Last updated: April 29, 2026
STIX = data format. TAXII = transport. Together: machine-readable threat intel sharing.
STIX object types
- Indicator (the “what to look for”)
- Threat Actor
- Campaign
- Intrusion Set
- Malware
- Tool
- Attack Pattern (= ATT&CK technique)
- Vulnerability (= CVE)
- Identity (= Victim)
- Relationship
Why structured matters
Vendor PDF report → manual extraction. Vendor STIX feed → automatic ingestion into TIP, automatic enrichment of SIEM alerts.
TIPs that consume STIX
- MISP (open source)
- OpenCTI (open source)
- Anomali ThreatStream
- ThreatConnect
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.