About

About Cyber Terrain Ontology Organization

The Cyber Terrain Ontology Organization and this website (cyberterrain.org) are focused on the formal representation of threat intelligence knowledge. Hohimer Intelligence Strategies LLC stewards the organization, developing open ontologies and semantic web tools that bring rigor and interoperability to the cyber threat intelligence community.

Why We Started

STIX 2.1 is the OASIS standard the cybersecurity industry uses to exchange threat intelligence — indicators, threat actors, malware, campaigns, and the relationships between them. It’s rich, well-designed, and widely adopted.

But it ships as a JSON schema. The STIX 2.1 specification describes a genuine object model — classes, relationships, controlled vocabularies — but only in prose. A JSON schema can validate that a document is shaped correctly; it can’t enforce that a Malware object really is a kind of a broader concept, or reason about what follows from an Intrusion Set using an Attack Pattern. That model lives in the heads of the people who wrote the spec, not in a form a machine — or another ontology — can consume.

STONES is our answer: a faithful OWL 2 binding of STIX 2.1. Every STIX Domain Object, Cyber Observable Object, Relationship Object, and vocabulary term becomes a first-class citizen in a formal class hierarchy — not reinterpreted, not extended, just made explicit. STIX 2.1 was already an ontological model. STONES simply gives it the ontology it always implied.

Beyond STIX

Formalizing STIX solves one problem, but it isn’t the whole problem. Real cybersecurity analysis draws on far more than threat intelligence exchange: adversary tactics and techniques, software weaknesses, security controls, affected products, risk and likelihood. No single existing model — STIX included — was built to cover that full domain of discourse.

STONEWORK is our open-source expansion of STONES built to close that gap. It extends the STONES foundation with the classes and relationships needed to align ATT&CK, CAPEC, CWE, CVE, CPE, NIST, and CIS Controls into one connected semantic layer — built with the explicit goal of sufficient coverage of the cybersecurity domain, not just STIX’s slice of it.

Open, By Design

Both STONES and STONEWORK are MIT-licensed and developed in the open. We build them this way because a community that depends on shared, interoperable ground truth is not well served by proprietary, closed ontologies that lock it into a single vendor’s model of the domain. Hohimer Intelligence Strategies LLC stewards both as free, open resources for the cyber threat intelligence community.

Want to hear about new STONES and STONEWORK releases? Sign up for updates.