Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1228

STIX

Reviewed byCybersecurity entrepreneur & security researcher

What is STIX?

STIXSTIX is an OASIS standard that defines a structured, machine-readable language for representing and exchanging cyber threat intelligence between organizations and tools.


Structured Threat Information eXpression (STIX) is an open language, standardized by the OASIS Cyber Threat Intelligence Technical Committee, for representing cyber threat intelligence in a consistent, machine-readable form. The current version, STIX 2.1, became an OASIS Standard on 10 June 2021 and expresses intelligence as JSON. It defines three object families: 18 STIX Domain Objects (SDOs) such as indicator, malware, threat-actor, campaign, intrusion-set, attack-pattern, tool, and vulnerability; STIX Cyber-observable Objects (SCOs) for raw artefacts like files, IP addresses, and network traffic; and STIX Relationship Objects (SROs) that wire them into a graph (e.g. a threat-actor uses malware that targets an identity).

Because every concept has a stable schema and a globally unique ID, STIX lets producers share context — tactics, techniques, kill-chain phases, sightings, and confidence — rather than isolated indicators, and lets SIEMs, threat-intelligence platforms (TIPs), and SOAR tools ingest the same feed without bespoke parsers. STIX is normally transported by its companion protocol TAXII 2.1 (published the same day), a REST API offering collections and channels for pull/push sharing.

STIX underpins operational sharing across ISACs, national CERTs/CSIRTs, and commercial vendors, and pairs naturally with the Traffic Light Protocol for handling restrictions and with MITRE ATT&CK for technique references. STIX 2.1 supersedes the XML-based STIX 1.x and its older CybOX observable model.

flowchart LR
  subgraph B["STIX 2.1 Bundle (JSON)"]
    TA["Threat Actor (SDO)"] -->|"uses"| MW["Malware (SDO)"]
    IND["Indicator (SDO)"] -->|"indicates"| MW
    IND -->|"based-on"| OD["Observed Data + SCOs"]
  end
  B -->|"shared via TAXII 2.1"| C["SIEM / TIP / SOAR"]

● Examples

  1. 01

    Sharing a malware family with linked indicators, attack-pattern, and threat-actor objects through an ISAC.

  2. 02

    Exporting CTI from a TIP as STIX 2.1 bundles consumed by a SIEM.

● Frequently asked questions

What is STIX?

STIX is an OASIS standard that defines a structured, machine-readable language for representing and exchanging cyber threat intelligence between organizations and tools. It belongs to the Defense & Operations category of cybersecurity.

What does STIX mean?

STIX is an OASIS standard that defines a structured, machine-readable language for representing and exchanging cyber threat intelligence between organizations and tools.

How do you defend against STIX?

Defences for STIX typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for STIX?

Common alternative names include: Structured Threat Information eXpression, STIX 2.1.

● Related terms

● See also