Integration · Threat Intelligence

HailBytes + OpenCTI

STIX-native, and it works in both directions.

Inbound: enrichment

HailBytes ASM matches discovered assets, IPs, domains, and hashes against your OpenCTI graph of campaigns, intrusion sets, and indicators. Per-provider TTL, daily quota, and stale-fallback semantics live in the enrichment orchestrator, so a slow or unavailable upstream degrades gracefully instead of stalling the scan pipeline.

Outbound: TAXII 2.1 feed

HailBytes also runs a TAXII 2.1 server, where each project is exposed as one collection. Object IDs are deterministic UUIDv5, which means a republished bundle updates objects in place rather than accumulating duplicates on every poll — the difference between a feed you can leave running and one that needs periodic cleanup.

So OpenCTI can pull HailBytes as a source, rather than only being pushed to. For teams whose TIP is the system of record, that's usually the direction that matters.

Also available

Vulnerability data exports as OpenVEX 0.2.0 (?format=openvex), which drops into Sigstore and Cosign attestation chains and any toolchain consuming VEX statements alongside SBOMs.

You operate your own OpenCTI instance — no upstream billing, and nothing hosted on our side.

All threat intel integrations → API reference → Talk to us →