Automation

Filigran's XTM One Uses AI Agents to Automate Threat Management

The orchestration layer connects threat intelligence and exposure validation tools into a continuous workflow, eliminating manual handoffs between security systems.

Omega Editorial· June 9, 2026· 3 min read

Filigran introduces AI orchestration for security workflows

French cybersecurity firm Filigran has released XTM One, an orchestration layer that uses coordinated AI agents to automate continuous threat exposure management across its security platform.

The system bridges Filigran's OpenCTI threat intelligence platform and OpenAEV exposure validation tool, creating an automated workflow where security teams previously moved manually between disconnected systems. Organizations typically ingest threat intelligence in one application, construct attack scenarios in another, and monitor remediation through separate dashboards. XTM One eliminates those manual transitions by routing information and tasks between AI agents throughout the security lifecycle.

How the agent coordination works

Unlike AI features embedded within individual products, XTM One operates as a dedicated coordination layer where agents work across Filigran's product suite. The platform includes prebuilt agents that handle intelligence ingestion and enrichment, threat summarization, attack scenario generation, validation testing, and remediation guidance. These agents form a continuous loop that identifies priority threats, tests their exploitability, and validates defenses from a unified interface.

According to co-founder Julien Richard, the platform addresses a fundamental capacity problem. "The volume of CVEs, threat actors and attack campaigns has reached a scale no human team can process manually," Richard said. "XTM One is not AI as a feature. It is AI as the operating system for threat management."

Early benchmarks indicate organizations using the platform achieve up to 70% faster threat detection and response cycles and reduce preparation time for offensive security testing by up to 80%, according to Filigran.

Deployment and customization options

XTM One supports custom agent development and workflow creation. Organizations can use Filigran's models or integrate their own through Bring Your Own LLM functionality. The platform can be deployed on-premises, a capability Filigran is targeting at regulated industries and government agencies with data residency requirements.

Jean-Philippe Salles, vice president of product management at Filigran, said the natural-language interface reduces barriers to adoption. The system allows junior analysts to become productive more quickly while removing repetitive tasks from experienced practitioners.

Pricing and availability

Filigran will offer XTM One in three tiers. Current Enterprise Edition customers of OpenCTI or OpenAEV receive prepackaged agents, a usage quota, and BYOLLM support at no additional charge. Organizations requiring custom agent creation, workflow orchestration, and premium model packages can license XTM One separately. A free, open-source Model Context Protocol server is available for integrating Filigran products into other AI architectures regardless of subscription tier.

The product is scheduled for general availability this month.

Why it matters

Security teams face an expanding attack surface and accelerating threat volume that outpaces manual analysis capabilities. By automating the handoffs between threat intelligence collection, scenario testing, and remediation tracking, XTM One addresses a workflow bottleneck that forces organizations to choose between speed and thoroughness. The platform's on-premises deployment option and BYOLLM support also reflect growing enterprise demand for AI systems that don't require sending sensitive security data to third-party cloud services.

Filigran, founded in 2022, raised $58 million in a Series C round in October backed by Eurazeo, Insight Partners, Accel Partners, and Deutsche Telekom's T.Capital.

Details of the XTM One launch were first reported by SiliconANGLE.

#cybersecurity#ai agents#threat intelligence#security automation#filigran#exposure management

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Automation

Automation· 3 min read

Relatient Expands Voice AI to Automate Clinical Phone Requests

New capability routes nursing questions, prescription inquiries, and billing calls directly into EHR workflows without staff intervention.

Via Automation Watch · Jul 23, 2026
Automation· 3 min read

Candid Health raises $120M to automate healthcare billing with AI

The revenue cycle management startup tripled its valuation while processing $7 billion in annual claims for over 200 healthcare organizations.

Via Automation Watch · Jul 23, 2026
Automation· 2 min read

Tariffs May Boost US Auto Plants but Cut Jobs Through Automation

Economist warns that reshoring manufacturing could paradoxically reduce employment as companies turn to 'dark factories' and AI-driven production.

Via AI Watch · Jul 23, 2026