EudorIA STIX 2.1 feeds
Indicators of compromise and threat context, available for security platforms compatible with STIX 2.1.
Public access, without registration. Acquired data retains provenance, timestamps and sharing markings to support correlation, analysis and detection.
Public collections
| Source | Content | Endpoint |
|---|---|---|
| CISA | Technical indicators, MITRE ATT&CK techniques and reports extracted from public advisory attachments. | STIX CISA |
| MISP | Technical indicators with event, object and attribute publication checks. Only values authorised for public sharing are distributed. | STIX MISP |
| OpenCTI | Public entities and metadata received through the signed OpenCTI feed. Reports are distributed as STIX notes, not as a copy of the source graph. | STIX OpenCTI |
Updates and coverage
- Acquisition
- Acquisition cycles are scheduled every 30 minutes, with sources reviewed in rotation. Individual source review frequency may vary.
- Sharing verification
- For MISP, publication permissions must have been verified within the last 24 hours. OpenCTI includes only public metadata synchronised within the last 24 hours.
- Historical coverage
- Historical backfill is in progress: coverage is not yet complete and varies by source.
Publication and retention are separate: the 24-hour limit governs feed inclusion, not IOC archive retention. Stored data follows the collection's retention policies; an indicator absent from the feed is not automatically harmless or revoked.
View the manifest and CISA coverageTechnical integration
Endpoints distribute STIX 2.1 JSON bundles over HTTPS for clients and connectors compatible with this format.
API parameters, pagination and markings
Pagination
Each successful response contains a STIX 2.1 bundle. To complete retrieval, follow the next-page link supplied in the HTTP header: Link: <...>; rel="next".
Continue while rel="next" is present, even if a page contains no indicators. The cursor advances through source records, not the number of objects in the bundle.
after: numeric source-record cursor; initial value 0. Use the value returned by the next-page link.limit: 1 to 20 source records per page, default 10. Each record may generate multiple STIX objects.
Sharing markings
Bundles use TLP:WHITE for public sharing in the adopted STIX profile. Current TLP 2.0 terminology identifies public sharing as TLP:CLEAR. Markings do not replace source terms of use. FIRST TLP specification
Transport and external services
These endpoints are HTTPS feeds, not a TAXII service. Access to CISA AIS and its integration are not included in this service.
Operational use
Assess indicator source, date, confidence and relevance to the systems being protected. Feeds support analysis and detection rules; they are not an automatic blocklist or a guarantee of protection.