📤 Sharing & Dissemination Hub
Publish and push this platform's intelligence in the formats SIEMs, ISACs and partners consume — STIX 2.1, TAXII 2.1, MISP, CSV/JSON and detection rules. Every channel reads the live database.
Shareable indicators
Enabled rules
TLP marking
Channels
Publish / Subscribe
🧩 STIX 2.1 Bundle
Standards-compliant STIX 2.1 objects (indicators, patterns, markings) for OpenCTI / SIEMs.
📡 TAXII 2.1 Server
Live, pollable TAXII 2.1 API-root & collections — point any TAXII client here.
🔄 MISP Pullable Feed
Standing MISP-format feed (manifest + events + hashes.csv) for MISP's Feeds fetcher.
🎯 Detection Rules
Auto-generate & export YARA / Sigma / Suricata from your IoCs.
🔌 RSS / Flat JSON
Lightweight consumer feeds for non-MISP subscribers.
Push to partners (outbound)
🚀 Push to remote TAXII 2.1
POST a STIX 2.1 bundle to a partner / ISAC TAXII inbox (add-objects). Configure the endpoint + token, then push.
🚀 Push to MISP instance
Create events on a live MISP server via its REST API (Authkey). Configure URL + key, then push.
🏷 TLP Governance
| Marking | Indicators |
|---|---|
| WHITE | 953.2K |
Exports honour a TLP ceiling — set ?tlp= on export.php to cap what leaves.
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron