HailBytes + OpenCTI
STIX-native, and it works in both directions.
Inbound: enrichment
HailBytes ASM matches discovered assets, IPs, domains, and hashes against your OpenCTI graph of campaigns, intrusion sets, and indicators. Per-provider TTL, daily quota, and stale-fallback semantics live in the enrichment orchestrator, so a slow or unavailable upstream degrades gracefully instead of stalling the scan pipeline.
Outbound: TAXII 2.1 feed
HailBytes also runs a TAXII 2.1 server, where each project is exposed as one collection. Object IDs are deterministic UUIDv5, which means a republished bundle updates objects in place rather than accumulating duplicates on every poll — the difference between a feed you can leave running and one that needs periodic cleanup.
So OpenCTI can pull HailBytes as a source, rather than only being pushed to. For teams whose TIP is the system of record, that's usually the direction that matters.
Also available
Vulnerability data exports as OpenVEX 0.2.0 (?format=openvex), which drops into Sigstore and Cosign attestation chains and any toolchain consuming VEX statements alongside SBOMs.
You operate your own OpenCTI instance — no upstream billing, and nothing hosted on our side.