Skip to main content
Get live ICS/OT threat indicators from Reyhford in under five minutes.

Prerequisites

TAXII discovery is public. Collections and objects require a valid API key in the Authorization header.

Step 1 — Discover the server

Expected response includes title, versions (2.1), and API roots.

Step 2 — List collections

The primary collection is ics-feed for ICS/OT indicators, or global-feed for all.

Step 3 — Poll for STIX objects

Use the added_after query parameter for incremental polling:

Step 4 — Search via REST (optional)

For programmatic filtering, use the Indicators REST API:

Next steps

Authentication

API keys, WorkOS JWT, and TAXII bearer tokens.

Splunk integration

Ingest the TAXII feed into Splunk ES.