stix2
Produce and consume STIX 2 JSON content
Decision gist · record as of 2026-08-14
Yes, if you work with STIX 2 threat intelligence data. The library has low install friction, no known vulnerabilities, permissive licensing, and active maintenance from OASIS-backed maintainers. The aging status reflects stable maturity rather than abandonment—recent commits and community governance are present. Install it if you need to produce, consume, or transform STIX 2 JSON in a Python application; skip it if you don't work with CTI standards.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low friction installation with four lightweight runtime dependencies.
- Last release was 183 days ago; repository remains active with recent commits and community maintenance, though classified as aging rather than actively developed.
License · maintenance · safety
BSD (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only license and copyright notice preservation in distributions.
last release 2026-02-12 (183 days) · last repo commit 2026-02-12 · 433 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,790,694 downloads/mo, #3,556 on PyPI
Alternatives
Verify before relying
pip install stix2
from stix2 import Indicator
indicator = Indicator(
name="File hash for malware variant",
indicator_types=["malicious-activity"],
pattern_type="stix",
pattern="[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"
)
print(indicator.serialize(pretty=True))- Whether the aging maintenance status reflects planned stability or reduced active development.
- Performance characteristics when handling large volumes of STIX objects or complex pattern queries.
What it is and what it does
stix2 is a Python library for working with STIX 2 (Structured Threat Information Expression), the OASIS standard format for representing and sharing cyber threat intelligence. It provides APIs to construct STIX objects (like indicators, malware, campaigns) by passing keyword arguments to constructors, parse STIX JSON strings into Python objects, and serialize objects back to JSON. The library supports STIX 2.1 at the Committee Specification level and handles common CTI tasks including object versioning, data markings, and resolving STIX identifiers across multiple data sources.
The package depends on pytz for timezone handling, requests for HTTP operations, simplejson for JSON serialization, and stix2-patterns for pattern validation. It is maintained as an OASIS TC Open Repository with BSD-3-Clause licensing, meaning contributions are open to the community. The library supports modern Python versions (3.10 through 3.14) and is positioned for developers building threat intelligence systems, security platforms, or tools that need to consume or produce standardized CTI data.
Use it for
- Parse STIX JSON feeds from threat intelligence platforms and convert them into Python objects for analysis.
- Create and serialize malware indicators, attack patterns, or campaign objects for sharing with other security tools.
- Build a threat intelligence ingestion pipeline that normalizes data from multiple CTI sources into STIX format.
- Validate and version STIX objects as part of a security data management workflow.
- Integrate threat intelligence data into a security information and event management (SIEM) or incident response system.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you work with STIX 2 threat intelligence data.
The library has low install friction, no known vulnerabilities, permissive licensing, and active maintenance from OASIS-backed maintainers. The aging status reflects stable maturity rather than abandonment—recent commits and community governance are present. Install it if you need to produce, consume, or transform STIX 2 JSON in a Python application; skip it if you don't work with CTI standards.
Install
stix2 on PyPI
Before you install
Low friction installation with four lightweight runtime dependencies. Last release was 183 days ago; repository remains active with recent commits and community maintenance, though classified as aging rather than actively developed.
Requires Python 3.10 or later.
License in practice
BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only license and copyright notice preservation in distributions.
Quickstart
pip install stix2
from stix2 import Indicator
indicator = Indicator(
name="File hash for malware variant",
indicator_types=["malicious-activity"],
pattern_type="stix",
pattern="[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"
)
print(indicator.serialize(pretty=True))
Verify before relying
- Whether the aging maintenance status reflects planned stability or reduced active development.
- Performance characteristics when handling large volumes of STIX objects or complex pattern queries.
Package facts
| License | BSD permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagespytzrequestssimplejsonstix2-patterns |
| Maintenance | Aging 183 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,790,694 / month, #3,556 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security |
Evidence: stix2-3.0.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “stix 2 json serialization”
- stix2Serializes and deserializes STIX 2 JSON content, providing Python…
- stix2-validatorValidates STIX 2.x JSON documents against the STIX 2.1 specification,…
- mixboxMixbox provides shared utility code for cybersecurity and threat…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also stix · stix2-patterns · stix2-validator · taxii2-client · OTXv2 · cart · mixbox · pycti · cybox · microsoft-kiota-serialization-json