STIX 2.1 defines a structured language and serialization for representing cyber threat intelligence, while TAXII 2.1 defines an application-layer protocol and RESTful API for communicating cyber threat information. Supporting a STIX object model does not by itself prove TAXII transport support, and supporting a TAXII endpoint does not prove semantic compatibility with every producer or consumer.
External reference
STIX 2.1 is the OASIS threat-intelligence representation standard, with current published material including 2025 errata. TAXII 2.1 is an OASIS Standard defining a RESTful API and resources for communicating cyber threat information.
Primary source →Operational method
Separate representation from transport
Confirm whether a requirement concerns the STIX data model, TAXII transport, both, or a different integration path such as webhook, API or file import.
Define the required objects and relationships
List the indicator, malware, threat-actor, relationship, sighting or other intelligence objects the workflow actually needs rather than claiming generic “STIX support.”
Define TAXII capabilities
Where TAXII is required, verify discovery, API root, collection, authentication, filtering, pagination and object lifecycle expectations against the actual implementation.
Test producer/consumer compatibility
Use representative objects from the intended counterparties and verify parsing, field preservation, version handling, access control and error behavior.
Document unsupported semantics
Record extensions, custom properties, object types or workflows that are not preserved so interoperability claims remain bounded.
Relevant Cybatar sources
Claim boundary
Cybatar public documentation does not currently establish native STIX 2.1 or TAXII 2.1 client/server conformance. Any STIX/TAXII interoperability requirement must be verified against the deployed integration path before it is claimed.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.