> For the complete documentation index, see [llms.txt](https://abrahamreyes9.gitbook.io/cysa+/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://abrahamreyes9.gitbook.io/cysa+/1.0-threat-and-vulnerability-management/1.1-explain-the-importance-of-threat-data-and-intelligence/indicator-management/trusted-automated-exchange-of-indicator-information-taxii.md).

# Trusted Automated eXchange of Indicator Information (TAXII)

For sharing STIX data. TAXII protocol provides a means for transmitting CTI data between servers and clients over HTTPS and a REST API. For example, a CTI service provider would maintain a repository of CTI data. Subscribers to the service obtain updates to the data to load into analysis tools over TAXII. This data can be requested by the client (referred to as a collection), or the data can be pushed to subscribers (referred to as a channel). TAXII services can support various sharing models:&#x20;

* Hub and spoke - one central clearing house&#x20;
* Source / subscriber - one org is a single source of info&#x20;
* P2P - multiple entities exchanging info
