Threat Intelligence
STIX
Structured Threat Information Expression
Formal standard
Global
OASIS Cyber Threat Intelligence TC
Since 2012
A JSON data model for cyber threat intelligence: indicators, observed data, threat actors, campaigns, malware, courses of action, and the relationships between them.
Relevant to regulated entities mainly through mandated reporting and sector information-sharing schemes, where the ISAC or supervisor expects machine-readable submissions rather than email.
At a glance
- Category
- Threat Intelligence
- Jurisdiction
- Global
- Governance
- OASIS Cyber Threat Intelligence TC
- Status
- STIX 2.1 OASIS Standard (2021), with errata published in 2025
- First released
- 2012
Links
Related frameworks
Other entries under Threat Intelligence.
- MITRE ATT&CK: Adversarial Tactics, Techniques and Common Knowledge
- MITRE D3FEND: Defensive Countermeasures Knowledge Graph
- CWE: Common Weakness Enumeration
- CAPEC: Common Attack Pattern Enumeration and Classification
- TAXII: Trusted Automated Exchange of Intelligence Information
See STIX in context
Open the interactive Data Landscape for Regulation to compare STIX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.