Filigran's XTM One Uses AI Agents to Automate Threat Management
The orchestration layer connects threat intelligence and exposure validation tools into a continuous workflow, eliminating manual handoffs between security systems.

Filigran introduces AI orchestration for security workflows
French cybersecurity firm Filigran has released XTM One, an orchestration layer that uses coordinated AI agents to automate continuous threat exposure management across its security platform.
The system bridges Filigran's OpenCTI threat intelligence platform and OpenAEV exposure validation tool, creating an automated workflow where security teams previously moved manually between disconnected systems. Organizations typically ingest threat intelligence in one application, construct attack scenarios in another, and monitor remediation through separate dashboards. XTM One eliminates those manual transitions by routing information and tasks between AI agents throughout the security lifecycle.
How the agent coordination works
Unlike AI features embedded within individual products, XTM One operates as a dedicated coordination layer where agents work across Filigran's product suite. The platform includes prebuilt agents that handle intelligence ingestion and enrichment, threat summarization, attack scenario generation, validation testing, and remediation guidance. These agents form a continuous loop that identifies priority threats, tests their exploitability, and validates defenses from a unified interface.
According to co-founder Julien Richard, the platform addresses a fundamental capacity problem. "The volume of CVEs, threat actors and attack campaigns has reached a scale no human team can process manually," Richard said. "XTM One is not AI as a feature. It is AI as the operating system for threat management."
Early benchmarks indicate organizations using the platform achieve up to 70% faster threat detection and response cycles and reduce preparation time for offensive security testing by up to 80%, according to Filigran.
Deployment and customization options
XTM One supports custom agent development and workflow creation. Organizations can use Filigran's models or integrate their own through Bring Your Own LLM functionality. The platform can be deployed on-premises, a capability Filigran is targeting at regulated industries and government agencies with data residency requirements.
Jean-Philippe Salles, vice president of product management at Filigran, said the natural-language interface reduces barriers to adoption. The system allows junior analysts to become productive more quickly while removing repetitive tasks from experienced practitioners.
Pricing and availability
Filigran will offer XTM One in three tiers. Current Enterprise Edition customers of OpenCTI or OpenAEV receive prepackaged agents, a usage quota, and BYOLLM support at no additional charge. Organizations requiring custom agent creation, workflow orchestration, and premium model packages can license XTM One separately. A free, open-source Model Context Protocol server is available for integrating Filigran products into other AI architectures regardless of subscription tier.
The product is scheduled for general availability this month.
Why it matters
Security teams face an expanding attack surface and accelerating threat volume that outpaces manual analysis capabilities. By automating the handoffs between threat intelligence collection, scenario testing, and remediation tracking, XTM One addresses a workflow bottleneck that forces organizations to choose between speed and thoroughness. The platform's on-premises deployment option and BYOLLM support also reflect growing enterprise demand for AI systems that don't require sending sensitive security data to third-party cloud services.
Filigran, founded in 2022, raised $58 million in a Series C round in October backed by Eurazeo, Insight Partners, Accel Partners, and Deutsche Telekom's T.Capital.
Details of the XTM One launch were first reported by SiliconANGLE.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call

