本文へ移動

Back to the overview

AV-2 Integrated Dictionary

Architecture data repository with definitions of all terms used throughout the architecture data and presentations.

Viewpoint: All Viewpoint · https://mithril.fund/ontology/dm2/2.02/views#AV-2

Mithril in this model

Kind DM2 class Count Why
Operator Organization 1 DM2 Organization: "A specific real-world assemblage of people and other resources organized for an on-going purpose." The named public operator of mithril.fund is one specific company, an individual — not a type.
Legal entity (twin) Organization 3 DM2 Organization (an individual). The enterprise twin's LegalEntity / OperatorOrg records are specific legal persons, each with its own jurisdiction.
Organization account Organization 0 DM2 Organization (an individual): each registered org is one did:webvh organization (com-<handle>.kotoba.cloud) with members.
Product vendor Organization 272 DM2 Organization (an individual): each product record names the company that provides it.
VC fund Organization 8 DM2 Organization (an individual): each fund record is one named firm with its own source URL.
Portfolio company Organization 6 DM2 Organization (an individual): each record is one named company.
Legal body Organization 37 DM2 Organization (an individual): courts, agencies, bar associations and prosecutors are specific bodies organized for an on-going purpose.
Threat actor group Organization 176 DM2 Organization (an individual): an ATT&CK intrusion set is reported as one specific group of people acting for an on-going purpose. The record is a reported association, not an attribution made here.
Historical ransomware group Organization 219 DM2 Organization (an individual): each Ransomwatch record names one group. The records are historical and unconfirmed, as the catalog labels them.
Organization type (account) OrganizationType 1 DM2 OrganizationType: "A type of Organization." Every Mithril organization account has the same shape (roles, did:webvh, membership VCs); that shape is the type, the registered orgs its members.
Organization type (catalog) OrganizationType 4 DM2 OrganizationType: the catalogs group organizations by kind (VC fund, portfolio company, intrusion set, historical group); each kind is a type of Organization.
Reference organization model OrganizationType 1 DM2 OrganizationType: orgbrain's ontology describes a kind of company (its roles, authorities, processes) that a customer's org is compared against — a type, not a particular company.
Organization role PersonRoleType 4 DM2 PersonRoleType: "A category of person roles defined by the role or roles they share that are relevant to an architecture." owner / admin / member / billing are categories of person roles; DM2 has no plain PersonRole class, and no individual person is published.
Job role (orgbrain) PersonRoleType 8 DM2 PersonRoleType: CEO, CFO, IT Admin … are categories of person roles in the reference model (with a minimum headcount), not individuals.
Business process Activity 6 DM2 Activity: "Work, not specific to a single organization, weapon system or individual that transforms inputs (Resources) into outputs (Resources) or changes their state." Each BPMN process is such work, defined for the reference organization.
Process task Activity 39 DM2 Activity: each BPMN task is a unit of work, part of its process.
RACI task Activity 15 DM2 Activity: each RACI task (annual budget, payroll run …) is recurring work with a responsible role.
Attack technique Activity 498 DM2 Activity: an ATT&CK technique is reported adversary work that changes the state of the systems it acts on; it is not specific to one group.
Authority Rule 6 DM2 Rule: "A principle or condition that governs behavior; a prescribed guide for conduct or action." An authority (approve-spend, sign-contract …) is the condition under which a task may be done.
Security service Service 8 DM2 Service: "A mechanism to enable access to a set of one or more capabilities, where the access is provided using a prescribed interface and is exercised consistent with constraints and policies as specified by the service description." Each of the eight services is offered through a documented interface with stated capabilities.
Service endpoint ServicePort 3 DM2 ServicePort: "A part of a Performer that specifics a interaction component through which the Performer interacts with other Performers." POST /v1/security/govern | respond | recover are those interaction points.
External service Service 2 DM2 Service: Stripe (billing) and Cloudflare (Workers, R2, Durable Objects, custom domains) are mechanisms giving Mithril access to capabilities through prescribed interfaces.
Capability Capability 31 DM2 Capability: "The ability to achieve a Desired Effect under specified [performance] standards and conditions through combinations of ways and means [activities and resources] to perform a set of activities." Each service lists the abilities it provides.
Mithril platform System 1 DM2 System: "A functionally, physically, and/or behaviorally related group of regularly interacting or interdependent elements." Mithril as a whole: the Workers, data stores and security products that serve mithril.fund.
Worker System 5 DM2 System: each Cloudflare Worker is a deployed group of interacting code, bindings and routes.
Data store System 4 DM2 System: an R2 bucket or a Durable Object class is a group of storage elements that a Worker regularly interacts with.
Security product System 10 DM2 System: each Mithril security product (EDR, SIEM, CMDB …) is a group of engines, rules and an API that work together.
Market product System 374 DM2 System: each catalogued commercial product (a scanner, an EDR suite …) is a system; the catalog records what it is, not how it performs.
Product category SystemType 45 DM2 SystemType: "The Powertype of System." A category such as edr-xdr is a set of systems; its members are the products filed under it.
Resident bot System 2 DM2 System: a Hermes profile is a model, tools, schedule and memory working together to act for the repository (support inbox, security watch).
Cloud agent System 0 DM2 System: a desktop agent backed up to /v1/agents is persona, memory and model working together. The records belong to their owners and are never published, so there are no public instances.
Runtime control Rule 2 DM2 Rule: "A principle or condition that governs behavior." A rate limit or the Biscuit root-key check governs what the edge admits.
Standard or framework Standard 7 DM2 Standard: "A formal agreement documenting generally accepted specifications or criteria for products, processes, procedures, policies, systems, and/or personnel." ISO/IEC 27001, SOC 2, PCI DSS, NIST CSF 2.0, CIS Controls, CSA CCM, ISO/IEC 27701.
Regulation Rule 9 DM2 Rule: a regulation (GDPR, HIPAA, DORA, APPI …) or a government authorization program (FedRAMP) is a prescribed guide for conduct issued by an authority, not a consensus standard.
CSF 2.0 subcategory Guidance 106 DM2 Guidance: "An authoritative statement intended to lead or steer the execution of actions." A CSF 2.0 subcategory is an outcome statement NIST publishes to steer practice; it is part of the CSF standard.
Legislation Rule 4 DM2 Rule: a statute or regulation (GDPR, NIS2, APPI, PDPA) is a prescribed guide for conduct.
Treaty Agreement 1 DM2 Agreement: "A consent among parties regarding the terms and conditions of activities that said parties participate in." The Budapest Convention is agreed among its parties.
Standard (legal corpus) Standard 1 DM2 Standard: the legal corpus files NIST CSF 2.0 as a framework — a formal, generally accepted specification.
Security specification Standard 1 DM2 Standard: SCAP is a published family of specifications for exchanging configuration and vulnerability information.
Legal corpus Information 9 DM2 Information: "the state of a something of interest that is materialized -- in any medium or form -- and communicated or received." A legislation portal or case-law database is a body of published information, not itself a rule.
Sanctions list Information 9 DM2 Information: each list is a published body of designations (a CSV, XML or web page). The prohibition it carries is the issuing authority's regulation, which the catalog does not record — so the list is Information, not Rule. Aggregators (OpenSanctions) publish lists too.
Audit log Data 1 DM2 Data: "Representation of information in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means." A lab audit log is machine-readable records.
Threat model Information 1 DM2 Information: an authored threat-model scenario template is information about a situation; the catalog marks it as not evidence of an attack.
Published dataset Data 8 DM2 Data: each catalog Mithril publishes (JSON blocks, JSON-LD, datoms) is information formalized for processing by automatic means.
Pedigree PedigreeInformation 8 DM2 PedigreeInformation: "Information describing pedigree." Each dataset's provenance — the source URLs, evidence layers, fetch dates, upstream commits and file hashes it records, and prov:wasDerivedFrom on every security-data claim — is its pedigree.
Architectural description ArchitecturalDescription 53 DM2 ArchitecturalDescription: "Information describing an architecture such as an OV-5 Activity Model document." Each page of this architecture surface, and the JSON-LD, describes Mithril's architecture.
DoDAF model ArchitecturalDescriptionType 52 DM2 ArchitecturalDescriptionType: "The Powertype of ArchitecturalDescription." Each of the 52 official models (AV-1 … DIV-3) is a kind of architectural description; the page for it is an instance.
Country Country 5 DM2 Country: "A political state or nation or its territory."
Geopolitical extent GeoPoliticalExtent 2 DM2 GeoPoliticalExtent: "A geospatial extent whose boundaries are by declaration or agreement by political parties." The EU and the EEA are extents by agreement, not countries.
Logical location Location 1 DM2 Location: "A point or extent in space that may be referred to physically or logically." The Cloudflare global edge, the twin's worker jurisdiction, is logical, not geopolitical.

5 more kinds map to DM2 classes this model does not list; the full dictionary is on the overview. Integrated dictionary — the site mapping

Concepts with Mithril instances

Concept Code Count Examples
Activity o 558
  • 契約審査ライフサイクル
  • インシデントエスカレーションライフサイクル
  • 法人設立・組織変更
  • 請求・支払ライフサイクル
  • アクセス権プロビジョニングライフサイクル
  • 入退社ライフサイクル
  • 契約書ドラフト作成
  • 法務・条項審査
  • 財務条件審査
  • CEO 契約承認
  • 契約締結
  • 契約書保管
  • and 546 more (all in the JSON-LD)
Agreement o 1
  • Budapest Convention on Cybercrime (ETS 185)
ArchitecturalDescription o 53
  • Mithril architecture — DoDAF 2.02 (overview)
  • AV-1 Overview and Summary Information — Mithril
  • AV-2 Integrated Dictionary — Mithril
  • OV-1: High Level Operational Concept Graphic — Mithril
  • OV-2: Operational Connectivity Description — Mithril
  • OV-3: Operational Resource Flow Matrix — Mithril
  • OV-4: Organizational Relationships Chart — Mithril
  • OV-5a: Activity Decomposition Tree — Mithril
  • OV-5b: Activity Model — Mithril
  • OV-6a: Operational Rules Model — Mithril
  • OV-6b: State Transition Description — Mithril
  • OV-6c: Event-Trace Description — Mithril
  • and 41 more (all in the JSON-LD)
ArchitecturalDescriptionType o 52
  • AV-1 Overview and Summary Information
  • AV-2 Integrated Dictionary
  • OV-1: High Level Operational Concept Graphic
  • OV-2: Operational Connectivity Description
  • OV-3: Operational Resource Flow Matrix
  • OV-4: Organizational Relationships Chart
  • OV-5a: Activity Decomposition Tree
  • OV-5b: Activity Model
  • OV-6a: Operational Rules Model
  • OV-6b: State Transition Description
  • OV-6c: Event-Trace Description
  • SV-1 Systems Interface Description
  • and 40 more (all in the JSON-LD)
Capability o 31
  • continuous external attack-surface and asset inventory
  • reachable attack-path identification
  • asset context (public routes, dependencies, owner)
  • exposure events fed to the VM ledger
  • dynamic probing of running applications
  • probing with authenticated scenarios
  • runtime vulnerability detection as findings
  • static source-code analysis
  • taint / data-flow inspection
  • code findings with file and line
  • dependency-manifest inspection, emitting dependency notes
  • header verification on received mail (SPF / DKIM / DMARC alignment)
  • and 19 more (all in the JSON-LD)
Country o 5
  • Australia
  • Japan
  • Ukraine
  • United Kingdom
  • United States
Data o 9
  • Arp Cache Discovery — 公開ラボ監査ログ
  • VC fund catalog
  • Compliance standards catalog
  • Sanctions watchlist catalog
  • Legal data catalog
  • Public security knowledge
  • Enterprise digital twin
  • orgbrain reference organization
  • NIST CSF 2.0 catalog
GeoPoliticalExtent df 2
  • European Economic Area
  • European Union
Guidance df 106
  • DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • DE.AE-03 — Information is correlated from multiple sources
  • DE.AE-04 — The estimated impact and scope of adverse events are understood
  • DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis
  • DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • DE.CM-02 — The physical environment is monitored to find potentially adverse events
  • DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • DE.CM-06 — External service provider activities and services are monitored to find potentially adverse events
  • DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • GV.OC-01 — The organizational mission is understood and informs cybersecurity risk management
  • and 94 more (all in the JSON-LD)
Information dfo 19
  • EUR-Lex — EU 官報・連合法源ポータル
  • CourtListener / RECAP — US 連邦裁判例・ドocket コーパス
  • CanLII — カナダ判例・法源コーパス
  • AustLII — オーストラリア法情報研究所 (判例・法源コーパス)
  • Canada Justice Laws Website (カナダ連邦法令ポータル)
  • NZLII — ニュージーランド法情報研究所 (判例・法源コーパス)
  • Singapore Statutes Online — シンガポール法令公式ポータル (AGC Legislation Division 運営)
  • HUDOC — 欧州人権裁判所 (ECtHR) 判例データベース
  • Singapore Law Watch — 判例・法務ポータル (Singapore Academy of Law 運営)
  • US Treasury OFAC SDN List
  • UN Security Council Consolidated List
  • EU Financial Sanctions Database
  • and 7 more (all in the JSON-LD)
Location dfo 1
  • Cloudflare global edge
Organization o 722
  • Kotoba Labs Inc.
  • cloud-kotoba (kotoba.cloud operator)
  • AWAI Network, L.L.C. (Delaware)
  • kotoba-lang (language substrate)
  • 1Password (AgileBits)
  • 42Crunch
  • ANY.RUN
  • AT&T Cybersecurity
  • AWS
  • Abnormal Security
  • Acronis
  • Akamai
  • and 710 more (all in the JSON-LD)
OrganizationType o 6
  • Mithril organization account
  • VC fund
  • Portfolio company
  • ATT&CK intrusion set
  • Historical ransomware group (Ransomwatch)
  • orgbrain reference organization
PedigreeInformation dfo 8
  • Pedigree of VC fund catalog — 8 funds each with source-url (8 primary-fetched); 6 companies with sourced rounds
  • Pedigree of Compliance standards catalog — 16 of 16 frameworks with source-url
  • Pedigree of Sanctions watchlist catalog — 9 source lists with issuing authority and URL (6 declared-2026-03, 3 primary-fetched)
  • Pedigree of Legal data catalog — 52 records each with source-url (37 primary-fetched, 15 secondary-reported)
  • Pedigree of Public security knowledge — every claim carries prov:wasDerivedFrom one of 7 archived sources (CISA, MITRE, NIST, OTRF, OTRF, joshhighet/ransomwatch, Kotoba); snapshot baguqeera6fji5y3mgsvalio2cz7ca6kxlhojidwtsuqwx6klgf3wycr2gpca, 2026-09-13T23:53:34.337Z
  • Pedigree of Enterprise digital twin — every instance cites an in-repo source (2026-09-18T00:00:00+09:00)
  • Pedigree of orgbrain reference organization — kotoba-lang/kyber@055c94b00d71, 7 files pinned by sha256
  • Pedigree of NIST CSF 2.0 catalog — 106 subcategories from NIST CSWP 29 (2024-02-26, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)
PersonRoleType o 12
  • owner
  • admin
  • member
  • billing
  • CEO
  • CFO
  • COO
  • CTO
  • HR Manager
  • Finance Staff
  • IT Admin
  • board
Rule dfo 21
  • approve-spend
  • sign-contract
  • hire
  • fire
  • compliance
  • it-admin
  • SUPPORT_RATE_LIMIT 10/min per client address (503 by name on miss)
  • POST /v1/invoke verifies Biscuits against pinned root public key; absent key refuses every invocation by name
  • GDPR (EU 2016/679)
  • CCPA / CPRA (Cal. Civ. Code 1798)
  • FedRAMP (NIST SP 800-53 Rev.5 baseline)
  • HIPAA Security Rule (45 CFR 164 Subpart C)
  • and 9 more (all in the JSON-LD)
Service o 10
  • CTEM
  • DAST
  • SAST
  • SPECT
  • VM
  • GRC
  • IR
  • DR
  • Stripe (live billing, AWAI account)
  • Cloudflare Workers / R2 / DO / custom domains
ServicePort o 3
  • POST /v1/security/govern
  • POST /v1/security/respond
  • POST /v1/security/recover
Standard df 9
  • ISO/IEC 27001:2022
  • SOC 2 (Type I / Type II)
  • PCI DSS 4.0
  • NIST Cybersecurity Framework 2.0
  • CIS Controls v8.1
  • ISO/IEC 27701:2019 (privacy extension)
  • CSA Cloud Controls Matrix v4
  • NIST Cybersecurity Framework 2.0
  • SCAP — 構成・脆弱性情報を交換する仕様群
System o 396
  • Mithril (mithril.fund)
  • kotoba-cloud-control-plane
  • kotoba-identity-authority
  • kotoba-research-authority
  • kotoba-cloud-database
  • kotobase-authn
  • R2 kotobase-graph-database-production (PUBLIC_BLOCKS)
  • R2 internal-security-nvd (NVD_BLOCKS, read-only allow-listed keys)
  • Durable Object PqKeyRegistry (SQLite, post-quantum key registry)
  • Durable Object BillingAccount (SQLite)
  • EDR / XDR
  • CMDB / 資産台帳
  • and 384 more (all in the JSON-LD)
SystemType o 45
  • Vulnerability Assessment / VM
  • Attack Surface Management / EASM
  • Patch Management
  • Penetration Testing / PTaaS
  • Bug Bounty / Crowdsourced Testing
  • EDR / XDR
  • NDR / Network Detection
  • SIEM / Log Analytics
  • SOAR / Orchestration
  • Threat Intelligence
  • SBOM / VEX
  • AppSec (SAST/DAST/SCA)
  • and 33 more (all in the JSON-LD)

Relations

Concept Code Count Examples
WholePartType ifo 164
  • 契約審査ライフサイクル → 契約書ドラフト作成
  • 契約審査ライフサイクル → 法務・条項審査
  • 契約審査ライフサイクル → 財務条件審査
  • 契約審査ライフサイクル → CEO 契約承認
  • 契約審査ライフサイクル → 契約締結
  • 契約審査ライフサイクル → 契約書保管
  • インシデントエスカレーションライフサイクル → インシデント検知・トリアージ
  • インシデントエスカレーションライフサイクル → 指揮本部設立・指揮官任命
  • and 156 more (all in the JSON-LD)
couple if 657
  • CTEM → VM (site:feedsFindingsTo)
  • DAST → VM (site:feedsFindingsTo)
  • SAST → VM (site:feedsFindingsTo)
  • SPECT → VM (site:feedsFindingsTo)
  • IR → DR (site:handsOffTo)
  • CTEM → Threat Intelligence (site:coversCategory)
  • CTEM → CSPM / CNAPP (site:coversCategory)
  • CTEM → Vulnerability Assessment / VM (site:coversCategory)
  • and 649 more (all in the JSON-LD)
describedBy dfo 69
  • CTEM → CTEM — /security/services/
  • DAST → DAST — /security/services/
  • SAST → SAST — /security/services/
  • SPECT → SPECT — /security/services/
  • VM → VM — /security/services/
  • GRC → GRC — /security/services/
  • IR → IR — /security/services/
  • DR → DR — /security/services/
  • and 61 more (all in the JSON-LD)
individualResourceInLocation o 3
  • Japan → cloud-kotoba (kotoba.cloud operator)
  • Delaware → AWAI Network, L.L.C. (Delaware)
  • Japan → kotoba-lang (language substrate)
servicePortDescribedBy o 3
  • POST /v1/security/govern → GRC — /security/services/
  • POST /v1/security/respond → IR — /security/services/
  • POST /v1/security/recover → DR — /security/services/
typeInstance ifo 891
  • exposure management → continuous external attack-surface and asset inventory
  • exposure management → reachable attack-path identification
  • exposure management → asset context (public routes, dependencies, owner)
  • exposure management → exposure events fed to the VM ledger
  • dynamic testing → dynamic probing of running applications
  • dynamic testing → probing with authenticated scenarios
  • dynamic testing → runtime vulnerability detection as findings
  • static analysis → static source-code analysis
  • and 883 more (all in the JSON-LD)
Concepts without Mithril instances (136)

The model concept codes (o, n, np, s, df, dfo, if, ifo) are shown verbatim: the DoD workbook publishes no legend for them, and none is assigned here.