Skip to main content
Data products

STIX/TAXII threat intelligence feeds

IP, domain, URL, and malware hash indicators in STIX 2.1, served over TAXII 2.1. Ingest with any TAXII client, plain curl, or your SIEM's native TAXII input — no proprietary connector required.

Evaluate a feed in my tool

Pro: €99/month. Enterprise: quotation. TAXII polling does not consume the monthly lookup quota. The Free plan does not include feed access.

Open-standard threat feeds · no vendor tools

format
STIX 2.1 · TAXII 2.1
collections
ip · domain · url · hash
refresh
nightly · full rebuild
GET/taxii/api-root/collections/
Shared TAXII collections and their indicator counts
CollectionIndicators
malicious-domainsMalicious Domains18 385 963
malicious-ipsMalicious IP Addresses8 453 503
malicious-urlsMalicious URLs1 211 674
malicious-file-hashesMalicious File Hashes3 874 265
malicious-subdomainsMalicious Subdomains5 848 966
malware-iocsMalware IOCs27 445 218
c2-indicatorsCommand-and-Control Indicators13 048 719
ransomware-iocsRansomware IOCs6 801
phishing-indicatorsPhishing Indicators9 480 350
9 collectionscounted 12 hr. ago
Capabilities

Key features.

Available signals and integration options.

STIX 2.1

Latest standard format for threat intelligence.

TAXII 2.1 Server

Standard protocol for automated feed consumption.

Rich Objects

Inspect the indicator objects and available source metadata in a captured response.

Source context

Check which source and relationship fields are present for the collection you consume.

Nightly Refresh

The shared corpus is rebuilt nightly, by default around 02:00 UTC. Schedule polling after the rebuild and inspect returned dates.

Legacy Support

STIX 2.1 Indicators with OpenCTI-oriented extensions.

Applications

Use cases.

Workflows to evaluate with your existing tools.

MISP Integration

Validate the TAXII client and object mapping used by your MISP deployment.

OpenCTI

Enrich your OpenCTI platform.

Commercial TIPs

Check TAXII 2.1 support and import behavior in the TIP you already use.

Custom Solutions

Build with any TAXII-compatible client.

Evaluation Facts

Use this layer to confirm whether the feed matches your CTI exchange, TIP synchronization, and enrichment requirements.

Formats
STIX 2.1 indicator collections. Inspect an actual response for available object types and fields.
Transport
TAXII 2.1 discovery, API roots, collections, and objects with next-token pagination.
Consumers
Teams using OpenCTI, MISP, SIEM import jobs or custom TAXII clients. Validate the client version and field mapping during evaluation.
Access model
Pro and Enterprise plans, authenticated with your API key. Feed polling does not consume the monthly request quota.
Best fit
Teams that need machine-readable CTI exchange instead of one-off analyst lookups or CSV exports.
Limitations
Collection rebuild time, polling time and indicator observation time are distinct. Confirm compatibility, coverage and false positives before relying on the feed.
Support

Frequently asked questions.

How can I share and ingest threat intelligence using standards like TAXII without vendor tools?

Use a TAXII 2.1 client or the documented HTTP endpoints. Existing SIEM and TIP ingestion options vary by version and deployment. Confirm authentication, STIX field mapping and pagination with an actual import.

How often are the STIX/TAXII feeds updated?

The shared corpus is rebuilt nightly, by default around 02:00 UTC. Polling more frequently does not accelerate that rebuild. Inspect the date fields in the response; a polling timestamp is not the observation time of every indicator.

Does TAXII feed polling consume my monthly request quota?

No. On the plans that include feed access (Pro and Enterprise), feed polling does not count against your monthly API request quota.

How large are TAXII response pages?

Responses use pagination. Follow the next token while the response indicates more results. Verify page size and total import volume for your plan with an actual capture.

What STIX/TAXII versions do you support?

We support STIX 2.1 and TAXII 2.1. Legacy STIX/TAXII 1.x is not offered.

What platforms are compatible?

Evaluate a TAXII 2.1 client for your platform. Support for the standard does not establish that every client version imports every field correctly.

What STIX objects are included?

The endpoint serves STIX 2.1 objects. Inspect the collection and a captured response to confirm the object types, extensions and source fields available for your import.

How do I connect?

Use the documented discovery URL and API key/secret authentication. Pro or Enterprise feed access is required; check the client mapping and follow response pagination.

Cite this data

These figures may be quoted in research, articles and reports. Attribute them to isMalicious with a link to this page, so readers can check the numbers at the source and see how they move.

Attribution text: Source: isMalicious, isMalicious STIX/TAXII Feeds — https://ismalicious.com/data/stix-taxii

Get Started

Ready to get started?

Tell us your current tool, the gap you want to investigate, a success criterion, expected volume and decision date. We will scope an evaluation against your existing sources.

Pro: €99/month. Enterprise: quotation. TAXII polling does not consume the monthly lookup quota. The Free plan does not include feed access.