STIX/TAXII threat intelligence feeds
IP, domain, URL, and malware hash indicators in STIX 2.1, served over TAXII 2.1. Ingest with any TAXII client, plain curl, or your SIEM's native TAXII input — no proprietary connector required.
Pro: €99/month. Enterprise: quotation. TAXII polling does not consume the monthly lookup quota. The Free plan does not include feed access.
Open-standard threat feeds · no vendor tools
- format
- STIX 2.1 · TAXII 2.1
- collections
- ip · domain · url · hash
- refresh
- nightly · full rebuild
| Collection | Indicators |
|---|---|
| malicious-domainsMalicious Domains | 18 385 963 |
| malicious-ipsMalicious IP Addresses | 8 453 503 |
| malicious-urlsMalicious URLs | 1 211 674 |
| malicious-file-hashesMalicious File Hashes | 3 874 265 |
| malicious-subdomainsMalicious Subdomains | 5 848 966 |
| malware-iocsMalware IOCs | 27 445 218 |
| c2-indicatorsCommand-and-Control Indicators | 13 048 719 |
| ransomware-iocsRansomware IOCs | 6 801 |
| phishing-indicatorsPhishing Indicators | 9 480 350 |
Key features.
Available signals and integration options.
STIX 2.1
Latest standard format for threat intelligence.
TAXII 2.1 Server
Standard protocol for automated feed consumption.
Rich Objects
Inspect the indicator objects and available source metadata in a captured response.
Source context
Check which source and relationship fields are present for the collection you consume.
Nightly Refresh
The shared corpus is rebuilt nightly, by default around 02:00 UTC. Schedule polling after the rebuild and inspect returned dates.
Legacy Support
STIX 2.1 Indicators with OpenCTI-oriented extensions.
Use cases.
Workflows to evaluate with your existing tools.
MISP Integration
Validate the TAXII client and object mapping used by your MISP deployment.
OpenCTI
Enrich your OpenCTI platform.
Commercial TIPs
Check TAXII 2.1 support and import behavior in the TIP you already use.
Custom Solutions
Build with any TAXII-compatible client.
Evaluation Facts
Use this layer to confirm whether the feed matches your CTI exchange, TIP synchronization, and enrichment requirements.
- Formats
- STIX 2.1 indicator collections. Inspect an actual response for available object types and fields.
- Transport
- TAXII 2.1 discovery, API roots, collections, and objects with next-token pagination.
- Consumers
- Teams using OpenCTI, MISP, SIEM import jobs or custom TAXII clients. Validate the client version and field mapping during evaluation.
- Access model
- Pro and Enterprise plans, authenticated with your API key. Feed polling does not consume the monthly request quota.
- Best fit
- Teams that need machine-readable CTI exchange instead of one-off analyst lookups or CSV exports.
- Limitations
- Collection rebuild time, polling time and indicator observation time are distinct. Confirm compatibility, coverage and false positives before relying on the feed.
Frequently asked questions.
How can I share and ingest threat intelligence using standards like TAXII without vendor tools?
How often are the STIX/TAXII feeds updated?
Does TAXII feed polling consume my monthly request quota?
How large are TAXII response pages?
What STIX/TAXII versions do you support?
What platforms are compatible?
What STIX objects are included?
How do I connect?
Cite this data
These figures may be quoted in research, articles and reports. Attribute them to isMalicious with a link to this page, so readers can check the numbers at the source and see how they move.
Attribution text: Source: isMalicious, isMalicious STIX/TAXII Feeds — https://ismalicious.com/data/stix-taxii
Related tools.
Ready to get started?
Tell us your current tool, the gap you want to investigate, a success criterion, expected volume and decision date. We will scope an evaluation against your existing sources.
Pro: €99/month. Enterprise: quotation. TAXII polling does not consume the monthly lookup quota. The Free plan does not include feed access.