viewer, and forwards mouse and keyboard input while staying invisible to the target user.
-
4.2
derv82/wifit3
Cross-platform USB Wi-Fi auditor in Python: scans networks, captures WPA handshakes and PMKIDs, attacks WPS and WEP via its own userland drivers without aircrack-ng.
-
3.8
TwoSevenOneT/InjectSetConsole
Proof of Concept for Windows process code injection via a named pipe, without using VirtualAllocEx or WriteProcessMemory. Demonstrates an EDR evasion technique for security researchers.