Questions
- Is this a replacement for ATT&CK?
No. The calculus is framework-neutral and aligns by mapping, never by import or subclassing — ATT&CK IDs stay on the technique, objectives map to tactics, and the calculus works at the procedure level below them. Nothing in the model depends on any framework's tree surviving its next revision. The same holds for D3FEND, Summiting the Pyramid (whose L1–L5 robustness scale it adopts directly), DFIQ and MBC. See Alignment.
- Is this a tool or a specification?
A specification first. MC-SPEC is the normative text and everything else projects from it: the mc-core ontology is a conformance projection into OWL-RL / SHACL / SPARQL, and the tooling (a Threat Research Workbench) is built against that. There is no package to install today.
- What is the status and the version?
MC-SPEC 0.4.20 — 141 clauses. Machine ontology mc-core 0.4.20.2 — 459 terms, 24 derivation rules, self-verifying (acceptance 20/20, ablation 3/3, a 47-vector regression family, SHACL conforming), independently retested at 170 pass / 0 fail, twice. Both are working drafts: conformance language binds once the specification ships, and an amendment batch is queued for the next spec version. The site's pages have been aligned to 0.4.20 vocabulary (e.g. detectability became detection face); the formal specification text and the ontology deposit are prepared but not yet hosted here.
- Can I use it today?
You can read it, argue with it, and model against it by hand — the framework, results and alignment pages state the commitments the calculus makes. The specification text, the ontology deposit and the worked-example corpus are not yet public. The corpus is deliberately empty and being seeded; it is the part most in need of outside work.
- How do I cite it?
Cite the concept DOI 10.5281/zenodo.21313285 together with the version you read — e.g. "MC-SPEC 0.4.20" — since clause numbers move between versions. Cite the ontology by its full serial (mc-core 0.4.20.2); deposits are immutable, so a serial is a stable reference. A versioned DOI for the 0.4.20.2 deposit is pending.
- How do I contribute?
Confusion reports first — if a page didn't land, say which sentence lost you; that is a contribution here, because it shows where the guidance is thin. Beyond that: threat analyses mapped into maneuver records are the work that most needs doing. Changes to the ontology go through an authorship gate — quoted clause text, a balloted decision on any underdetermined choice, a signed diff — so start with a conversation, not a pull request. The project repository is private while the corpus seeds; see Governance for who to reach.
- What is the licence?
Apache-2.0, © The Maneuver Calculus contributors.