Filigran Connects OpenCTI to Agentic Threat Management
Open Source Threat Intelligence Becomes a Platform
Alan Shimel speaks with Julien Richard, co-founder and CTO of Filigran, about the company’s journey from OpenCTI to a broader threat management platform. Richard explains that OpenCTI began as an open source project built to solve a missing piece in threat intelligence. Over time, enterprise users asked for production support, advanced features and a company behind the technology.
That open source foundation still shapes Filigran’s approach. The company wants practitioners to test, use and improve the software before leaders adopt it at scale. Richard says value often starts with teams in the field, then moves upward as security leaders see which tools actually help analysts work better.
CTEM Needs Better Signal From Threat Intelligence
The conversation turns to CTEM and the gap between leadership expectations and practitioner reality. Richard says many security teams still spend too much time sorting through noise, false positives and fragmented tools. Agentic threat management can help only if it is grounded in high-quality threat knowledge and clear evidence.
Filigran’s approach starts with OpenCTI for threat intelligence, then connects that knowledge to validation and risk assessment. The goal is to move teams from reactive work to proactive, threat-informed defense. Instead of treating each tool or alert as a vertical problem, organizations can use intelligence to decide what matters most.
XTM One Brings Agents Into the Threat Loop
Richard also discusses XTM One, Filigran’s agentic layer for threat management. The platform is designed to orchestrate agents, skills and workflows across OpenCTI, OpenAEV and existing security tools. It gives teams control over the agentic loop, including human review, assessment and evaluation.
For organizations evaluating agentic threat management, the key issue is trust. Agents must enrich knowledge, generate scenarios, provide evidence and help prioritize action without removing human control. Richard argues that the larger opportunity is reducing wasted effort, improving analyst focus and helping teams spend time on threats that can actually affect the business.
Download the State of Threat Management Report https://filigran.io/ctem-market-survey-report/
For more information on the XTM One Platform https://filigran.io/platform/xtm-one/
Transcript
Hey everyone, it's Alan Shimel, and welcome back here to "Techstrong TV" with our continuing coverage from Black Hat 2026 in Las Vegas. We got a chance to get off of the busy, crazy show floor. We're up here at a beautiful suite in the Four Seasons Hotel, actually.
And want to introduce you to my friend, Julien Richard. Julian is a co-founder and CTO of a company called Filigran. If you haven't heard of Filigran, not to worry, hopefully by the time this interview's over, you're going to know all about them.
But first, let's say hello to Julian. " It's great to have you here. All right.
Thank you. Thank you so much. So, as I mentioned, you're one of the co-founders, and you're CTO here.
As a multi-time co-founder myself, I always like to get the story. " Oh, no. Right?
Share with our audience a little bit of your journey. How did you come to wanting to- Yeah ... take the pledge?
Yeah. So it really started a very long time ago. So I'm really an engineer from my studies, and as soon as I come to my first job, I really start to also create and build stuff on my spare time.
So I really takes a lot of time to, let's say, discover different kind of technology, discover different kind of product approach. And it's always in my heart the fact that technology is just there to solve problem and to fix issue for people. And so basically, when you really love technology and love solving problem, you try to experiment a lot of things.
So I spent many years to try different things. I also start different companies myself, but I was alone, just young, just have this feeling I can solve any problem by myself, and basically it's not working like this. You need a team, you need people around you to be able to do it.
So I failed multiple times, and along this, I would say, way, I meet Samuel, the other co-founder of the company, so 15 years ago. And we start building stuff together also, and it's not really succeed, but at some point you have this idea, working at ANSSI at this time, so French agency- Mm-hmm ... government.
And we have this idea about there is a missing piece in threat management, starting from intelligence, so threat intelligence. Mm-hmm. And because we build so many stuff together, so we spend so many times building things, he asked me if I want to also discover this cybersecurity world, and of course, I decide to help him.
And so we create OpenCTI, open source threat intelligence. So- Really? It's, yeah, maybe 20 years of building, creating, failing also, before creating Filigran.
Well, you know what they say, you learn more with your failures- Oh, yeah ... than you do with your successes. Yeah.
It's really part of- Part of your journey ... you need to fail and to learn with failure. Yeah.
And we also learn from success, but it's the combination that is really important. So, in the chicken and egg question, the open source project came before the company? Yeah.
Or the company came first? Yeah. We really wanted to build something useful, so you have to find the value first, and open source is the right way of doing it for us.
It's really important, you expose yourself, you expose your ideas, how you're doing it, and people can just take it, try and learn with it. And so, yeah, I think we build with Samuel OpenCTI for maybe three or four years before having so many people asking for enterprise grade support and going to production with some kind of insurance. Mm-hmm.
But we decide to create Filigran to, let's say, also achieve a vision because only two people to create the next threat management system or to solve all this kind of issue, you cannot just doing that at two people. You need full team, you need everyone behind you, and so we create Filigran to achieve this vision. And we are not done yet on the vision because we decide to create many things and to solve the full threat management loop, so starting with OpenCTI, and then we create the suite of products we need to solve this problem.
I love it. That's a great story. And you know, here's the thing, we see it in AI today even though.
It's open weight, not open source. Uh-huh. But the model is the same, right?
How do you get it to an audience? How do you get that quick feedback loops? How do you get a community coalescing around it?
Open source is a great model, but as you said, you quickly run into the issues that they always run into. Who's gonna support it? Who's gonna train it?
I need premium kind of functionality over and above a community version, let's say. I need a company behind it. I need a throat to choke almost, right?
And then, so the next logical step is usually creating a company. Now, I've been in business a long time. The issue then becomes, but we got to pay the bills, right?
So I want to support this open source community. I want to expand it. I want it to grow and thrive.
And this is something I've spoken to plenty of founders on this. " What was that key moment for you and Samuel? It really comes from the usage and the company that's really start to use it.
Uh-huh. And really, a key system, so they want protection and like you said, maybe some specific enhanced features that it was planned, but two years from now, for example. So you bring back these really important features firstly in your roadmap.
Mm-hmm. And that was the key moment, I think. " Right.
And this enterprise feature that is really hard to develop, hard to maintain, hard to come into an enterprise edition of the product. And so we start to create some specific features under enterprise edition that is easily testable by anyone, because you can generate freely your license for maybe one month if you want to try it. Oh, really?
Yeah. You offer a free one-month trial to... And again, that's from your open source roots, right?
Get your hands on the software. Exactly. Tell me if you like it.
Yeah. Tell me if it bring the value you expect from it. Mm-hmm.
Excellent. Now, we're gonna pivot here in a second, but for people who want to go download it for themselves and take their free month, what's the website? io.
io. But of course you will find the GitHub projects link. On GitHub.
And you have the Docker image and all the technical stuff you need to deploy it directly on your system. Or if you want to try it more easily, you can go to the hub that is a community website, and you can start directly a trial that will deploy OpenCTI, our product directly in our SaaS. And so it's really easy to start like this.
Excellent. io, though. Yeah.
Just as you're seeing on the bottom third of the screen, that's how you spell it. Julian, I want to pivot. You guys recently did a report, yes?
Yeah. What is that about? We ask security leaders about what they think about threat intelligence, the problem about CTEM, and what they think about are we really doing this promising loop about getting the problem until remediation in their system, when they think about the problem and their needs about that.
So I have a feeling I know what some of the answers are going to be, but I'm going to let you lead us here with it. What do you think are the big takeaways, the key findings that our audience should know about? It was quite surprising that there's some leaders that think that there's a lot of things missing in the loop, or the value they find about the CTEM, or there's an active program on it.
So very like, don't really confident about the results and what they do. And on the technical side, like the team really on the field, but achieving every day analysis and really on the field. For them is more like something more we are on it, we take care about it.
So it's the difference between practitioner every day on the field that do all the day, and the leaders that seems to lack of visibility or does not really bring the value on top of it. So it's a bit this difference about- Yeah ... teams fatigue on one side because they act every day and spend their day to prioritize and find the value, and the leaders that definitely does not really have the real value on it.
This is a major development I've seen over the course of my career. When I was co-founding and running companies, we used to hire what they call enterprise salespeople, who would go talk to the CIOs and the CTOs and CFOs and so forth, because they were the ones who signed the check, and that was the people making the decisions. But I think one of the things that happened, and a lot of it was because of open source.
Open source came in the back door, and the field people, as you say, were using it. Mm-hmm. And by the time the leaders found out about it, it was too late to rip out, and not only that, they didn't want to rip it out because it was working.
And I think that motion has carried through, where good leaders look to their field people to say: "What are you using? Why do you like this tool versus that tool? " Now, as I said, good leaders I think do that.
Mm-hmm. There are not good leaders who still insist they're going to tell the field people what's the best tool for them to use. I don't know if that makes sense in today's world.
Yeah, I think the value needs to come from the field first, and then you have to listen about the usage and try to find the right way then to articulate that as a leader to bring the most value on top of it. But yeah, and the open source motion and what we do is, it's really on that direction because people use it, find the value, and tell their leaders that with this kind of tool you can do more than before, and then you need to adapt the workflow and everything you do because in this report, we also have the feedback, like 40% of the time on the field is just loss because they investigate false positive or things that does not really matter. Right.
So there's also team fatigue, and we also need to find a way to make people spend their time to something that really matter. Because at the end of the day, if you really take your times on something that really protects your company, you feel great at the end of the day. Fulfilled.
You feel valuable. You feel valuable. And everyone, no one wants to be a cog in the wheel.
No one wants to be an appendix, you know what I mean? Everybody wants to be involved. And it goes back, Julien, it goes back to you yourself.
You spend all those years just experimenting, your curiosity, your passion- Mm ... to find things, to fix things. I think a lot of people in our industry are like that.
And so it gives them purpose. What were some of the other key findings? Anything in the report that you said, "Wow, I did not have that on my bingo card.
" Anything like that? No, I think it's the same answer about the difference between the leadership and the team, and the fact that the problem is not solved, but some people think about it's done because they already have like 40, 50 tools. Like the cybersecurity, it's plenty of tools you install every day.
So it's really the difference with the perception between I have like hundred of people, 50 tools, and is under control, and people on the field that say, "Okay, that's not manageable. " And it's also what we push as Filigrun as the direction is really like you need to change from reactive to proactive. You need to change your mind and the way you operate.
It's not just about tool, it's also about people interaction, tool interaction, and the full loop around your problem. So stop verticalize the problem and start to think about proactive, and loop and yeah, that's. Understood.
So look, this is a big problem, right? There's a couple of things you touched on. I remember when they used to tell me that 700 security companies were too many.
We can only support 400, 500. Now I think we have 7,000, maybe more. So certainly we have sprawl when it comes to tools and companies.
But we also have this leadership versus field, all of that. We didn't even talk about AI or anything like that, and how that is changing all of this. But I want to ask you though, I think we've identified the problem.
Tell our audience, and I'm going to ask you to look at this camera, if you don't mind. Tell our audience, how does Filigrun help fix, or at least help leaders and field people address this problem and make it better? Yeah, okay.
So at Filigrun, we really think that the threat management, it's a complete loop and you need to change your mind about how you take decision and how finally you solve the problem. So it's come from multiple and different step. The first one, what we think it's the reason we start with OpenCTI, it start with the knowledge.
So you need to get the knowledge and the threats, and understand what's going on. So without this understanding, you are in the dark. You don't really understand, and you don't really know.
And then you need to find in these reports and all of this data, if it's something that can be a problem for you. So we have to cut the noise first because there's so many vendors, so many information you get. So the first step is really to make this information actionable.
So OpenCTI and what we do about threat intelligence is really to achieve this first level of understanding and turn noise into signal. Yeah. Then you want to really check and prove that what you think and what you learn, it may be something that can target and can...
Or say the attacker or the behavior is really something you need to know if you are protected or not. So that's come like the second step, like I want to prove that I'm protecting against this behavior and this knowledge. So that's come OpenAev in the Filigrun stack about, okay, so let's generate scenario.
Let's generate real time and real threat to test it and make evidence. And then you have the third one that is currently still under development about assessment of the risk, because maybe you know that you are not protected, but it does not mean you need to remediate directly, because maybe it's not something very risky for your company. So it's all about prioritization.
So that's the three pillars we create to help all the company to really do some proactive security with what we name threat informed defense. So everything is related to intelligence and to threat knowledge. And then we create XDM1, so it's out since three or four months.
Okay. With all the agentic loop to articulate all of these products, to really create all interaction and automation with full control of the company is really important. You need to control what the AI agents will do.
So your own skills, your own agents, your own model if you want to, to articulate and really automate all the loop between the knowledge to the remediation. So Julien, if it's okay, I want to return to, is it XDM1? XDM1, yeah.
It came out a couple of months ago. Look, everybody is wary today. Well, some people are wary, and some people are jumping up and down, but we're all talking about agentic and agentic workflows and what this means.
I want to make sure our audience understands how the XDM1 is helping in this agentic age, what exactly it's doing. Yeah. So XDM1 is really the missing piece to the articulation and automation of your threat management.
So it's a full agentic platform, really dedicated to the threat management. So basically, you create your own agents. So of course, we pre-provide all the agent, and all the skill with all the experience we have at Filigran about threat management and so on.
So you don't start from blank. But if you want, you have the full control of the agentic loop, so you can create your own agent, customize everything, your skill, and you get the full control. So the human in the loop, the assessment, and the evaluation of your agent.
And so you are able to really basically interconnect the agent with also all your environment because a lot of knowledge is really important knowledge to take decision is not only the threat knowledge, it's also what's currently running in your system, what the kind of tools you use internally. So it's really like a pivotal piece that can interrogate and enrich the information you need to, or say, have trust about the agent and your automation. And so you will be able to take the knowledge, enrich it, create your scenario automatically, and at the end you will have your proof and your evidence, but only if you trust the system.
And so XDM1 is an agentic layer that allow you to trust it and bring, let's say, the most value of your existing tools also. So it's not just all about Filigran tools. It's also like if you already have a threat intelligence platform or already have a tool to create scenario, you can bring XDM1 to articulate the system and your initiative.
Of course, with our own products, it's faster, maybe better, but it's not mandatory to use the full threat of Filigran to achieve the value. It's not the target we have. The target is really to protect companies, not to push every product we develop- With every feature.
Understood. And thank you for doing that. But look, as I told you, I've been in security a long time.
Threat intel is a known quantity now, right? " How big a problem, how big a market though are we talking about, especially now when we start talking about agentic, and the involvement there? How big a problem are we addressing?
And I don't know if you want to address that by money or if you want to address it by impact. Eventually it all comes down to money anyway, but how- Yeah. how big a problem is this?
Yeah, I think threat intelligence, it's a strange market because it's an old one, but at the same time now it's quite new in term of how we think about it and how we use it. So I think the market is really huge about newcomers, like people that's really, okay, think about threat intel. It's not something you can say now you don't need it.
You really need to understand what's going on. And with all of capabilities we give, I think we can come back to what I said about the fatigue of the team, and their feeling about not doing the right thing, and why it's important, because when it comes to money, if you have 40% of your time just spending times to investigate false positive, that's really costly. I think we can say that one company with just a small team, like maybe four or five people, that represents half a million by year of just cost of not doing the right thing.
So- Sure ... you can imagine that for bigger company with a strong security team and experts, that can represent millions. Absolutely.
Julien, I want to thank you for coming on Techstrong TV. Yeah, thank you. I appreciate for doing all this, and I hope the rest of Black Hat is great for you.
And I'm sure we'll be following Filigran as well. io. Exactly.
All right. Thank you. Julien Richard here on Techstrong TV.
Hey, we're going to take a break. We've got more Black Hat stuff coming.