Summary
The core message of this session was that STIX/TAXII still offers a valuable, vendor-neutral foundation for sharing cyber threat intelligence, but its usefulness depends on better adoption, cleaner implementations, shared interpretation, and higher-quality context. The speakers opened with a healthcare-oriented case study framing: major vendors have suffered ransomware breaches, and internet-facing appliances have exposed vulnerabilities that could lead to compromise. The motivating question was whether organizations could have acted faster if relevant intelligence had already been shared. From there, the session moved into a primer on STIX/TAXII, asking who had used the standards and specifically who had experience with version 2.1 or version 1.
The first main section traced the history and structure of STIX/TAXII. The initiative was launched by MITRE and the Department of Homeland Security in 2012, became popular as a framework or standard for sharing cyber threat intelligence, and was later taken over by OASIS. In 2017, STIX/TAXII 2.0 introduced architectural changes, including a move from XML to JSON, but also brought more complexity and technical debt. Version 2.1, described as the current version in use, provides a detailed specification and language, yet the speakers noted reduced activity since 2022. STIX was explained as the common language for describing threat intelligence through domain objects, relationship objects, indicators, reports, context, and observables. TAXII was presented as the protocol for exchanging that STIX-based intelligence, commonly through TAXII collections and also through TAXII channels.
The speakers then balanced the “good” and “bad” aspects. On the positive side, STIX/TAXII can accelerate intelligence sharing, help organizations correlate reports from different sources, support global collaboration, enable a vendor-neutral ecosystem, and provide components for automated processes such as triage. The speakers connected this need for automation to the speed of current threats and to the idea that AI agents cannot rely on manually written CTI context. On the negative side, adoption has become harder because of interoperability issues, version incompatibilities, heavy maintenance costs, and low-value feeds that may deliver tens of thousands of IOCs without enough usable context.
The final section focused on improving adoption. The speakers argued that the community must create a shared “book of knowledge” so fields are interpreted consistently, otherwise organizations may abandon the standard. They recommended decoupling implementation details such as authentication from the protocol itself and instead relying on industry standards. They also emphasized that high-quality information means more than an IP address: context is needed so recipients understand how to act. Practical recommendations included supporting version 2.1, building precise detections around meaningful IOCs, avoiding excessive feed ingestion, and recognizing that information sharing remains voluntary even though it is foundational to stronger collective defense.
Key Topics
5 key topics from Arnold van Wijnbergen and Giovanni Steernberg at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Prioritize STIX/TAXII 2.1 support for interoperability.
- Model context carefully without overcomplicating implementations.
- Filter feeds to avoid overwhelming analysts with low-value IOCs.
- Build precise detections instead of spraying every indicator.
- Strengthen community alignment around shared field interpretation.
“You want an IP address with context because the context will tell the story”
Up Next

Next in agenda
Keynote: Mapping Microsoft: A Tale of Exploration and 200 Vulnerabilities
Vaisha Bernard
Also on cybersecurity
Power, Trust, Responsibility in Fragmented Digital World
Miguel De Bruycker
Also on cybersecurity
The hype is killing kittens, but not that grumpy old cat
Edwin van Andel