Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Marking definitions

The marking definitions object represents a specific marking.

Data markings represent restrictions, permissions, and other guidance for how data can be used and shared.

For example, data may be shared with the restriction that it must not be reshared, or that it must be encrypted at rest.

In STIX, data markings are specified using the marking definition object. These definitions are applied to STIX Objects using object markings and to individual properties of STIX Objects via granular markings.

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Threat groupings

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Vulnerabilities

Relationships

STIX Visualizer