STIX/TAXII feeds
Standard threat intelligence format
Threat intelligence in STIX 2.1 format, delivered via TAXII 2.1. Compatible with all major threat intelligence platforms. Continuous, programmatic integration.
- format
- STIX 2.1 · TAXII 2.1
- collections
- ip · domain · url · hash
- refresh
- 5 min · incremental
Key features. Everything you need to protect your infrastructure and users.
STIX 2.1
Latest standard format for threat intelligence.
TAXII 2.1 Server
Standard protocol for automated feed consumption.
Rich Objects
Indicators, malware, actors, campaigns, and more.
Relationships
Connected threat graph with STIX relationships.
Real-Time Updates
Poll for new objects continuously.
Legacy Support
STIX 2.1 Indicators with OpenCTI-oriented extensions.
Use cases. How security teams use this tool.
MISP Integration
Feed threat data into MISP instances.
OpenCTI
Enrich your OpenCTI platform.
Commercial TIPs
Integrate with ThreatConnect, Anomali, etc.
Custom Solutions
Build with any TAXII-compatible client.
Evaluation Facts
Use this layer to confirm whether the feed matches your CTI exchange, TIP synchronization, and enrichment requirements.
- Formats
- STIX 2.1 indicators, relationships, malware, campaigns, attack patterns, and threat actor objects.
- Transport
- TAXII 2.1 discovery, API roots, collections, objects, and manifest-compatible polling.
- Consumers
- OpenCTI, MISP, commercial TIPs, SIEM enrichment jobs, SOAR playbooks, and custom TAXII clients.
- Access model
- Authenticated access with API credentials, documented rate limits, and plan-based collection availability.
- Best fit
- Teams that need machine-readable CTI exchange instead of one-off analyst lookups or CSV exports.
- Limitations
- STIX/TAXII delivers normalized intelligence objects; sandbox detonation and endpoint telemetry remain external systems.
Connection Parameters
Connect your Threat Intelligence Platform (TIP) or custom TAXII client using the following standard parameters.
| Discovery URL | https://api.ismalicious.com/taxii2/ |
| Authentication | Basic Auth or HTTP Bearer (using your API Key as token/password) |
| Version | TAXII 2.1 (STIX 2.1) |
| Format Header | application/taxii+json;version=2.1 |
OpenCTI Integration
Native support via the built-in TAXII connector.
- Install the TAXII 2 connector in OpenCTI.
- Set the Discovery URL to
https://api.ismalicious.com/taxii2/ - Use Basic Auth: username
apiand password set to your full API credential from the dashboard (the same base64 value as theX-API-KEYheader). - Select the threat collections you wish to import.
MISP Integration
Ingest feeds directly into MISP events and attributes.
- Navigate to Sync Actions > Servers in MISP.
- Add a new TAXII Server connection.
- Enter the Discovery URL and your isMalicious API Key.
- Configure fetch rules for automated pulling.
Frequently asked questions.
What STIX/TAXII versions do you support?
What platforms are compatible?
What STIX objects are included?
How do I connect?
Related tools.
Ready to get started?
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key