skip to content

What is the difference between STIX and TAXII when you ingest a partner's phishing-kit indicators?

level: juniorimportance: must knowfreq 70%

answer

  1. one is the noun, one is the courier
  2. typed objects joined by relationships
  3. collections polled over HTTPS
  4. format versus transport
  5. you can ship one without the other

basics

~20 s

STIX is the data format: typed objects such as indicator, malware and relationship that describe adversary activity. TAXII is the HTTPS protocol that moves STIX objects between parties. One says what you mean, the other delivers it.

solid answer

~50 s

STIX is a data model and JSON serialisation for threat information. It gives you typed objects with stable ids and explicit links: an `indicator` carrying a pattern, a `malware` object for the phishing kit, an `infrastructure` object for the sending hosts, and `relationship` objects tying them together, plus handling markings. TAXII is an application-layer protocol over HTTPS that serves those objects: a server exposes API roots and collections, and a consumer polls a collection endpoint, usually with an `added_after` filter so it only pulls what is new since the last run. They are designed together but are separable. Plenty of communities publish STIX bundles over a MISP feed, a git repository or a connector and never run a TAXII server; a TAXII server can serve badly modelled objects. The interview trap is calling TAXII a format or a query language. It is neither.

go deeper

for a junior

Be ready to say in one sentence that STIX is the format and TAXII is the transport, and to name two or three STIX object types. Getting the pair the right way round is most of the mark here.

for a middle

Expect to explain the mechanics: collections polled over HTTPS with an added_after filter, and the STIX object graph of SDOs, SCOs and relationships. Be able to say what the relationships buy you over a flat list of values.

for a senior

Show that you operate the pipe. Talk about monitoring time-since-last-object per collection, expiring ingested indicators, and refusing to treat a partner's indicator as a local finding until your own telemetry matches it.

for a principal

Own the choice of exchange mechanism for a community whose members have unequal tooling, and be able to argue when a TAXII server is worth running at all versus a simpler feed everyone can already consume.

## The one-line version **STIX** (Structured Threat Information Expression) is a *data model plus serialisation*. **TAXII** (Trusted Automated Exchange of Intelligence Information) is an *application-layer transport protocol over HTTPS*. Both are OASIS standards, both are usually seen together, and neither requires the other. STIX is the noun; TAXII is the courier. ## What STIX actually gives you A STIX 2.1 document is JSON. Its content is a graph of typed objects, each with a globally unique id and common properties (`created`, `modified`, `revoked`, `object_marking_refs`, `confidence`): - **SDOs** — the domain objects: `indicator`, `malware`, `attack-pattern`, `infrastructure`, `threat-actor`, `intrusion-set`, `campaign`, `tool`, `identity`, `vulnerability`, `observed-data`, `report`, `grouping`. - **SCOs** — the observable values themselves: `domain-name`, `url`, `ipv4-addr`, `file`, `email-addr`. - **SROs** — the edges: `relationship` (with a `relationship_type` such as `indicates` or `uses`) and `sighting`. - **`marking-definition`** — handling restrictions, typically Traffic Light Protocol, referenced from an object's `object_marking_refs`. The value is the *graph*, not the values. A CSV of two hundred domains tells you nothing about why they matter. A STIX bundle can say: this domain is an indicator that *indicates* this phishing kit, which is *used by* this intrusion set, and it was submitted by this identity under this marking. That structure is what survives the transfer into your platform, and it is what lets an analyst answer "why is this on my blocklist" six months later. ## What TAXII actually gives you A TAXII 2.1 server exposes one or more **API roots**, each holding **collections**. A consumer authenticates over HTTPS and polls a collection's objects endpoint, filtering with parameters such as `added_after` so each run pulls only what arrived since last time; results are paged. That is the whole shape of it. There is no query language, no analytics, no correlation — just discovery, authentication, collections and paged retrieval. One genuinely useful property for a sharing community: collections are the unit of access control. The same server can offer a full collection to vetted members and a reduced collection to associates, without maintaining two feeds by hand. ## Why the separation matters operationally You can consume STIX with no TAXII anywhere: a MISP feed served as JSON over HTTPS, a git repository of bundles, a vendor connector into OpenCTI, even an attachment on a mail. And you can run a TAXII server that serves objects nobody modelled properly — bare `indicator` objects with no relationships, which is a CSV with extra ceremony. When someone says "we are STIX/TAXII compliant", the useful follow-up is which objects they actually populate and whether the relationships are there. ## Reading what arrives — and what does not Two direction errors are worth fixing early. First, an `indicator` is the **producer's claim** that a pattern signals malicious activity. Ingesting it proves that a partner believes something. It proves nothing at all about your estate. Only a match in your own telemetry does that, and even a match is a match, not a compromise. Second, and this is the one that quietly costs organisations months: a collection that returns no new objects for three weeks looks exactly the same whether the producer stopped publishing, your API credential expired, the collection was retired, a proxy is eating the poll, or the sector really is quiet. Absence of output is not evidence of absence of activity. Instrument the poll itself: alert on time-since-last-object per collection and on the object count per poll, not merely on HTTP status. A feed that silently died is worse than no feed, because the empty result reads as reassurance. ## The common wrong answers - "TAXII is the format, STIX is the server." Reversed. - "You need a TAXII server to share STIX." You do not. - "TAXII lets you query the producer's data." It offers filters on a collection endpoint, not a query language. - "We ingest 40,000 indicators a day, so we have good intel." Volume without relationships, markings and expiry is a blocklist, and an ageing one.

  • Your TAXII collection has returned no new objects for three weeks. What do you conclude?
    Nothing yet, and that is the point. A dead poll and a quiet producer look identical from the consumer side: expired credentials, a retired collection, a proxy swallowing the request, or a genuinely idle partner all produce an empty result. Check the last-object timestamp against another member's copy, re-authenticate, and monitor time-since-last-object per collection as a feed-health signal. Never read an empty feed as good news about the sector.
  • If STIX and TAXII are separable, how else do people actually move STIX?
    MISP feeds served as JSON over HTTPS, git repositories of bundles, platform connectors that pull directly from a partner's API, vendor portals with a download, and plain email for one-off sensitive material. Many sharing communities never stand up a TAXII server at all, because the members who could consume it already have a connector for whatever their platform speaks.
  • Which part of a STIX object carries a handling restriction like TLP?
    The `object_marking_refs` property, which points at `marking-definition` objects. Each SDO carries its own markings, so one bundle can mix restrictions object by object. Note this is metadata, not enforcement: nothing in the format stops a recipient copying the value into a ticket, so markings work only because the community agrees to honour them.

STIX is the language the letter is written in; TAXII is the postal service that carries it. You can write the same letter and hand-deliver it.

saying these in an interview costs you the question

  • Calls TAXII a data format or a query language
  • Believes you must run a TAXII server to share STIX
  • Treats an ingested indicator as proof something happened locally
  • Reads an empty TAXII poll as a quiet sector
  • Measures intel quality by indicator volume

context