STIX 2.1 Export
How ledger subjects, designators, claims, and observations map to STIX 2.1 objects, and the Y2 ledger property extension
A STIX export projects one subject's fold at the requested cursors into an OASIS STIX 2.1 bundle. It is a projection: the ledger remains the store, and re-exporting the same fold yields the same object IDs.
The subject neighborhood is bounded. If it exceeds the read budget, the endpoint rejects the export; export the paginated ledger records and project the complete log offline instead.
Mapping
| Ledger | STIX 2.1 |
|---|---|
person subject | identity, identity_class: individual |
organization subject | identity, identity_class: organization |
system subject | identity, identity_class: system |
| Live preferred label | identity.name. An unlabeled subject is named by its ledger ID. |
| Other published names and pseudonyms | designated_names in the extension; no threat-actor is created to hold aliases |
external-id designations | identity.external_references (sec-edgar-cik, lei, wikidata, mitre-attack) |
ticker designations | identity.external_references with source_name: ticker and MIC:SYMBOL |
email | email-addr |
handle | user-account with account_login and account_type from the namespace; no credential or login history |
domain, hostname | domain-name |
url | url |
asn | autonomous-system |
designated-by to an observable | relationship of type designated-by |
| Other claims | relationship with the predicate as its type, confidence, start_time, and stop_time |
Unconfirmed same-as | relationship of type related-to, described as a hypothesis |
follows | relationship of type follows between two user-account objects |
| Cited observations | external_references on the relationship: method as source_name, URL, excerpt as description, hashes.SHA-256 |
| Retracted claim | Omitted; with history=true, a relationship with revoked: true |
duplicate-of and attributed-to are never emitted: identity is not confirmed by the ledger.
Extension
Every exported identity and relationship carries a property extension defined in the bundle:
{
"type": "extension-definition",
"spec_version": "2.1",
"name": "Y2 passive entity ledger",
"schema": "https://y2.dev/docs/ontology/reference/stix-export",
"version": "0.1.0",
"extension_types": ["property-extension"]
}| Property | On | Meaning |
|---|---|---|
ledger_subject_id | identity | The sbj_… ID |
designated_names | identity | Names other than the label |
ledger_claim_id | relationship | The head line's clm_… ID |
claim_key | relationship | `predicate |
predicate | relationship | The ledger predicate, even when the type is related-to |
verification | relationship | The ladder state |
qualifier, note | relationship | When present |
A Y2 producer identity is the created_by_ref of the extension, identities, and relationships.
Identifiers and timestamps
STIX requires type--UUID identifiers. The UUID carries a SHA-256 digest, the same derivation Y2
uses for public IDs, laid out as an RFC 9562 name-based UUID (version 8):
| Object | Digest input |
|---|---|
| Cyber observables | The type and the STIX ID-contributing properties, so equal observables share an ID across exports |
| Identities | The type, a one-way per-workspace scope, and the ledger subject ID |
| Relationships | The type, the scope, and the claim key |
The workspace ID is never exported. A relationship's created is the first line of its claim key;
modified is the head line's record time. An identity's modified is the later of its opening and
the record times of its designation and label claims, including retractions.
STIX revocation is permanent. Reasserting a retracted claim starts a new relationship ID and a new
created time; later corrections keep that new ID. The extension retains the original claim key.
An explicit validAt cursor adds that snapshot time to the identity and relationship ID scope.
STIX has one version clock, so different valid-time pictures cannot share an object version with
different contents. The ledger subject ID in the extension still joins those snapshots. Bundle IDs
digest the full exported content; repeating an unchanged projection yields the same bundle ID.