OpenCTI

Integration version1.0.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.

Overview

The OpenCTI integration for Datadog enriches your security logs with threat intelligence data from OpenCTI, providing actionable context for triage. This integration connects Datadog with your OpenCTI instance to automatically pull and analyze key indicators including IPs, hashes, and domains.

Datadog ingests the threats, enabling deeper visibility into potential risks within your environment. You can correlate this data with logs, metrics, and Cloud SIEM alerts to identify and respond to malicious activity faster.

This integration includes:

  • Threat Intelligence Feeds: Import IP, hash, and domain risk lists directly into Datadog for continuous enrichment.
  • Cloud SIEM Correlation: Combine Recorded Future intelligence with Datadog logs to detect and prioritize threats.

For more details on Datadog’s OpenCTI connector, see the Datadog’s OpenCTI connector

Setup

Prerequisites

  • Access to the docker-compose.yml file used to deploy your OpenCTI stack.
  • An OpenCTI Admin Token and a generated UUID for the new connector ID

Setup

  • Follow the OpenCTI connector setup guide to configure your connector.

Notes

  • Please allow up to 30 minutes after installation for OpenCTI Threat Intelligence data to begin enriching your logs.

Uninstallation

To uninstall the OpenCTI integration:

  1. In Datadog, navigate to Integrations, select the OpenCTI tile, and click Uninstall Integration.
  2. Delete all associated OpenCTI accounts in Datadog.
  3. Out-of-the-box (OOTB) assets are automatically removed.
  4. If you cloned or customized any assets, delete those manually.

Once this integration has been uninstalled, any previous authorizations are revoked. Additionally, ensure that all API keys associated with this integration have been disabled by searching for “OpenCTI” on the API Keys page.

Support

Need help? For permission issues or licensing requirements, reach out to Filigran.

For configuration or integration errors, contact Datadog support.