A standard language for threat intelligence, covering indicators, attack patterns, threat actors and how they relate. Sentinel can take it in by file import, the upload API or TAXII.
Also called Structured Threat Information Expression.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains STIX in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Threat intelligence-based filtering
Uses Microsoft's threat intelligence feed to flag traffic involving known malicious domains and IP addresses. Every Azure Firewall SKU can raise alerts; only Standard and Premium can block the traffic as well.
- Upload API
Successor to the deprecated platform connector: a TIP or your own app pushes STIX objects straight into Sentinel over REST, with no data connector, signing in as an Entra app that holds Microsoft Sentinel Contributor. The endpoint is per workspace, and the API is still in preview.
- TAXII
A protocol, open to all, for passing STIX intelligence around. Sentinel imports from version 2.0 and 2.1 servers with one connector and exports to 2.1 servers with a separate export connector.
Related terms
- ThreatIntelIndicators
Since 31 July 2025, when ThreatIntelligenceIndicator (the legacy table) stopped getting data, STIX indicators in Microsoft Sentinel have been stored here instead.
- ThreatIntelObjects
Holds STIX objects in Sentinel apart from indicators, like relationships, identities, attack patterns and threat actors. Indicators go in ThreatIntelIndicators next to it.