$npx skillfedfor your agent

stix2

Produce and consume STIX 2 JSON content

With conditionsPyPI SecurityReleased Feb 20261.8M downloads / moBSDPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — stix2-3.0.2-py2.py3-none-any.whl
v3.0.2 · released 2026-02-12 · Python >=3.10 · 4 runtime deps: pytz, requests, simplejson, stix2-patterns

Yes, if you work with STIX 2 threat intelligence data. The library has low install friction, no known vulnerabilities, permissive licensing, and active maintenance from OASIS-backed maintainers. The aging status reflects stable maturity rather than abandonment—recent commits and community governance are present. Install it if you need to produce, consume, or transform STIX 2 JSON in a Python application; skip it if you don't work with CTI standards.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low friction installation with four lightweight runtime dependencies.
  • Last release was 183 days ago; repository remains active with recent commits and community maintenance, though classified as aging rather than actively developed.

License · maintenance · safety

BSD (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only license and copyright notice preservation in distributions.

last release 2026-02-12 (183 days) · last repo commit 2026-02-12 · 433 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,790,694 downloads/mo, #3,556 on PyPI

Verify before relying

pip install stix2

from stix2 import Indicator

indicator = Indicator(
    name="File hash for malware variant",
    indicator_types=["malicious-activity"],
    pattern_type="stix",
    pattern="[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"
)
print(indicator.serialize(pretty=True))
  • Whether the aging maintenance status reflects planned stability or reduced active development.
  • Performance characteristics when handling large volumes of STIX objects or complex pattern queries.
Same gist for agents: .md · .json

What it is and what it does

stix2 is a Python library for working with STIX 2 (Structured Threat Information Expression), the OASIS standard format for representing and sharing cyber threat intelligence. It provides APIs to construct STIX objects (like indicators, malware, campaigns) by passing keyword arguments to constructors, parse STIX JSON strings into Python objects, and serialize objects back to JSON. The library supports STIX 2.1 at the Committee Specification level and handles common CTI tasks including object versioning, data markings, and resolving STIX identifiers across multiple data sources.

The package depends on pytz for timezone handling, requests for HTTP operations, simplejson for JSON serialization, and stix2-patterns for pattern validation. It is maintained as an OASIS TC Open Repository with BSD-3-Clause licensing, meaning contributions are open to the community. The library supports modern Python versions (3.10 through 3.14) and is positioned for developers building threat intelligence systems, security platforms, or tools that need to consume or produce standardized CTI data.

Use it for

  • Parse STIX JSON feeds from threat intelligence platforms and convert them into Python objects for analysis.
  • Create and serialize malware indicators, attack patterns, or campaign objects for sharing with other security tools.
  • Build a threat intelligence ingestion pipeline that normalizes data from multiple CTI sources into STIX format.
  • Validate and version STIX objects as part of a security data management workflow.
  • Integrate threat intelligence data into a security information and event management (SIEM) or incident response system.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work with STIX 2 threat intelligence data.

The library has low install friction, no known vulnerabilities, permissive licensing, and active maintenance from OASIS-backed maintainers. The aging status reflects stable maturity rather than abandonment—recent commits and community governance are present. Install it if you need to produce, consume, or transform STIX 2 JSON in a Python application; skip it if you don't work with CTI standards.

Install

stix2 on PyPI

Before you install

Low friction installation with four lightweight runtime dependencies. Last release was 183 days ago; repository remains active with recent commits and community maintenance, though classified as aging rather than actively developed.

Requires Python 3.10 or later.

License in practice

BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only license and copyright notice preservation in distributions.

Quickstart

pip install stix2

from stix2 import Indicator

indicator = Indicator(
    name="File hash for malware variant",
    indicator_types=["malicious-activity"],
    pattern_type="stix",
    pattern="[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"
)
print(indicator.serialize(pretty=True))

Verify before relying

  • Whether the aging maintenance status reflects planned stability or reduced active development.
  • Performance characteristics when handling large volumes of STIX objects or complex pattern queries.

Package facts

LicenseBSD permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
pytzrequestssimplejsonstix2-patterns
MaintenanceAging 183 days since the last release
Last repo commit
First released
Downloads1,790,694 / month, #3,556 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security

Evidence: stix2-3.0.2-py2.py3-none-any.whl

Tags

Capabilities
stix 2 json serializationcyber threat intelligence pythonstix object creation parsingthreat intelligence data formatoasis stix librarycti json handlingmalware indicator parsing
Topics
threat-intelligencestix-standardcti
PyPI keywords
stixstix2jsoncticyberthreatintelligence

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “stix 2 json serialization”

  • stix2Serializes and deserializes STIX 2 JSON content, providing Python…
  • stix2-validatorValidates STIX 2.x JSON documents against the STIX 2.1 specification,…
  • mixboxMixbox provides shared utility code for cybersecurity and threat…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also stix · stix2-patterns · stix2-validator · taxii2-client · OTXv2 · cart · mixbox · pycti · cybox · microsoft-kiota-serialization-json