EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
Shared threat intelligence

EudorIA STIX 2.1 feeds

Indicators of compromise and threat context, available for security platforms compatible with STIX 2.1.

Public access, without registration. Acquired data retains provenance, timestamps and sharing markings to support correlation, analysis and detection.

Public collections

SourceContentEndpoint
CISATechnical indicators, MITRE ATT&CK techniques and reports extracted from public advisory attachments.STIX CISA
MISPTechnical indicators with event, object and attribute publication checks. Only values authorised for public sharing are distributed.STIX MISP
OpenCTIPublic entities and metadata received through the signed OpenCTI feed. Reports are distributed as STIX notes, not as a copy of the source graph.STIX OpenCTI

Updates and coverage

Acquisition
Acquisition cycles are scheduled every 30 minutes, with sources reviewed in rotation. Individual source review frequency may vary.
Sharing verification
For MISP, publication permissions must have been verified within the last 24 hours. OpenCTI includes only public metadata synchronised within the last 24 hours.
Historical coverage
Historical backfill is in progress: coverage is not yet complete and varies by source.

Publication and retention are separate: the 24-hour limit governs feed inclusion, not IOC archive retention. Stored data follows the collection's retention policies; an indicator absent from the feed is not automatically harmless or revoked.

View the manifest and CISA coverage

Technical integration

Endpoints distribute STIX 2.1 JSON bundles over HTTPS for clients and connectors compatible with this format.

API parameters, pagination and markings

Pagination

Each successful response contains a STIX 2.1 bundle. To complete retrieval, follow the next-page link supplied in the HTTP header: Link: <...>; rel="next".

Continue while rel="next" is present, even if a page contains no indicators. The cursor advances through source records, not the number of objects in the bundle.

  • after: numeric source-record cursor; initial value 0. Use the value returned by the next-page link.
  • limit: 1 to 20 source records per page, default 10. Each record may generate multiple STIX objects.

Sharing markings

Bundles use TLP:WHITE for public sharing in the adopted STIX profile. Current TLP 2.0 terminology identifies public sharing as TLP:CLEAR. Markings do not replace source terms of use. FIRST TLP specification

Transport and external services

These endpoints are HTTPS feeds, not a TAXII service. Access to CISA AIS and its integration are not included in this service.

Operational use

Assess indicator source, date, confidence and relevance to the systems being protected. Feeds support analysis and detection rules; they are not an automatic blocklist or a guarantee of protection.