TENSOR Framework

TENSOR and Existing Standards

Reuse, then prove the relationship

An investigative layer alongside existing standards

TENSOR makes questions, evidence, uncertainty, and decisions portable across an investigation. Existing standards already describe adversary behavior, defensive knowledge, evidence, events, and operational workflows. Core should connect that work with explicit, tested mappings.

The relationships below are design boundaries. They do not establish implemented adapters, partnership, endorsement, or external conformance.

Existing workRelationship to investigate
MITRE ATT&CKReference adversary behavior that motivates a question; a technique label alone does not answer it.
MITRE D3FENDReference defensive techniques and artifact concepts; record observed control behavior separately.
MITRE ATLASSupply AI threat context while keeping the same Core for AI and conventional investigations.
CASE / UCOEvaluate reuse of evidence, identity, actions, provenance, and hypothesis concepts. The overlap is substantial.
STIX 2.1Preserve native threat intelligence and observable identities, versions, and markings.
Attack FlowKeep a suspected adversary sequence distinct from the investigator's question and decision sequence.
CACAO 2.0Bind collection and response procedures while preserving the reason for an investigative decision.
OCSFReference normalized events and transformation provenance without implying evidence completeness.

A provisional binding, an open reuse decision

The candidate JSON binding makes the Core proposal executable for review. It is not a CASE/UCO adapter. Whether stable TENSOR should use a CASE profile, extension, or separately bound model remains subject to the two reference cases and independent review.

Read the source-backed standards crosswalk for scope, references, and mapping acceptance requirements.

Version identity carries meaning

New Core definitions use a logical identity, an artifact version, and an exact-byte digest. A changed proposition, criterion, or transition meaning needs a new concept identity. A display correction still produces a new artifact version. Historical releases stay retrievable.

Candidate versions may change during review. There is no stable compatibility guarantee yet. The legacy graph release channel keeps its existing identifiers and artifacts; the new candidate does not silently reinterpret them.

What a mapping must show

  • Pinned source and target versions, object identities, and a versioned mapping.
  • Direction, cardinality, assumptions, transformations, and unmapped meaning.
  • Handling of uncertainty, evidence, confidence, identity, time, revisions, and markings.
  • Positive, negative, and lossy fixtures with explicit exchange results.

Inspect Core · Review validation scope · Propose a mapping