Vulnerability (SDO)
CVEs & Temporal Scores: Every vulnerability is represented as a STIX vulnerability SDO enriched with custom properties x_hermes_threat_score, x_hermes_inflection, and EPSS probability metrics.
Preview, copy, or download standardized CTI bundles directly below, or configure your SIEM/SOAR connectors using the TAXII 2.1 discovery manifest:
Export the full Hermes Knowledge Graph, cryptographic observations, and prescriptive decision directives as standardized OASIS STIX 2.1 JSON bundles for native ingestion into OpenCTI, MISP, Microsoft Sentinel, and SOAR pipelines.
// Loading STIX 2.1 bundle... Connect your Cyber Threat Intelligence platform directly to Hermes using standard TAXII 2.1 endpoints or by polling static JSON feeds:
URL: https://hermes-codex.vercel.app/api/taxii2/taxii2/
Collection: hermes-all
Version: 2.1
Source Format: STIX 2.1
URL: https://hermes-codex.vercel.app/api/stix2/bundle.json
Target Event: Auto-publish
Root URL: https://hermes-codex.vercel.app/api/taxii2/taxii2/
Collection ID: hermes-vulnerabilities
Friendly Name: Hermes Codex CTI
As defined in Section 27 of the Hermes Strategic Master Plan, Hermes models all cyber risk concepts into standardized STIX 2.1 Domain Objects (SDOs) and Relationship Objects (SROs):
Vulnerability (SDO)
CVEs & Temporal Scores: Every vulnerability is represented as a STIX vulnerability SDO enriched with custom properties x_hermes_threat_score, x_hermes_inflection, and EPSS probability metrics.
Threat Actor (SDO)
Adversaries & Syndicates: Threat groups (e.g. Akira, Storm-1175, Medusa) mapped as threat-actor SDOs with sophistication ratings and known motivation tags.
Attack Pattern (SDO)
MITRE ATT&CK Techniques: TTPs and agentic prompt injection patterns mapped as attack-pattern SDOs with direct cross-references to the MITRE knowledge base.
Course of Action (SDO)
Prescriptive Directives: Remediation actions from the Hermes Decision Engine compiled into course-of-action SDOs linked via mitigates relationships.
In strict adherence to the static architecture guidelines, all feeds are pre-compiled and served via high-speed global CDN:
| Endpoint | Format | Primary Use Case |
|---|---|---|
/api/stix2/bundle.json | OASIS STIX 2.1 | Full Knowledge Graph import into OpenCTI or MISP |
/api/stix2/latest.json | OASIS STIX 2.1 | Daily differential delta for real-time alerting |
/api/stix2/vulnerabilities.json | OASIS STIX 2.1 | Curated vulnerability catalog with HTS scores |
/api/taxii2/taxii2/ | TAXII 2.1 JSON | Server Discovery endpoint for TAXII clients |
/api/taxii2/root/collections/ | TAXII 2.1 JSON | API Root & Collections manifest |
/api/entities/index.json | Machine JSON | Section 27 Canonical Entity index |
/api/methodology/index.json | Machine JSON | Active methodology versions registry |