Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security TAXII
Cyber Security

TAXII

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Cyber Security

TAXII is the transport protocol used to exchange threat intelligence between systems. It defines how STIX content and other intelligence objects are delivered, queried, and synchronised so that organisations can automate collection and distribution instead of relying on manual feeds or ad hoc sharing.

Expanded Definition

TAXII, the Trusted Automated eXchange of Indicator Information, is the transport layer that moves threat intelligence between producing and consuming systems. In practice, it carries STIX objects, indicators, sightings, and related context so organisations can automate ingestion, distribution, and polling instead of manually copying feeds. The distinction matters: STIX defines the intelligence content, while TAXII defines how that content is delivered and retrieved. This separation is why TAXII is often used in SOC pipelines, threat intel platforms, and machine-readable sharing programs where repeatability and schema fidelity are required. The protocol is standardised by OASIS and is most often implemented alongside OASIS Cyber Threat Intelligence Technical Committee specifications. Definitions vary across vendors when they describe TAXII as a “feed,” but that shorthand can obscure its query and collection model.

The most common misapplication is treating TAXII as a static subscription feed, which occurs when teams ignore collections, querying, and versioning semantics.

Examples and Use Cases

Implementing TAXII rigorously often introduces integration and normalisation overhead, requiring organisations to weigh automation speed against the cost of maintaining clean STIX mappings and collection policies.

  • A threat intelligence platform publishes curated indicators to downstream SIEM and SOAR systems through TAXII collections, reducing manual copy-and-paste workflows.
  • A national CERT or industry sharing group exposes a TAXII server so members can pull sector-specific intelligence on a schedule that fits their operational cadence.
  • A detection engineering team queries a TAXII source for updated campaign objects before deploying new blocking rules into EDR or email security controls.
  • An NHI security team correlates intelligence about stolen API keys and service account abuse with internal telemetry, using TAXII delivery to keep signatures current.
  • During MISP or STIX-based sharing, a platform synchronises new observables from a partner feed into local enrichment pipelines rather than relying on emailed reports.

NHIMG notes in its Ultimate Guide to NHIs that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which makes timely intelligence delivery especially relevant. For implementation patterns, practitioners often align TAXII usage with the NIST Cybersecurity Framework 2.0 by linking intelligence collection to detection and response workflows.

Why It Matters in NHI Security

TAXII matters in NHI security because machine identities are often the first assets to be abused when attackers steal tokens, certificates, or API keys. Fast intelligence sharing can shorten dwell time, support blocklist refreshes, and help defenders spot reuse of compromised credentials across environments. That becomes more important when organisations already struggle with visibility and rotation discipline; NHIMG reports that only 5.7% of organisations have full visibility into their service accounts, and 71% of NHIs are not rotated within recommended time frames, conditions that make timely threat intelligence operationally valuable. TAXII also supports governance by making sharing auditable and repeatable, which is critical when multiple teams consume the same intelligence differently. It is closely related to a broader zero trust posture, where identities and signals are continuously evaluated rather than assumed safe.

Organisations typically encounter the limitations of TAXII only after an indicator failed to reach the right control in time, at which point transport reliability becomes operationally unavoidable to address.

For programme context, the Ultimate Guide to NHIs is useful for understanding why service account and API key exposure turns threat intelligence into an identity-security problem, not just a TI plumbing issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07Covers threat intel use cases that protect non-human identities from abuse.
NIST CSF 2.0RS.AN-1Threat intelligence exchange supports analysis during response activities.
NIST Zero Trust (SP 800-207)GV.OV-03Zero trust depends on timely signals that inform continuous authorization.
NIST AI RMFAI risk programs often consume threat intel to manage model and agent abuse.
OWASP Agentic AI Top 10A2Agentic systems need external threat signals to reduce tool abuse risk.

Feed TAXII intelligence into NHI detection and response pipelines to reduce exposure windows.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org