Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Relationships

Use the relationship objects to link together two SDOs or STIX Cyber-observable Objects (SCOs) to describe how they relate to each other.

STIX Relationship Objects (SROs) represent types of relationships between various STIX objects. The following relationship objects are available:

  • Object-Object Relationship: This object defines relationships between SDOs, except the indicator object. An example of an object-object defined relationship is that an attack pattern delivers a malware.
  • Object-Indicator Relationship: This object defines relationships between the indicator object and other SDOs. An example of an object-indicator defined relationship is that an indicator detects evidence of a campaign.
  • Object-Observable Relationship: This object defines relationships between SDOs and the observable object (SCO). An example of an object-observable defined relationship is that an infrastructure consists of cyber observable objects which provides information of a potential attack.
Relationship ObjectExample SourceExample TargetExample Description
Object-Object RelationshipsAttack-patternMalwareThis relationship describes that this Attack Pattern is used to deliver this malware instance \(or family\).
Object-Indicator RelationshipsIndicatorAttack-Pattern, Campaign, Infrastructure, Intrusion-set, Malware, Threat-actor, ToolThis relationship describes that the indicator can detect evidence of the related attack pattern, campaign, infrastructure, intrusion set, malware, threat actor, or tool.The evidence may not be direct. For example, the indicator may detect secondary evidence of the campaign such as malware that is commonly used by that particular campaign.
Object-Observable RelationshipsInfrastructureObserved dataThis relationship describes that the indicator is created based on information from an observed data object.An example of an object-observable defined relationship is that an infrastructure consists of cyber observable objects which provides information of a potential attack.

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Threat groupings

Marking definitions

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Vulnerabilities

STIX Visualizer