Prerequisites
- API key from reyhford.com/portal
curlor any TAXII 2.1 client
TAXII discovery is public. Collections and objects require a valid API key in the
Authorization header.Step 1 — Discover the server
title, versions (2.1), and API roots.
Step 2 — List collections
ics-feed for ICS/OT indicators, or global-feed for all.
Step 3 — Poll for STIX objects
added_after query parameter for incremental polling:
Step 4 — Search via REST (optional)
For programmatic filtering, use the Indicators REST API:Next steps
Authentication
API keys, WorkOS JWT, and TAXII bearer tokens.
Splunk integration
Ingest the TAXII feed into Splunk ES.