STIX Viewer
Read a STIX 2.1 bundle as structured objects instead of raw JSON.
Paste a bundle on the left.
How it works
A STIX bundle is an edge list, not a tree. Every object sits flat in one array and refers to the others by UUID, so reading one as raw JSON means holding a dozen identifiers in your head at once. This groups the objects by type and resolves each to the property that actually names it.
Where the name lives depends on the type
Most Domain Objects carry name. An address or a URL carries value, a directory carries
path, a registry key carries key, and a file is identified by its hashes. Falling back
to the identifier for all of them would leave a bundle of observables unreadable, which is the problem a viewer
exists to solve.
Three shapes accepted
A full bundle, a bare array of objects pulled out of one, or a single object copied from a feed. Which of the three you pasted is reported rather than smoothed over — if you pasted one object, nothing here will talk to you about a bundle.
Nothing is executed
The content is read with JSON.parse, which is a data parser and not an evaluator, and rendered as
text nodes rather than markup. A bundle crafted to attack whatever normally consumes it is inert here.
Example
The sample is a four-object bundle: a threat actor, a piece of malware, the relationship that links them, and an IPv4 observable. It is fictional and uses reserved documentation ranges throughout — it exists to show the shape, not to report on anything real.
Frequently asked questions
Why group the objects by type instead of listing them in order?
Because source order in a bundle carries no meaning, and four hundred objects listed flat is not a view of anything. Grouping by type answers the first question a reader has — what is in here — before they start looking for a particular object.
Where does the name of an object come from?
It depends on the type. Most Domain Objects carry name; an address or URL carries value, a directory carries path, a registry key carries key, and a file is identified by its hashes. Showing the identifier for all of them would make a bundle of observables unreadable.
Can I paste something that is not a full bundle?
Yes — a bare array of objects or a single object both work, and which of the three you pasted is reported back. Pasting one object will not produce a page talking about a bundle you do not have.
Is the bundle uploaded anywhere?
No. It is parsed in your own tab and rendered as text nodes. Bundles routinely carry customer indicators and unpublished analysis, so this page makes no network request at all while reading one.
Related tools
STIX Validator
Check a STIX 2.1 bundle for structural and required-property errors.
LocalSTIX Bundle Explorer
Trace the relationship graph inside a STIX bundle object by object.
LocalYARA Syntax Viewer
Break a YARA rule into its meta, strings and condition sections.
LocalSigma Syntax Viewer
Read a Sigma detection rule as structured logsource and detection blocks.
LocalYARA Rule Formatter
Reformat a YARA rule to consistent indentation and section order.
LocalSigma Rule Formatter
Reorder a Sigma rule’s top-level keys to the conventional sequence.
Local