Skip to content

Hermes STIX 2.1 & TAXII 2.1 Machine-Actionable CTI Feeds


πŸ“‘ Interactive STIX 2.1 Inspector & TAXII Server Workbench

Section titled β€œπŸ“‘ Interactive STIX 2.1 Inspector & TAXII Server Workbench”

Preview, copy, or download standardized CTI bundles directly below, or configure your SIEM/SOAR connectors using the TAXII 2.1 discovery manifest:

OASIS STIX 2.1 & TAXII 2.1 COMPLIANT
SPEC VERSION: 2.1

Machine-Actionable CTI Feeds: STIX 2.1 Exporter & TAXII 2.1 Server

Export the full Hermes Knowledge Graph, cryptographic observations, and prescriptive decision directives as standardized OASIS STIX 2.1 JSON bundles for native ingestion into OpenCTI, MISP, Microsoft Sentinel, and SOAR pipelines.

609 Total STIX Objects
410 Vulnerabilities (SDO)
3 Threat Actors (SDO)
15 Attack Patterns (SDO)
173 Relationships (SRO)
bundle.json (application/stix+json;version=2.1) Loading...
// Loading STIX 2.1 bundle...

πŸ“‘ TAXII 2.1 Integration & SIEM/SOAR Ingestion

Connect your Cyber Threat Intelligence platform directly to Hermes using standard TAXII 2.1 endpoints or by polling static JSON feeds:

OpenCTI TAXII 2.1 Native
TAXII 2.1 Connector Config: URL: https://hermes-codex.vercel.app/api/taxii2/taxii2/
Collection: hermes-all
Version: 2.1
MISP STIX 2.1 Feed
MISP Feed Settings: Source Format: STIX 2.1
URL: https://hermes-codex.vercel.app/api/stix2/bundle.json
Target Event: Auto-publish
Microsoft Sentinel Threat Intel (TAXII)
TAXII Data Connector: Root URL: https://hermes-codex.vercel.app/api/taxii2/taxii2/
Collection ID: hermes-vulnerabilities
Friendly Name: Hermes Codex CTI

As defined in Section 27 of the Hermes Strategic Master Plan, Hermes models all cyber risk concepts into standardized STIX 2.1 Domain Objects (SDOs) and Relationship Objects (SROs):

Vulnerability (SDO)

CVEs & Temporal Scores: Every vulnerability is represented as a STIX vulnerability SDO enriched with custom properties x_hermes_threat_score, x_hermes_inflection, and EPSS probability metrics.

Threat Actor (SDO)

Adversaries & Syndicates: Threat groups (e.g. Akira, Storm-1175, Medusa) mapped as threat-actor SDOs with sophistication ratings and known motivation tags.

Attack Pattern (SDO)

MITRE ATT&CK Techniques: TTPs and agentic prompt injection patterns mapped as attack-pattern SDOs with direct cross-references to the MITRE knowledge base.

Course of Action (SDO)

Prescriptive Directives: Remediation actions from the Hermes Decision Engine compiled into course-of-action SDOs linked via mitigates relationships.


In strict adherence to the static architecture guidelines, all feeds are pre-compiled and served via high-speed global CDN:

EndpointFormatPrimary Use Case
/api/stix2/bundle.jsonOASIS STIX 2.1Full Knowledge Graph import into OpenCTI or MISP
/api/stix2/latest.jsonOASIS STIX 2.1Daily differential delta for real-time alerting
/api/stix2/vulnerabilities.jsonOASIS STIX 2.1Curated vulnerability catalog with HTS scores
/api/taxii2/taxii2/TAXII 2.1 JSONServer Discovery endpoint for TAXII clients
/api/taxii2/root/collections/TAXII 2.1 JSONAPI Root & Collections manifest
/api/entities/index.jsonMachine JSONSection 27 Canonical Entity index
/api/methodology/index.jsonMachine JSONActive methodology versions registry