DISARM and STIX 2.1: a common language for describing information operations

Since the summer 2026 issues, our monthly monitoring of how Belarusian state media talk about European Union countries has come with two additional layers: techniques from the DISARM framework and a data package in the STIX 2.1 standard. This page explains in plain terms what they are, why they matter and, just as importantly, what they do not mean.

The problem: the same thing, different names

Imagine ten hospitals in different countries treating the same disease, each recording the diagnosis in its own words. One writes “lung inflammation”, another “pneumonia”, a third lists the symptoms. Every record is correct, but they cannot be added up into a picture of an epidemic. That is why medicine has the International Classification of Diseases: each diagnosis has its own code, and a doctor in Vilnius understands a record made in Lisbon without translation.

Information operations were long described in the same way. Researchers, fact-checkers and government services named the same techniques differently: “planting”, “stirring up”, “smearing”, “information attack”. Observations piled up, but comparing and exchanging them was hard. DISARM and STIX tackle this from two sides: the first provides common names for techniques, the second a common format for exchanging observations.

DISARM: a vocabulary of techniques

DISARM (Disinformation Analysis and Risk Management) is an open framework of information-operation techniques, developed and maintained by the DISARM Foundation. It is modelled on MITRE ATT&CK, which cybersecurity specialists use to describe the actions of attackers, and it describes behaviour rather than message content: what those running an operation actually do.

DISARM divides the life cycle of an operation into four phases: planning, preparation, execution and assessment. Within the phases are tactics, within the tactics specific techniques, and each technique has its own code. For example, T0023 stands for distorting facts, T0079 for sowing division, T0075.001 for discrediting credible sources. This “red” framework describes the attacker’s actions; alongside it there is a “blue” framework of countermeasures.

The European External Action Service (EEAS) made DISARM part of its analytical approach to foreign information manipulation and interference (FIMI) as early as its first report on FIMI threats in 2023. The framework has since become one of the shared languages of the European community that counters information operations.

How we use DISARM

Since the June 2026 issue, the narrative categories and manipulation types identified by our AI analysis have been translated into DISARM techniques. The number next to a technique is the count of materials showing signs of that technique; a single material can map to several techniques at once. In the August issue the most frequent techniques were:

Code
Technique
Materials

T0135
Undermine
1,059

T0023
Distort Facts
912

T0078
Dismay
803

T0075.001
Discredit Credible Sources
753

T0079
Divide
730

An important caveat: for now this is a translation through a fixed mapping table (version v0). The model does not assign a technique to each material individually; the technique follows from the category the model has already assigned. The exception is manipulation types for which the model cites a passage from the material itself; such links are marked separately and carry higher confidence. The next version will assign techniques material by material and always attach a supporting quotation. We check all codes against a pinned version of the DISARM reference dated 22 November 2024, so that technique numbers do not drift from the original.

STIX 2.1: a form for exchange

If DISARM is the vocabulary, STIX (Structured Threat Information Expression) is the form on which observations are written down so that someone else’s software can read them. The standard is maintained by the OASIS consortium; it was originally designed for exchanging cyber-threat data. In STIX an observation is broken down into objects (who, which technique, against which country, in which material) and the relationships between them (uses, targets, derived from).

The EEAS has encoded FIMI incidents in STIX since its first threat report, and in the fourth report (March 2026) all the incidents described are recorded in this format. DISARM techniques fit naturally into STIX: each becomes an “attack pattern” object referencing the framework, and open threat-intelligence platforms such as OpenCTI can work with this reference.

What our package contains

Since the August 2026 issue, each monthly issue has come with a STIX 2.1 package. It records the issue as a whole, the countries discussed, narratives, DISARM techniques referencing the framework, the materials in which these techniques were found, and cases where one topic appeared in several sources on the same day. Each link between a material and a technique states how it was established (through the mapping table, or through an identified manipulation type with a quotation) and a confidence level on the same scale used in the confidence section of our issues: low (1–29), moderate (30–69), high (70–100).

The package is checked with the official OASIS tools. In August both external versions passed without a single error: the partner version contains about 29,500 objects, the public version about 3,800.

Three levels of access

Not everything that is useful to researchers should be published openly. The package is therefore built in three versions marked under TLP 2.0 (Traffic Light Protocol), the widely used labelling system that tells recipients how far the data may be shared.

Version
Marking
Contents

Public
TLP:CLEAR
Countries, narratives and DISARM techniques at issue level; addresses of state-media materials

Partner
TLP:GREEN
The same, plus outlets and their channels on different platforms, links from each material to techniques with method and confidence, same-day topic co-occurrence

Internal
TLP:AMBER+STRICT
Working version, not shared

No version contains the full texts of materials or information about our internal infrastructure.

What these layers do not mean

A technique code next to a material does not prove intent and is not a verdict on truthfulness. It describes a technique whose signs were found in the text. Most such links come from automated analysis, so their confidence is moderate until they are checked by hand.

The same topic appearing in several sources on the same day is not evidence of coordination. In our series such cases always carry low confidence: we do not yet test the timing of publications statistically.

STIX does not by itself attribute anything. Belarusian state media appear in the package as outlets and channels through which materials are distributed; the package does not settle the responsibility of specific individuals.

How to obtain the package

The public version of the package for any issue from August 2026 onwards, together with a description of its structure, can be requested at info@factcheck.lt. Organisations that work with STIX can receive the partner version by arrangement.

Page prepared by FactCheck.LT. Version 1.0, September 2026. The package structure will evolve: the next step is coding DISARM techniques material by material, with a supporting quotation for every link.

Share to friends
Factсheck LT