# TLCTC — Top Level Cyber Threat Clusters > A cause-oriented, axiomatic cyber threat taxonomy. TLCTC classifies threats by the generic vulnerability exploited — *why* a compromise happens — rather than by outcome ("ransomware," "data breach") or actor ("APT"). Ten non-overlapping clusters, ten axioms, classification rules, and an attack-path notation with velocity (Δt) and boundary operators. Licensed CC BY 4.0. The complete taxonomy is published as an agent-consumable **Open Knowledge Format (OKF) bundle** at `/okf/` — a tree of markdown files with YAML frontmatter, rendered from the canonical sources so LLM agents and RAG pipelines can consume TLCTC directly. Start at the bundle index and follow its links; each document is single-purpose and cross-linked. ## OKF bundle (agent-consumable knowledge) - [OKF bundle index](https://www.tlctc.net/okf/index.md): Navigation root for the markdown knowledge bundle - [Clusters](https://www.tlctc.net/okf/clusters/index.md): The ten threat clusters with full six-field definitions (Definition, Generic Vulnerability, Attacker's View, Developer's View, Boundary Tests, Topology) - [Axioms](https://www.tlctc.net/okf/axioms/index.md): The ten framework axioms - [Rules](https://www.tlctc.net/okf/rules/index.md): The 17 classification rules of v2.6 (R-SCOPE, R-SPECIFIC, R-ROLE, R-EXEC, R-CRED, R-SUPPLY, R-MITM, transit, intra-system and unresolved-step rules) - [Controls](https://www.tlctc.net/okf/controls/index.md): NIST CSF × TLCTC control matrix, full 60-cell ISO 27001:2022 Annex A starter controls, the CDE→COE→ECR effectiveness model, and KRI/KCI/KPI indicators - [Mappings](https://www.tlctc.net/okf/mappings/index.md): MITRE ATT&CK, MITRE CWE, and SigmaHQ rules grouped by cluster - [Attack paths](https://www.tlctc.net/okf/attack-paths/index.md): 59 real incidents rendered in TLCTC notation with step tables - [Glossary](https://www.tlctc.net/okf/glossary/index.md): Definitions of TLCTC terms ## Agent skill and prompts - [Agent Skills discovery index](https://www.tlctc.net/.well-known/skills/index.json): Lists the `tlctc-classify` agent skill (CC BY 4.0), the complete TLCTC v2.6 analysis system for classifying incidents, CVEs and threat reports - [tlctc-classify SKILL.md](https://www.tlctc.net/.well-known/skills/tlctc-classify/SKILL.md): The skill itself. Install: `npx skills add Barnes70/TLCTC` (Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and other agents), `/plugin marketplace add Barnes70/TLCTC` (Claude Code plugin), `hermes skills install well-known:https://www.tlctc.net/.well-known/skills/tlctc-classify` (Hermes Agent), `openclaw skills install @barnes70/tlctc-classify` (OpenClaw, via ClawHub) - [Monster prompts](https://www.tlctc.net/tlctc-prompt-index.html): Five audience-shaped paste-in prompts (CTI / forensic, SOC, DevSecOps, CISO, regulators) plus the canonical v2.6 core, for chat interfaces without skill support ## Core documents - [Core paper (v2.6)](https://www.tlctc.net/tlctc-whitepaper.html): The canonical definition of the framework — derivation, clusters, axioms, rules, notation ([PDF](https://www.tlctc.net/tlctc-whitepaper.pdf)) - [Application paper (v2.6)](https://www.tlctc.net/tlctc-application.html): Classification procedure, worked examples, governance and control mapping ([PDF](https://www.tlctc.net/tlctc-application.pdf)) - [White paper](https://www.tlctc.net/tlctc-v2.0-whitepaper.html): The extended practitioner handbook — full notation grammar, boundary catalogs, decision procedures - [Framework JSON (machine-readable)](https://github.com/Barnes70/TLCTC/blob/main/json-schemas/layer-1/tlctc-framework.v2.6.json): Layer-1 dictionary (v2.6) — clusters, axioms, rules ## Reference - [Citable record, core paper (Zenodo DOI)](https://doi.org/10.5281/zenodo.20633176): A Cause-Oriented Cyber Threat Taxonomy: The Top Level Cyber Threat Clusters Framework (concept DOI; v2.6 = 10.5281/zenodo.22943490) - [Citable record, application paper (Zenodo DOI)](https://doi.org/10.5281/zenodo.22697636): Applying the Top Level Cyber Threat Clusters (concept DOI; v2.6 = 10.5281/zenodo.22943516) - [Source repository (GitHub)](https://github.com/Barnes70/TLCTC): Canonical source of truth; the OKF bundle is generated from it - [Open Knowledge Format spec](https://github.com/GoogleCloudPlatform/knowledge-catalog/tree/main/okf): The format this bundle conforms to (OKF v0.1) ## Notes for agents - The OKF bundle is a **rendered view**; the JSON schemas, white paper, and tools in the source repository remain the single source of truth. - ISO 27001:2022 Annex A control placements and the CWE mapping are **starter / AI-assisted guidance**, labelled as such in each document — not certified control sets. The taxonomy itself (clusters, axioms, rules) is authored and frozen.