TAXII
Definition
Trusted Automated eXchange of Intelligence Information. The transport protocol used to share STIX content between organisations. TAXII defines server and client roles, collection discovery, and pull or push delivery mechanisms. Used together with STIX to enable automated, cross-organisation intelligence sharing.
- Full name
- Trusted Automated eXchange of Intelligence Information
- Function
- Transport protocol for STIX content
- Roles defined
- Server and client
- Delivery modes
- Pull or push
Common questions
What is the relationship between TAXII and STIX?+
STIX defines the structured data format for describing a threat, such as an indicator, malware, or actor. TAXII is the separate transport layer that moves that STIX data between systems, so the two are used together but solve different problems: content format versus content delivery.
What does TAXII's collection discovery capability let a client do?+
It lets a client query a TAXII server to find out what threat intelligence collections that server exposes before subscribing, so organisations can discover and select relevant feeds programmatically rather than negotiating access manually.
Related terms
- Diamond Model
- An analytic framework that structures a cyber intrusion event around four linked elements: adversary, capability, infrastructure, and victim. The model makes explicit...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- STIX
- Structured Threat Information eXpression. A standardised, machine-readable language for encoding and sharing threat intelligence objects such as indicators, threat actors, campaigns, and...
- Tactics, Techniques, and Procedures (TTPs)
- A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....