Our CTI now talks STIX 2.1 over a real TAXII 2.1 server.
We kept getting the same question from members running MISP or OpenCTI: "can we just pull this over TAXII instead of hitting your REST API?" So we built it. Discovery, collections, pull, and — new this release — push, all in STIX 2.1.
We adapted to the standard everyone else already built for
Most of the Alliance's data has always been reachable through our own REST endpoints, and honestly that's still the fastest way to get a Crime Score for a single IP. But if you already run a threat intel platform — MISP, OpenCTI, Anomali, ThreatConnect, whatever your team standardised on — those tools expect to speak STIX 2.1 over TAXII 2.1, not a bespoke JSON schema. Writing and maintaining a custom parser for every member's platform doesn't scale. The server sits alongside the existing REST API and the older STIX 2.0 endpoint — nothing was ripped out, we just added the plumbing most CTI tooling already expects.
Standard TAXII 2.1 discovery-to-object walk
If your client already talks TAXII, this should just work — that was the point.
GET /taxii2/ | Discovery — server metadata and the API root. No auth required. |
GET /taxii2/onefirewall/ | API root — version and capability info for the OneFirewall root. |
GET /taxii2/onefirewall/collections/ | Lists the three live collections: IP, domain, and URL indicators. |
GET /collections/{id}/objects/ | Paginated STIX 2.1 Indicators. Supports added_after, limit, next. |
POST /collections/{id}/objects/ | Push — submit up to 50 STIX 2.1 Indicators. New this release. |
GET /collections/{id}/manifest/ | Lightweight change-detection metadata, without pulling full objects. |
