This repository contains a small Python generator that builds STIX 2.1
marking-definition objects for the Admiralty source reliability and
information credibility scales, then packages them into a STIX bundle.
The entrypoint is generate-objects.py.
The script generates:
- 6
marking-definitionobjects for Admiralty information credibility (1-6) - 6
marking-definitionobjects for Admiralty source reliability (A-F) - 1 STIX
bundlecontaining:- the DOGESEC identity object
- the shared
stix2extensionsmarking-definition object - the two extension-definition input objects
- all generated marking-definition objects
The generated objects are deterministic:
- object IDs are created with UUIDv5
- the
createdtimestamp is fixed - bundle contents are sorted before hashing
- the bundle ID only changes when the bundled object content changes
This makes the output stable across repeated runs, which is useful for version control and downstream automation.
- Python 3.9 or newer
- Network access to GitHub so the script can download the two required
extension-definition JSON objects from
muchdogesec/stix2extensions
The script only uses the Python standard library, so no package installation is required.
The script pulls these upstream STIX objects directly from GitHub:
- DOGESEC identity: dogesec.json
stix2extensionsmarking-definition: stix2extensions.json- Admiralty information credibility extension-definition: marking_definition_admiralty_information_credibility.json
- Admiralty source reliability extension-definition: marking_definition_admiralty_source_reliability.json
The script resolves output paths relative to the repository root and writes to this structure:
manually_generated/
objects/
marking-definition/
bundle/
If the objects/marking-definition or objects/bundle directories do not
exist, the script will create them.
From the repository root:
PYTHONPATH=. python3 generate-objects.pyIf GitHub is reachable, the script will download the extension-definition input objects and then write:
- individual
marking-definitionJSON files tomanually_generated/objects/marking-definition/ - a bundle file to
manually_generated/objects/bundle/bundle--<uuid>.json
Example output:
Wrote 12 marking-definition objects
Wrote bundle: /path/to/repo/manually_generated/objects/bundle/bundle--<uuid>.json
Bundle ID: bundle--...
The script defines fixed values for:
- a UUID namespace used to generate deterministic STIX IDs
- a fixed
createdtimestamp:2020-01-01T00:00:00.000Z - STIX
spec_version:2.1 - the
created_by_ref - the two extension-definition IDs used in generated objects
- the raw GitHub URLs for the four upstream input objects
Two in-memory dictionaries define the generated content:
INFORMATION_CREDIBILITY1= Confirmed by other sources2= Probably true3= Possibly true4= Doubtful5= Improbable6= Truth cannot be judged
SOURCE_RELIABILITYA= Completely reliableB= Usually reliableC= Fairly reliableD= Not usually reliableE= UnreliableF= Reliability cannot be judged
For each Admiralty code, the script builds a marking-definition object with:
- a deterministic STIX ID
- a human-readable
nameincluding the code and description - an
extensionsblock containing the Admiralty-specific code and description - two fixed
object_marking_refs
Information credibility and source reliability objects use different extension-definition IDs and different extension property names.
Each generated marking definition is written to a separate JSON file named after the STIX object ID:
marking-definition--<uuid>.json
This keeps filenames stable and directly traceable to the object they contain.
The script then creates a STIX bundle containing:
- the downloaded DOGESEC identity object
- the downloaded
stix2extensionsmarking-definition object - the downloaded information credibility extension-definition object
- the downloaded source reliability extension-definition object
- all generated marking-definition objects
Before assigning a bundle ID, it:
- sorts all bundled objects by ID
- serializes them into canonical JSON
- hashes that JSON with SHA-256
- uses the hash as input to a deterministic UUIDv5 bundle ID
This means the bundle ID is content-derived and reproducible.
After a successful run, you should have:
manually_generated/objects/marking-definition/
marking-definition--<uuid>.json
marking-definition--<uuid>.json
...
manually_generated/objects/bundle/
bundle--<uuid>.json
blog/representing_admiralty_codes_in_stix/