Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Before you connect it
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
Imports and exports STIX 1.1.1, 1.2, 2.0 and 2.1 through the MISP-STIX converter used by MISP core. Conversion uses mapped object types; it is not a guarantee of lossless exchange.
Imports and exports STIX 2.1 through configured TAXII feeds. Modified entities may receive new STIX IDs on export; the documented extension does not fully preserve STIX object versioning.
The optional OpenCTI HarfangLab Intel connector converts selected STIX indicator patterns into IOC rules for IP addresses, domains, URLs and file hashes. It is not a general STIX object import.
Uses STIX 2.1 for intelligence objects and exports contextualized indicators through its CTI feed. The documented CTI feed exports indicators rather than raw observables.
Reads IOCs from STIX v2 JSON files and applies the observable types and operators listed in the manual. This is a supported subset, not full STIX model ingestion.