These general instructions are for connecting the PrecisionSec STIX/TAXII Threat Intelligence Feed to your existing security product.
Credentials required. If you have not yet received evaluation credentials, please request access.
The feed uses TAXII 2.x with bearer token authentication. Use the following connection details:
| Field | Value |
|---|---|
| Discovery URL | https://opencti.precisionsec.com/taxii2 |
| API Root URL | https://opencti.precisionsec.com/taxii2/root/ |
| Collection Title | PrecisionSec TAXII2 Feed |
| Collection ID | 11ceb4b8-95c5-48c4-a242-3af679c9f785 |
| Collection URL | https://opencti.precisionsec.com/taxii2/root/collections/11ceb4b8-95c5-48c4-a242-3af679c9f785/ |
| Authentication | Bearer token |
Configure your TAXII client to send your API token as an Authorization: Bearer <token> header on all requests.
Running OpenCTI? You can connect directly to the PrecisionSec live stream instead of polling the TAXII2 collection. See the OpenCTI Live Stream Integration Guide.
Only need ClickFix indicators? A narrower, free collection scoped to just ClickFix is available — see the ClickFix STIX/TAXII Integration Guide.