Y2 Elite workspaces are rolling out for teams
Y2Y2Docs
Ontology & Fusion

STIX 2.1 Export

How ledger subjects, designators, claims, and observations map to STIX 2.1 objects, and the Y2 ledger property extension

A STIX export projects one subject's fold at the requested cursors into an OASIS STIX 2.1 bundle. It is a projection: the ledger remains the store, and re-exporting the same fold yields the same object IDs.

The subject neighborhood is bounded. If it exceeds the read budget, the endpoint rejects the export; export the paginated ledger records and project the complete log offline instead.

Mapping

LedgerSTIX 2.1
person subjectidentity, identity_class: individual
organization subjectidentity, identity_class: organization
system subjectidentity, identity_class: system
Live preferred labelidentity.name. An unlabeled subject is named by its ledger ID.
Other published names and pseudonymsdesignated_names in the extension; no threat-actor is created to hold aliases
external-id designationsidentity.external_references (sec-edgar-cik, lei, wikidata, mitre-attack)
ticker designationsidentity.external_references with source_name: ticker and MIC:SYMBOL
emailemail-addr
handleuser-account with account_login and account_type from the namespace; no credential or login history
domain, hostnamedomain-name
urlurl
asnautonomous-system
designated-by to an observablerelationship of type designated-by
Other claimsrelationship with the predicate as its type, confidence, start_time, and stop_time
Unconfirmed same-asrelationship of type related-to, described as a hypothesis
followsrelationship of type follows between two user-account objects
Cited observationsexternal_references on the relationship: method as source_name, URL, excerpt as description, hashes.SHA-256
Retracted claimOmitted; with history=true, a relationship with revoked: true

duplicate-of and attributed-to are never emitted: identity is not confirmed by the ledger.

Extension

Every exported identity and relationship carries a property extension defined in the bundle:

{
  "type": "extension-definition",
  "spec_version": "2.1",
  "name": "Y2 passive entity ledger",
  "schema": "https://y2.dev/docs/ontology/reference/stix-export",
  "version": "0.1.0",
  "extension_types": ["property-extension"]
}
PropertyOnMeaning
ledger_subject_ididentityThe sbj_… ID
designated_namesidentityNames other than the label
ledger_claim_idrelationshipThe head line's clm_… ID
claim_keyrelationship`predicate
predicaterelationshipThe ledger predicate, even when the type is related-to
verificationrelationshipThe ladder state
qualifier, noterelationshipWhen present

A Y2 producer identity is the created_by_ref of the extension, identities, and relationships.

Identifiers and timestamps

STIX requires type--UUID identifiers. The UUID carries a SHA-256 digest, the same derivation Y2 uses for public IDs, laid out as an RFC 9562 name-based UUID (version 8):

ObjectDigest input
Cyber observablesThe type and the STIX ID-contributing properties, so equal observables share an ID across exports
IdentitiesThe type, a one-way per-workspace scope, and the ledger subject ID
RelationshipsThe type, the scope, and the claim key

The workspace ID is never exported. A relationship's created is the first line of its claim key; modified is the head line's record time. An identity's modified is the later of its opening and the record times of its designation and label claims, including retractions.

STIX revocation is permanent. Reasserting a retracted claim starts a new relationship ID and a new created time; later corrections keep that new ID. The extension retains the original claim key.

An explicit validAt cursor adds that snapshot time to the identity and relationship ID scope. STIX has one version clock, so different valid-time pictures cannot share an object version with different contents. The ledger subject ID in the extension still joins those snapshots. Bundle IDs digest the full exported content; repeating an unchanged projection yields the same bundle ID.