Skip to main content
QUIETLYTIC
Cybersecurity

STIX Viewer

Read a STIX 2.1 bundle as structured objects instead of raw JSON.

Local · nothing leaves this browser Waiting for a bundle
Esc Clear
Objects by type

Paste a bundle on the left.

How it works

A STIX bundle is an edge list, not a tree. Every object sits flat in one array and refers to the others by UUID, so reading one as raw JSON means holding a dozen identifiers in your head at once. This groups the objects by type and resolves each to the property that actually names it.

Where the name lives depends on the type

Most Domain Objects carry name. An address or a URL carries value, a directory carries path, a registry key carries key, and a file is identified by its hashes. Falling back to the identifier for all of them would leave a bundle of observables unreadable, which is the problem a viewer exists to solve.

Three shapes accepted

A full bundle, a bare array of objects pulled out of one, or a single object copied from a feed. Which of the three you pasted is reported rather than smoothed over — if you pasted one object, nothing here will talk to you about a bundle.

Nothing is executed

The content is read with JSON.parse, which is a data parser and not an evaluator, and rendered as text nodes rather than markup. A bundle crafted to attack whatever normally consumes it is inert here.

Example

The sample is a four-object bundle: a threat actor, a piece of malware, the relationship that links them, and an IPv4 observable. It is fictional and uses reserved documentation ranges throughout — it exists to show the shape, not to report on anything real.

Frequently asked questions

Why group the objects by type instead of listing them in order?

Because source order in a bundle carries no meaning, and four hundred objects listed flat is not a view of anything. Grouping by type answers the first question a reader has — what is in here — before they start looking for a particular object.

Where does the name of an object come from?

It depends on the type. Most Domain Objects carry name; an address or URL carries value, a directory carries path, a registry key carries key, and a file is identified by its hashes. Showing the identifier for all of them would make a bundle of observables unreadable.

Can I paste something that is not a full bundle?

Yes — a bare array of objects or a single object both work, and which of the three you pasted is reported back. Pasting one object will not produce a page talking about a bundle you do not have.

Is the bundle uploaded anywhere?

No. It is parsed in your own tab and rendered as text nodes. Bundles routinely carry customer indicators and unpublished analysis, so this page makes no network request at all while reading one.

Related tools

From the intelligence desk