HailBytes + OpenCTI
STIX-native, and it works in both directions.
Inbound: enrichment
HailBytes ASM matches discovered assets, IPs, domains, and hashes against your OpenCTI graph of campaigns, intrusion sets, and indicators. Per-provider TTL, daily quota, and stale-fallback semantics live in the enrichment orchestrator, so a slow or unavailable upstream degrades gracefully instead of stalling the scan pipeline.
Outbound: TAXII 2.1 feed
HailBytes also runs a TAXII 2.1 server, where each project is exposed as one collection. Object IDs are deterministic UUIDv5, which means a republished bundle updates objects in place rather than accumulating duplicates on every poll: the difference between a feed you can leave running and one that needs periodic cleanup.
So OpenCTI can pull HailBytes as a source, rather than only being pushed to. For teams whose TIP is the system of record, that's usually the direction that matters.
Also available
Vulnerability data exports as OpenVEX 0.2.0 (?format=openvex), which drops into Sigstore and Cosign attestation chains and any toolchain consuming VEX statements alongside SBOMs.
You operate your own OpenCTI instance, no upstream billing, and nothing hosted on our side.