Guide

STIX 2.1 for Scam Indicator Feeds

Plan a CTI-focused article on turning scam chats into a STIX 2.1 feed with scored indicators, actor linking, and customer-specific exports.

Published 2026-10-05

Many scam indicators reach CTI teams too late, end up scattered across analyst notes, or stay trapped in screenshots and chat exports instead of landing in a format a CTI platform can ingest. This article looks at the narrower workflow question analysts care about: how scam conversations become a structured indicator feed that fits existing processes and can be exported in STIX 2.1. Active Defense runs AI decoy personas that keep scammers talking on Telegram and by e-mail and turns what they send into a threat-intelligence feed. The focus here is practical CTI use: collection, scoring, actor linking, and feed delivery, not general scam-awareness advice.

Why scam conversations matter to CTI teams

Scam operations tend to expose useful artifacts while they are actively pushing a target toward payment or account takeover. In practice, the conversation itself becomes a collection point: the scammer shares where money should go, which account to contact, which link to open, or which file to trust. For CTI teams, that makes live scam chats a source of operational data rather than just narrative evidence.

From those messages, Active Defense extracts indicators such as:

  • crypto wallets
  • bank details
  • phone numbers
  • messenger accounts
  • links
  • gift cards
  • payment handles
  • file and photo hashes

These are the same kinds of entities analysts routinely pivot on inside CTI platforms when they want to spot overlap, cluster related activity, and identify repeat use across campaigns. A reused wallet, a familiar photo hash, or the same messenger handle appearing in separate conversations can help turn isolated scam reports into connected observations. Readers interested in one of those high-signal artifacts can read more about what scammers’ crypto wallets can reveal.

Just as important, this feed is built from what scammers hand over in conversation, not from intrusive collection methods. Active Defense never hacks back. If you want to compare scam-derived feeds against a broader checklist, see what should be included in a threat-intelligence feed. For examples of recurring patterns from live conversations, the weekly scam briefings and monthly scam data reports are useful context, especially when evaluating how this data fits your CTI software workflow.

From live chat to structured indicators

The collection step starts inside the conversation itself. Active Defense uses AI decoy personas on Telegram and by e-mail to keep scammers engaged long enough to reveal the operational details analysts care about: payment routes, contact points, and the files or media used to support the scam. Instead of treating the chat as unstructured evidence to review later, the system treats each inbound message as source material for extraction.

Control over the engagement matters here. Replies are drafted by AI and approved by a human operator by default before anything is sent. For CTI teams evaluating source quality, that human-in-the-loop step helps explain how the exchange is managed. Outbound replies are sent with typing pauses and in short messages, which helps the conversation continue in a natural back-and-forth format.

Just as important, every message is stored the moment it arrives. That preserves the original inbound content for later processing, review, and export. Operationally, this matters because chat platforms are not a reliable evidence store: if a scammer later uses “delete for everyone,” the stored copy is still available for analysis.

Attachments are preserved in a way that supports later pivots:

  • files and voice messages are kept by SHA-256
  • photos are kept by SHA-256 plus a perceptual hash

That combination is useful in CTI work because it supports both exact matching and near-match comparison for reused images.

Taken together, this is the handoff point between messy conversational data and an analyst-ready stream of entities. The chat remains available as source history, while the messages, files, and media can be processed into structured indicators that fit downstream CTI workflows.

How indicators are scored and linked to actors

Once messages are collected, the next CTI question is how the extracted entities should be handled downstream. Active Defense extracts indicators from every message and assigns each one a confidence score. In this article, those indicators are scored, not verified.

That score combines two inputs: a structural check and an LLM. In practical terms, the structural side asks whether a value looks like the indicator type it is claimed to be. Examples include whether a string matches the expected format of an IBAN, wallet address, phone number, e-mail address, or URL. That does not make the value true or safe to act on by itself, but it does give analysts a clearer basis for handling it inside a CTI workflow.

Confidence scoring matters because scam conversations are messy. A chat may contain partial values, broken formatting, pasted text, or deliberate noise. When the feed carries a score with the extracted entity, analysts can use that signal to:

  • triage what to review first
  • filter lower-confidence items
  • set ingestion rules in the CTI platform
  • separate stronger pivots from weaker ones

This is especially useful when teams want different handling for different indicator classes. A wallet that strongly matches the expected format may be processed differently from a loosely captured payment handle or an incomplete bank detail.

The second step is linking related chats to one actor. Active Defense links chats when they share an indicator, a reused photo, or a forwarded account. For CTI teams, that linkage helps reduce fragmentation. Instead of treating each scam conversation as an isolated record, analysts can start to see repeated contact points, reused payment routes, and recurring supporting media as part of one operator or group.

That makes the feed more useful for correlation and clustering. It also gives analysts a better starting point for case building, because separate encounters that look unrelated at first can be grouped into a more coherent actor view. For a closer look at one high-value indicator class, the crypto wallet guide is useful context.

What STIX 2.1 delivery changes for your workflow

Each customer gets their own feed with STIX 2.1 export. For CTI teams, that changes the handoff point. Scam-derived indicators do not have to stay in a separate review process or live only inside chat evidence. They can move into the same environment where analysts already do enrichment, correlation, casework, and downstream distribution.

That matters because most teams do not want one generic feed handled the same way by everyone. A customer-specific feed lets each organization apply its own logic inside the CTI platform, including:

  • ingestion rules
  • retention choices
  • prioritization by indicator type or score
  • routing into existing analyst workflows

The practical benefit is less about format for its own sake and more about reducing translation work. Analysts and engineers can take scam indicators into the systems they already use instead of rebuilding context from screenshots, notes, or exported chats.

Another important point is that the feed is rebuildable from the stored history. If a team wants to revisit parsing decisions, regenerate an export, or inspect how a record was produced, the output can be reconstructed from preserved source events.

That rebuildability follows from the underlying event-sourced storage model. The foundation is the stored message history captured when messages arrive, not a transient chat view that may later change or disappear. For CTI operations, that gives a more stable basis for reproducing indicator records and checking how source conversations became feed output.

For teams comparing feed handling against their broader tooling needs, this is where delivery format and source preservation meet.

Operational considerations for evaluation and rollout

For teams planning a trial or rollout, one deployment fact is straightforward: the console and API run on Azure in Germany. For buyers assessing where the service operates, that is part of the evaluation baseline alongside feed format and source handling.

It is also worth avoiding a narrow comparison based only on how many indicators appear in the feed. A better evaluation looks at whether the feed is useful once it reaches the CTI platform. In practice, that means checking:

  • indicator coverage across the scam artifacts your team tracks
  • how confidence scoring supports filtering and triage
  • whether actor linking helps reduce duplicate or fragmented cases
  • how easily the feed imports into existing CTI workflows

Active Defense offers a free feed sample for qualified leads and a 90-day pilot for up to 1,000 sessions at a fixed price. The home page is the place to request either option.

Readers who want more context before testing import and workflow fit can also browse the briefings and reports. They show how live scam conversations turn into recurring observations that analysts can compare over time.

Common questions about STIX 2.1 scam indicator feeds

What kinds of scam indicators can be exported in the STIX 2.1 feed?

The feed covers the scam artifacts Active Defense extracts from conversations and attachments. That includes crypto wallets, bank details, phone numbers, messenger accounts, links, gift cards, payment handles, and file and photo hashes. In practice, this gives CTI teams a mix of payment, contact, delivery, and media reuse indicators that can be handled inside existing platform logic.

How does Active Defense decide whether an extracted wallet, phone number, or account should be trusted enough to include?

Each extracted indicator is scored with a confidence score rather than treated as verified. That score is based on two inputs: a structural check and an LLM. The structural side checks whether the value matches the expected form of the claimed indicator type. For analysts, that means the feed can carry weaker and stronger candidates with a signal that supports filtering, review thresholds, or different ingestion rules by type.

Can deleted Telegram messages still contribute to the feed if the scammer removes them later?

Yes. Every message is stored the moment it arrives. If a scammer later uses Telegram’s delete function, the stored copy remains available for processing and export. That matters when a message contains payment details, account handles, or media that would otherwise disappear from the analyst view.

How are separate scam chats linked to the same actor?

Chats are linked to one actor when they share an indicator, a reused photo, or a forwarded account. This helps reduce fragmentation in the feed. Instead of treating each conversation as a separate event with no relationship to the next, analysts can work from a more connected view of repeated infrastructure and reused assets.

What is the best way to evaluate a new scam indicator feed before full production ingestion?

Start by checking four things:

  • coverage across the indicator types your team uses
  • whether confidence scores support triage and filtering
  • whether actor linking improves clustering and case handling
  • how cleanly the STIX 2.1 export imports into your CTI platform

A sample feed or a limited pilot is a practical way to test those points before wider rollout.

A practical path from scam chats to CTI

For CTI teams, the practical point is simple: Active Defense turns scam conversations on Telegram and by e-mail into a customer-specific threat-intelligence feed. That feed combines scored indicators, actor linking, and STIX 2.1 export so scam-derived data can fit existing analysis workflows.

To test fit before broader use, teams can request a sample feed or start with the 90-day pilot.

Get these indicators as a feed

Active Defense keeps scammers talking with AI decoys and turns what they hand over into a feed of scored indicators with STIX 2.1 export.