Elastic Launches Custom Threat Intelligence Integration for STIX Data
Elastic has introduced a new Custom Threat Intelligence integration designed to enhance security visibility within its Search AI Platform. This tool enables security teams to ingest indicators of compromise (IoCs) from diverse sources, including STIX-compliant APIs, TAXII 2.1 servers, and log files in air-gapped environments. A core feature is the automatic conversion of STIX 2.1 format data into the Elastic Common Schema (ECS), facilitating unified analysis and detection workflows. The integration utilizes Common Expression Language (CEL) for flexible API communication, allowing users to customize HTTP requests, authentication, and data processing. It also includes a built-in TAXII 2.1 client for simplified data retrieval and a dedicated dashboard for visualizing threat intelligence patterns. By supporting both connected and isolated environments, this solution helps organizations stay ahead of emerging cyber threats through streamlined data ingestion and improved situational awareness. The release aims to simplify the merging of external threat intelligence into Elastic’s ecosystem, offering both default pipelines for standard mappings and options for custom extensions to handle unique data formats.
Wire timeline
Elastic Launches Custom Threat Intelligence Integration for STIX Data
Elastic has introduced a new Custom Threat Intelligence integration designed to enhance security visibility within its Search AI Platform. This tool enables security teams to ingest indicators of compromise (IoCs) from diverse sources, including STIX-compliant APIs, TAXII 2.1 servers, and log files in air-gapped environments. A core feature is the automatic conversion of STIX 2.1 format data into the Elastic Common Schema (ECS), facilitating unified analysis and detection workflows. The integration utilizes Common Expression Language (CEL) for flexible API communication, allowing users to customize HTTP requests, authentication, and data processing. It also includes a built-in TAXII 2.1 client for simplified data retrieval and a dedicated dashboard for visualizing threat intelligence patterns. By supporting both connected and isolated environments, this solution helps organizations stay ahead of emerging cyber threats through streamlined data ingestion and improved situational awareness. The release aims to simplify the merging of external threat intelligence into Elastic’s ecosystem, offering both default pipelines for standard mappings and options for custom extensions to handle unique data formats.
Elastic Blog - Elasticsearch, Kibana, and ELK Stack