Built on STONEWORK
The ontology is not the product
Everything we publish about STONES and STONEWORK — the class hierarchies, the property definitions, the vocabularies, the documentation — is free, MIT-licensed, and stays that way. Nothing on this page changes that. STONEWORK will keep being maintained and released as open ontology work regardless of what does or doesn’t get built commercially on top of it.
What follows is a look at two systems being built on STONEWORK: CTI Encyclopedia and MOAI. We’re building them to fund the continued work on STONEWORK itself — but we want to be upfront that they exist, why they exist, and that using STONEWORK never requires using either of them.
Why put this here
STONEWORK is a domain ontology. On its own, it’s a specification — a formal way of representing cyber threat intelligence. It becomes useful once something is actually built with it: data loaded, queried, reasoned over, put in front of an analyst. CTI Encyclopedia and MOAI are our own proof that STONEWORK holds up at that scale — reference implementations of the ontology doing real work, not just a diagram in documentation.
Explore STONEWORK’s interactive class diagram →
CTI Encyclopedia — a STONEWORK-governed knowledge graph
CTI Encyclopedia is a large-scale graph knowledgebase, structured entirely under STONEWORK: CVE, CPE, ATT&CK, CAPEC, CWE, NIST SP 800-53, and CIS Controls, aligned into a single connected semantic layer, exactly as STONEWORK’s ontology defines it.
It exists to answer a question STONEWORK alone can’t: does this ontology actually hold together at the scale and messiness of real-world threat intelligence data? CTI Encyclopedia is the answer — tens of millions of triples, kept current with near-real-time incremental updates from upstream sources.
Status: in development, not yet publicly released. Get notified at launch →
MOAI — an analyst platform on top of a STONEWORK graph
MOAI is a threat intelligence analysis platform — the application layer on top of a STONEWORK-governed graph. Where CTI Encyclopedia is curated reference data, MOAI is built for an analyst’s own environment: their own inventory, their own findings, their own annotations, layered onto the same ontology and, optionally, federated against CTI Encyclopedia’s reference data.
Status: in development, not yet publicly released. Get notified at launch →
Using STONEWORK without either of these
You don’t need CTI Encyclopedia or MOAI to use STONEWORK. The ontology files, documentation, and source are all available on the Downloads and Ontology pages, same as always. If you’re building your own graph, your own tooling, your own anything — that’s exactly what STONEWORK is for, whether or not it involves us.
Stay Updated
Whether you’re using STONES and STONEWORK in your own work or waiting on MOAI and CTI Encyclopedia, leave your email below and tell us what you’d like to hear about.