rsigma taxii sync
rsigma taxii sync
Fetch objects from a TAXII 2.1 collection and persist them in a local on-disk STIX store (FsStore).
Requires the taxii-sync Cargo feature (included in prebuilt release binaries and the GHCR image built with --all-features).
Synopsis
rsigma taxii sync --server <URL> --collection <ID> --store <DIR> [OPTIONS]
Description
taxii sync calls ingest_collection_with_bundle_id with IngestOptions::producer_strict() — per-object validation before import, References phase skipped for paginated pages (see validate-on-ingest). The TAXII client fetches one page at a time (--limit, default 64); forward references across pages resolve after the full collection is imported.
When --api-root is omitted, the client runs TAXII discovery and uses the server-declared default API root. Pass --api-root explicitly when the feed uses a non-default root.
Re-running sync against the same store is idempotent: unchanged objects increment objects_deduplicated rather than objects_added.
Flags
Required
| Flag | Description |
|---|---|
--server <URL> |
TAXII server base URL (scheme + host, optional path prefix). |
--collection <ID> |
Collection id to ingest. |
--store <DIR> |
FsStore root directory (created when missing). |
Connection
| Flag | Default | Description |
|---|---|---|
--api-root <URL> |
discovery | Full API root URL. When omitted, discovery runs and the default API root is used. |
--timeout <DURATION> |
60s |
HTTP timeout (humantime duration). |
--limit <N> |
64 |
TAXII page size (limit query parameter). Must be > 0. |
--allow-insecure-http |
off | Allow http:// URLs (local tests and wiremock only). |
--allow-custom |
off | Parse MITRE ATT&CK and other custom SDOs (x_* types). |
Authentication (at most one)
| Flag | Env | Description |
|---|---|---|
--bearer-token <TOKEN> |
RSIGMA_TAXII_BEARER_TOKEN |
Authorization: Bearer …. Export the env var or pass --bearer-token on the same command line; a bare assignment on the previous line is not inherited by the next command in most shells. |
--basic-user + --basic-password |
RSIGMA_TAXII_BASIC_PASSWORD |
HTTP Basic |
--api-key <VALUE> |
RSIGMA_TAXII_API_KEY |
Custom header (name via --api-key-header, default X-API-Key) |
mTLS
| Flag | Description |
|---|---|
--client-cert-pem + --client-key-pem |
PEM certificate and private key |
--client-p12 + --client-p12-password |
PKCS#12 / PFX identity (RSIGMA_TAXII_CLIENT_P12_PASSWORD) |
Import / validation
| Flag | Default | Description |
|---|---|---|
--bundle-id <ID> |
bundle--00000000-0000-0000-0000-000000000001 |
Synthetic bundle id for export_bundle. |
--strict |
on | Exit 1 when validation rejects one or more objects. |
--allow-invalid |
off | Import objects even when validation fails (diagnostics still recorded; conflicts with --strict). |
Output
Structured summary via the global --output-format flag (json, ndjson, table, csv, tsv). Validation rejections are listed on stderr when progress output is enabled.
Exit codes
| Code | Meaning |
|---|---|
0 |
Sync completed; no validation rejections (or --allow-invalid). |
1 |
Validation rejected one or more objects under default --strict. |
3 |
Configuration, store, or TAXII client error. |
Examples
Sync a collection into ./stix-store with a bearer token:
rsigma taxii sync \
--server https://taxii.example.com/ \
--api-root https://taxii.example.com/api1/ \
--collection <COLLECTION_ID> \
--store ./stix-store \
--bearer-token "$RSIGMA_TAXII_BEARER_TOKEN" \
--allow-custom
MITRE ATT&CK Enterprise (STIX 2.1 TAXII collection; requires --allow-custom for x-mitre-* types):
rsigma taxii sync \
--server https://attack-taxii.mitre.org/ \
--api-root https://attack-taxii.mitre.org/api/v21/ \
--collection x-mitre-collection--1f5f1533-f617-4ca8-9ab4-6a02367fa019 \
--store ./attck-store \
--allow-custom
List available collections (Enterprise, ICS, Mobile share the same ids across API roots):
curl -sS \
-H 'Accept: application/taxii+json;version=2.1' \
'https://attack-taxii.mitre.org/api/v21/collections/' \
| jq '.collections[] | {id, title}'
Pin a specific ATT&CK release by changing the API root (collection ids stay the same):
--api-root https://attack-taxii.mitre.org/api/v21/attack-19.2/