Filigran
Filigran is a cybersecurity company founded in 2022 that builds the eXtended Threat Management (XTM) suite of open-source and enterprise products for cyber threat intelligence, adversary simulation, and crisis management. Its flagship OpenCTI platform exposes a full GraphQL API for structuring, storing, and disseminating STIX 2.1 threat-intelligence knowledge, while OpenAEV (formerly OpenBAS) provides a RESTful API for breach-and-attack simulation and adversarial exposure validation. Filigran maintains official Python clients (pycti, pyobas), a native embedded Model Context Protocol (MCP) server, TAXII 2.1 and SSE live-stream data sharing, webhooks, and a React component / design-system library. The company is SOC 2 Type 2 and ISO/IEC 27001:2022 certified and is backed by Accel and Insight Partners.
Filigran publishes 2 APIs on the APIs.io network. Tagged areas include Company, Cybersecurity, Threat Intelligence, OpenCTI, and OpenAEV.
The Filigran catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Filigran’s developer surface includes documentation, API reference, getting-started guide, engineering blog, support, authentication, changelog, and 19 more developer resources.
API Rating
APIs
OpenCTI GraphQL API
The OpenCTI platform exposes a full GraphQL API on the /graphql endpoint for programmatic access to cyber threat intelligence knowledge modeled on STIX 2.1. Authentication uses ...
OpenAEV REST API
OpenAEV (formerly OpenBAS) is an ISO 22398-aligned platform for planning and running crisis exercises, adversary simulations, and breach-and-attack simulation. It ships a RESTfu...
MCP Servers
filigran-mcp.yml
MCP SERVEREvent Specifications
Filigran Opencti Webhooks
ASYNCAPIResources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API