---
title: OpenCTI
description: Collect OpenCTI Threat Intelligence Data for Cloud SIEM
breadcrumbs: Docs > Integrations > OpenCTI
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# OpenCTI
Integration version1.0.0
{% callout %}
# Important note for users on the following Datadog sites: us2.ddog-gov.com

{% alert level="info" %}
To find out if this integration is available in your organization, see your [Datadog Integrations](https://app.datadoghq.com/integrations) page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [support@ddog-gov.com](mailto:support@ddog-gov.com).
{% /alert %}

{% /callout %}
  OpenCTI Dashboard IntroOpenCTI Threat Intel Widgets
## Overview{% #overview %}

The OpenCTI integration for Datadog enriches your security logs with threat intelligence data from OpenCTI, providing actionable context for triage. This integration connects Datadog with your OpenCTI instance to automatically pull and analyze key indicators including IPs, hashes, and domains.

Datadog ingests the threats, enabling deeper visibility into potential risks within your environment. You can correlate this data with logs, metrics, and Cloud SIEM alerts to identify and respond to malicious activity faster.

This integration includes:

- **Threat Intelligence Feeds:** Import IP, hash, and domain risk lists directly into Datadog for continuous enrichment.
- **Cloud SIEM Correlation:** Combine Recorded Future intelligence with Datadog logs to detect and prioritize threats.

For more details on Datadog's OpenCTI connector, see the [Datadog's OpenCTI connector](https://github.com/OpenCTI-Platform/connectors/tree/master/stream/datadog-intel/README.md)

## Setup{% #setup %}

### Prerequisites{% #prerequisites %}

- Access to the `docker-compose.yml` file used to deploy your OpenCTI stack.
- An OpenCTI Admin Token and a generated UUID for the new connector ID

### Setup{% #setup-1 %}

- Follow the OpenCTI connector [setup guide](https://github.com/OpenCTI-Platform/connectors/tree/master/stream/datadog-intel/README.md) to configure your connector.

#### Notes{% #notes %}

- Please allow up to 30 minutes after installation for OpenCTI Threat Intelligence data to begin enriching your logs.

## Uninstallation{% #uninstallation %}

To uninstall the OpenCTI integration:

1. In Datadog, navigate to **Integrations**, select the OpenCTI tile, and click **Uninstall Integration**.
1. Delete all associated OpenCTI accounts in Datadog.
1. Out-of-the-box (OOTB) assets are automatically removed.
1. If you cloned or customized any assets, delete those manually.

Once this integration has been uninstalled, any previous authorizations are revoked. Additionally, ensure that all API keys associated with this integration have been disabled by searching for "OpenCTI" on the **API Keys** page.

## Support{% #support %}

Need help? For permission issues or licensing requirements, reach out to [Filigran](https://filigran.io/contact/).

For configuration or integration errors, contact Datadog support.
