STIX (Structured Threat Information eXpression) is a standardized language for describing cyber threat intelligence — malware, indicators, TTPs, threat actors — in a machine-readable format. TAXII (Trusted Automated eXchange of Intelligence Information) is the transport protocol that carries STIX content between organizations and Threat Intelligence Platforms. Together, STIX/TAXII enables automated ingestion of threat feeds directly into Splunk Enterprise Security.
TLP (Traffic Light Protocol) governs how shared intelligence can be redistributed. TLP:RED = recipient eyes only. TLP:AMBER = restricted to the organization and direct partners. TLP:GREEN = community-wide sharing. TLP:CLEAR = public, unrestricted. As an architect, TLP level determines which intelligence feeds can be operationalized in correlation searches and which must be treated with restricted access controls.
When designing a threat intelligence architecture in Splunk, the architect selects feeds based on: source reliability (track record of the provider), industry relevance (is this feed specific to your sector?), confidence scoring (how certain are the indicators?), and TLP level (can you share or act on this data?). High-volume feeds with low confidence degrade detection quality — selectivity is a design principle.