Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Observed data

Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.

Observed Data captures both a single observation of a single entity (file, network connection) as well as the aggregation of multiple observations of an entity.

You can use Observed Data by itself (without relationships) to convey raw data collected from any source. Sources include analyst reports, sandboxes, and network and host-based detection tools.

For example, Observed Data can capture information about an IP address, a network connection, a file, or a registry key. Observed Data is not an intelligence assertion, it is simply the raw information without any context for what it means.

  • Define observed data
    Define observed data that conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Threat actors

Threat groupings

Marking definitions

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Vulnerabilities

Relationships

STIX Visualizer