Deploy OpenCTI 7 Threat Intelligence Platform

Collect, link and share cyber threat intel. Full stack with workers.

Deploy OpenCTI 7 Threat Intelligence Platform

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Just deployed

Bucket

Bucket

Just deployed

Deploy and Host OpenCTI with Railway

Deploy on Railway

OpenCTI is an open-source platform for structuring, storing and sharing cyber threat intelligence as a STIX 2.1 knowledge graph. This community template deploys the full OpenCTI 7 stack on Railway: the platform, three workers, Elasticsearch, Redis, RabbitMQ, a Railway Bucket for files, and the ten built-in connectors from the official Docker setup.

About Hosting OpenCTI

OpenCTI's platform serves the web UI and GraphQL API and stores its knowledge graph in Elasticsearch. Redis holds caches and live event streams, RabbitMQ distributes work, and S3-compatible storage keeps uploaded reports and exports. Workers consume the queues and write data through the API, and connectors import or export data. This template follows the official docker-compose service by service, pins every image to the same release, generates all credentials, stores files in a Railway Bucket instead of MinIO, and loads the MITRE ATT&CK and OpenCTI reference datasets on first start.

Common Use Cases

  • Building a central threat intelligence knowledge base for a SOC or CERT team
  • Mapping threat actors, campaigns and malware to MITRE ATT&CK techniques
  • Importing PDF and HTML threat reports and extracting indicators and observables
  • Sharing curated intelligence as STIX 2.1 bundles, CSV or TAXII feeds
  • Connecting external feeds and enrichment services through OpenCTI connectors

Dependencies for OpenCTI Hosting

  • OpenCTI platform, worker and connectors 7.261008.0 (official opencti/* images)
  • Elasticsearch 8.19
  • Redis 8.2 (Railway Redis)
  • RabbitMQ 4.3 with the management plugin
  • S3-compatible object storage (Railway Bucket)

Deployment Dependencies

Implementation Details

ServiceImageRole
OpenCTIopencti/platform:7.261008.0Web UI, GraphQL API, background managers; public domain
OpenCTI Worker (3 replicas)opencti/worker:7.261008.0Processes queued bundles into the knowledge graph
connector-export-file-stix / -csv / -txtopencti/connector-export-file-*Exports to STIX 2.1, CSV and plain text
connector-import-file-stix, connector-import-document, connector-import-file-yaraopencti/connector-import-*Imports STIX files, PDF/text/HTML reports and YARA rules
connector-analysisopencti/connector-import-documentContent analysis of reports
connector-import-external-referenceopencti/connector-import-external-referenceFetches external reference URLs as files
connector-opencti, connector-mitreopencti/connector-opencti, opencti/connector-mitreReference datasets (markings, sectors, countries) and MITRE ATT&CK
Elasticsearchbuilt from services/elasticsearch (elasticsearch:8.19.21)Knowledge graph indexes (volume)
RabbitMQrabbitmq:4.3.6-managementWork queues (volume)
Redisredis:8.2Cache, streams, locks (volume)
BucketRailway BucketUploaded files, imports, exports

First login: wait until the OpenCTI service is healthy, open its public URL and log in with APP__ADMIN__EMAIL (default admin@opencti.io, change it before the first deploy if you like) and the generated APP__ADMIN__PASSWORD from the OpenCTI service variables. Change the password in your profile. MITRE ATT&CK and the OpenCTI datasets start importing immediately; on the very first start these two connectors may restart once or twice while their service accounts are created.

Adding connectors: OpenCTI's connector manager normally starts containers through Docker, which Railway does not offer. Add each extra connector as its own Railway service with the image opencti/connector-{name}:7.261008.0, OPENCTI_URL and OPENCTI_TOKEN copied from an existing connector, a new UUIDv4 CONNECTOR_ID, and the connector's own settings from the connectors catalog.

Scaling: raise the OpenCTI Worker replica count for faster ingestion. Give Elasticsearch more memory together with a larger ES_JAVA_OPTS heap, and the platform more memory together with NODE_OPTIONS, as your knowledge base grows.

E-mail: OpenCTI sends notifications over SMTP only. Add SMTP__HOSTNAME, SMTP__PORT, SMTP__USERNAME, SMTP__PASSWORD and SMTP__USE_SSL to the OpenCTI service; Railway allows outbound SMTP on the Pro plan.

Versions: every OpenCTI image is pinned to 7.261008.0. Upgrade by changing the tag on the platform, worker and all connectors together; the platform migrates its data on start. OpenCTI also publishes an LTS line if you prefer fewer upgrades.

Why Deploy OpenCTI on Railway?

OpenCTI needs several cooperating services. Railway runs them all in one project with private networking, persistent volumes, a managed S3 bucket and an HTTPS domain, so the complete stack, with reference data loaded, comes up from one template. You can scale workers and give Elasticsearch more resources from the dashboard as your intelligence grows.


Template Content

More templates in this category

View Template
Rocky Linux
Hosted Rocky Linux 9 workspace with SSH and persistent storage. 🚀

codestorm
48
View Template
Foundry Virtual Tabletop
A Self-Hosted & Modern Roleplaying Platform

Lucas
71
View Template
Letta Code Remote
Run a Letta Code agent 24/7. No inbound ports, just deploy.

Letta
51