Skip to main content
QUIETLYTIC
Cybersecurity

STIX Bundle Explorer

Trace the relationship graph inside a STIX bundle object by object.

Local · nothing leaves this browser Waiting for a bundle
Esc Clear
Relationships

Paste a bundle on the left.

How it works

In STIX, a relationship is an object in its own right. That makes a bundle an edge list rather than a tree, and it makes the interesting part — who uses what, what indicates what — a set of UUID pairs pointing elsewhere in the same file. Resolving both ends of every edge to a type and a name is the whole job here.

Sightings are edges too

A sighting links the thing seen to where it was seen. It has no single target the way a relationship does, so the first where_sighted_refs entry is shown as the far end rather than inventing a node that is not in the data.

The two things worth looking for

Dangling edges point at an object that is not in this bundle. That is legal — the object may live in another bundle — but it means nothing here resolves it, and a bundle shared as self-contained evidence generally should not have any.

Orphans are objects no relationship touches. In a bundle assembled by hand or trimmed for sharing, an orphan is often the actual finding: an indicator that was meant to be tied to a campaign and never was, so nothing downstream will ever connect the two.

Example

The sample bundle has one edge — a fictional actor uses a fictional malware family — and two observables that nothing points at. Both observables are reported as orphans, which is exactly the shape of a bundle where indicators were collected but never related to anything.

Frequently asked questions

What is an orphan and why does it matter?

An object no relationship touches. In a bundle assembled by hand or trimmed for sharing it is often the actual finding — an indicator that was meant to be tied to a campaign and never was, so nothing downstream will ever connect the two.

Why are some edges marked dangling?

One of their endpoints is not in this bundle. STIX allows a reference across bundles, so it is not an error, but nothing here resolves it and a bundle shared as self-contained evidence generally should not have any.

How are sightings handled?

A sighting links the thing seen to where it was seen, and has no single target the way a relationship does. The first where_sighted_refs entry is shown as the far end; no synthetic node is invented when there is none.

Does it infer relationships the bundle does not state?

No. Two objects that are related in reality but unlinked in the data are reported as unlinked, because inventing an edge would put an assertion into intelligence that no source made.

Related tools

From the intelligence desk