STIX (Structured Threat Information Expression)
STIX is a standardized language for describing cyber threat intelligence in a machine-readable format. It enables organizations to share IOCs, TTPs, and threat actor profiles in a consistent way. STIX is often paired with TAXII for transport.
Frequently Asked Questions
What is STIX (Structured Threat Information Expression)?
STIX is a standardized language for describing cyber threat intelligence in a machine-readable format. It enables organizations to share IOCs, TTPs, and threat actor profiles in a consistent way. STIX is often paired with TAXII for transport.
How is STIX (Structured Threat Information Expression) related to TAXII (Trusted Automated eXchange of Intelligence Information)?
STIX (Structured Threat Information Expression) and TAXII (Trusted Automated eXchange of Intelligence Information) are both key concepts in threat intelligence. TAXII is a transport protocol for sharing STIX-formatted threat intelligence between organizations. It defines how threat data is packaged, requested, and delivered. isMalicious provides a TAXII 2.1-compatible endpoint for enterprise consumers.
Related Terms
TAXII (Trusted Automated eXchange of Intelligence Information)
TAXII is a transport protocol for sharing STIX-formatted threat intelligence between organizations. It defines how threat data is packaged, requested, and delivered. isMalicious provides a TAXII 2.1-compatible endpoint for enterprise consumers.
IOC (Indicator of Compromise)
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.