Releases: ocsf/ocsf-schema
Releases · ocsf/ocsf-schema
Release list
1.9.0
[v1.9.0] - Aug 3rd, 2026
Added
-
Categories
-
Event Classes
-
Profiles
- Added
record_integrityprofile that adds a cryptographicattestationover the event (integrity, authenticity, and non-repudiation), applied at the base event so any class can carry it. #1661 - Added optional
delegationattribute to theai_operationprofile, linking data-plane actions to the delegated authority under which they were performed. #1665
- Added
-
Objects
- Added
delegationobject describing a durable authorization context issued by a principal to a delegate. #1665 - Added
job_actionobject to describe an action that job can perform. #1597 - Added
job_triggerobject to describe a condition when job performs its action. #1597 - Added
cpu_infoobject for CPUs (array namecpu_info_list). #1630 - Added
iam_roleobject for user, role and group management. #1603 - Added
clipboardandclipboard_itemobject for clipboard activity. #1655 - Added
dns_resource_recordobject to represent an RFC 1035 resource record, used across Answer, Authority, and Additional sections. #1634 - Added
dns_sectionobject to represent a DNS message section containing supplementary resource records and an optional TSIG record. #1634 - Added
tsigobject to represent a TSIG (Transaction Signature) record with structured fields for security analytics:algorithm,key_name,error_id, anderror. #1634 - Added
download_infoobject with information pertaining to a downloaded file. #1658 - Added
noteobject to capture a comment along with the user who made the comment and when the note was modified. #1670 - Added
ai_agentobject representing an autonomous AI agent, distinct from the existingagentobject (which models security sensors such as EDR, DLP, APM). #1641 - Added
attestationobject carrying afingerprintof and digitalsignaturesover an event, with optional tamper-evident chain attributes (prev_event,chain_uid) and anauthority_uididentifying the attesting party. #1661 - Added
prev_eventobject referencing the previous event in a tamper-evident chain by itsfingerprint(content binding) together withuidandtype_uid(retrieval). #1661 - Added
sensor_infoobject including thesensor_layer_idand related attributes. #1703
- Added
-
Observables
- Set
iam_role.name(49) &iam_role.uid(50) as Observable types. #1603
- Set
-
Platform Extensions
-
Dictionary Attributes
- Added
attestation_list,prev_event,authority_uid, andchain_uidattributes for therecord_integrityprofile. #1661 - Added
com_class_uuidattribute to reflect Class Identifier of a Component Object Model. #1597 - Added
event_codesthat is a set of event identifiers. #1597 - Added
log_sourcesthat is a set of log systems. #1597 - Added
job_actionsthat describes a set of actions that job can perform. #1597 - Added
job_triggersthat describes a set of conditions when job performs its actions. #1597 - Added
updated_jobthat reflects the attempted or the actual updated job. #1597 - Added
propertiesthat is a set of characteristics associated with an entity. #1597 - Added
speed_mhzfor compute unit clock speed in MHz. #1630 - Added
cpu_info_listas an array ofcpu_infoobjects. #1630 - Added
iam_role,iam_roles,updated_role,updated_group,updated_userattributes. #1603 - Added
updated_entity,updated_resources, andupdated_web_resourcesattributes for reporting intended or actual post-update state. #1618 - Added
initiatorandinitiator_idattributes for identifying which endpoint initiated a network communication, with genericUnknown (0)andOther (99)enums. #1598 - Added
transaction_id,query_additional,response_additional,authority, andkey_namedictionary attributes for DNS Activity restructuring. #1634 - Added
peripheral_devicesfor a set of peripherals. #1645 - Added
serializationandserialization_idattributes to record the canonical serialization or signing-envelope scheme used to produce the signed bytes. #1662 - Added
binary_data,contents,clipboard_native_type,string_data. #1655 - Added
uid_numericattribute to enable a unique identifier that is numeric to be represented natively using thelong_tdata type. #1643 - Added
download_infoattribute tofileobject. #1658 - Added
notesattribute as an array ofNoteobjects. #1670 - Added
prompt_textandresponse_textattributes for capturing the input prompt text and model response text of an AI message. #1674 - Added
ai_agentattribute referencing the newai_agentobject. #1641 - Added
hosted_ai_agent_listattribute for enumerating AI agents hosted by a process or other runtime. #1641 - Added
charterattribute (file type) for documents defining the role, scope, and operating bounds of an entity. #1641 - Added
criticality_iddictionary attribute with a four-level criticality enumLow (1),Medium (2),High (3), andVery High (4), plus genericUnknown (0)andOther (99)enums, paired with the existingcriticalitysibling. #1693 - Added
sensor_layer_idandsensor_layersibling. #1703 - Added
sensor_info_listas an array of typesensor_infofor theanalyticobject. #1703 - Added
delegationandissuer_uidattributes supporting thedelegationobject andai_operationprofile. #1665
- Added
Improved
-
Categories
-
Event Classes
- Added
updated_jobinScheduled Job Activityclass to reflect the actual or attempted state of the job upon update activity. #1597 - Added
iam_roleand role management support togroup_management,authorize_session. Filled out thegroup_managementclass with complete lifecycle as well as addedresources,policiesto the discrete activities. #1603 - Added
updated_*attributes toEntity ManagementandWeb Resources Activityfor class-specific update result reporting. #1618 - Added
initiator_idandinitiatortoNetwork Activitywith network-specific enumsSource Endpoint (1)andDestination Endpoint (2), and updatedsrc_endpointanddst_endpointdescriptions to reflect bi-flow and asymmetric flow scenarios. #1598 - Added
transaction_id,opcode_id/opcode,flag_ids/flags,authority,query_additional, andresponse_additionaltoDNS Activity. #1634 - Extended
activity_idattribute inHTTP Activityto cover all methods in IANA HTTP Method Registry. #1654 - Added
userstogroup_managementto replace deprecateduser. #1666 - Added
applicationattribute toApplication Lifecycleto replace the deprecatedappattribute, resolving the mismatch whereapp(captioned "Application") was typed as theproductobject. #1702 - Added
notestofindingand `incident_fin...
- Added
1.8.0
[v1.8.0] - Mar 16th, 2026
Added
-
Categories
-
Event Classes
-
Profiles
-
Objects
- Added
ai_modelobject with core fields (name,ai_provider,version) for AI operation events. #1488 - Added
message_contextobject for AI system interactions with role-based identification and token usage metrics (prompt_tokens,completion_tokens,total_tokens). #1488 - Added
tokenobject for API tokens, client tokens, and API keys used in API activity events. #1429 - Added
gpu_infoobject for GPU's (array namegpu_info_list). #1527 - Added
privilege_infoobject for describing specific privileges, actions, or permissions with usage status andtype_idenum (Read, Write, Execute). #1581 - Added
privilege_attack_infoobject for grouping privileges by potential MITRE ATT&CK techniques. #1581 - Added
service_privilege_analysisobject for privilege analysis results per cloud service or namespace. #1581 - Added
packetobject for network packets (array namepacket_list). #1569
- Added
-
Observables
-
Platform Extensions
- Added
macosextension (uid3). This extension adds themacos/macos_usersprofile and patches theprocessobject to add this profile. #1538
- Added
-
Dictionary Attributes
- Added
ai_providerattribute for AI model identification. #1488 - Added
ai_role_id,ai_roleattributes for AI communication context with proper sibling relationship. #1488 - Added
prompt_tokens,completion_tokens,total_tokensattributes for AI token usage metrics. #1488 - Added
embedding_modelattribute for AI retrieval systems. #1488 - Added
imported_symbolsattribute for reporting an executable file's imports. #1553 - Added
Imphash (18)enum to thealgorithm_idattribute of thefingerprintobject. #1553 - Added
tokenas atokenobject. #1429 - Added
bus_typeDerived frombus_type_id. #1527 - Added
bus_type_idIdentifier for the bus/interface standard. #1527 - Added
coresNumber of cores. #1527 - Added
vram_sizeInstalled VRAM. #1527 - Added
vram_modeDerived fromvram_type_id. #1527 - Added
vram_mode_idIdentifier for VRAM type. #1527 - Added
total_queued_durationto track how long an event spent in a queue. #1536 - Added
departmentandis_on_premises_sync_enabledfor ldap and Entra ID support. #1584 - Added
is_disabledandis_lockedas typeboolean_twith a "See specific usage" description. #1583 - Added
all_privileges_unusedboolean attribute indicating whether all privileges in a group are unused. #1581 - Added
analyzed_privileges_countinteger attribute for the total count of analyzed privileges. #1581 - Added
attacksingular attribute for MITRE ATT&CK details (complements existingattacksarray). #1581 - Added
is_unusedboolean attribute indicating whether an item is unused. #1581 - Added
privilege_attack_info,privilege_attack_info_listattributes for privilege-to-attack mappings. #1581 - Added
privilege_info,privilege_info_listattributes for specific privilege information. #1581 - Added
service_privilege_analysis,service_privilege_analysis_listattributes for service-level privilege analysis. #1581 - Added
total_potential_attacks_countinteger attribute for count of privileges mapping to attack techniques. #1581 - Added
read_count,write_count, andexecute_countinteger attributes. #1581 - Added
poolattribute of typegroup. #1521 - Added
mac_vendorasstring_t. #1575 - Added
network_observation_pointas typenetwork_endpoint. #1571 - Added
packetas apacketobject. #1569 - Added
packet_listas an array ofpacketobjects. #1569 - Added
encoding,encoding_idattributes for data encoding representation. #1569 - Added
format,format_idattributes for data format identification. #1569 - Added
source_idnormalized identifier for the source. #1569 - Added
sequence_numberattribute for ordering within a sequence. #1569 - Added
start_offsetattribute for the starting offset. #1569 - Added
end_offsetattribute for the ending offset. #1569
- Added
Improved
-
Categories
-
Event Classes
- Add
app_protocol_nametoNetwork Activityclass with clarified description for deep packet inspection. #1557 - Enhanced
app_namedescription inNetwork Activityclass to clarify network application identification by tools such as NBAR. #1557 - Added
ai_operationprofile toprocess_activityevent class. #1578 - Added
network_observation_pointattribute to the baseNetworkevent. #1571 - Added
packet_listtonetworkevent class. #1569
- Add
-
Profiles
-
Objects
- Extended
databaseobject with AI-specific database types (Vector (7),Knowledge Graph (8)) andembedding_modelfield for AI retrieval systems. #1488 - Added
signaturesto thefileobject. #1546 - Expanded on
created_timeattribute description within therelated_eventobject. 1552 - Added
imported_symbolsattribute to thefileobject. #1553 - Updated
fingerprintobject description. Updated the descriptions ofalgorithm,algorithm_id, andvalueattributes in thefingerprintobject. #1560 - Added
fingerprintsattribute to thenetwork_endpointobject. #1560 - Added
mac_vendorto theendpointobject. #1575 - Added
tokenas an attribute to theapiobject. #1429 - Added
created_timeattribute back to theauthentication_tokenobject with improved description. #1429 - Added
providerto theresource_detailsobject viacloudprofile. #1566 - Added
resourceattribute to thecheckobject to describe details about the resource that the check evaluated. #1574 - Added
total_queued_durationto themetadataobject. #1536 - Added
is_on_premises_sync_enabledtoAccount. Addeddepartmenttoldap_person. AddedActiveDirectory AccounttoAccount.type. #1584 - Added
is_disabledandis_lockedattributes to theaccountobject. #1583 - Added
analyzed_privileges_count,service_privilege_analysis_list, andtotal_potential_attacks_countattributes to thepermission_analysis_resultobject for detailed privilege analysis. #1581 - Added
macos/macos_usersprofile to theprocessobject viamacosextension patch. [#1538]...
- Extended
1.7.0
[v1.7.0] - Nov 14th, 2025
Added
-
Event Classes
- Added
Peripheral Activityevent class to the System category. #1471
- Added
-
Objects
-
Observables
- Set
network_endpoint.uidas an Observable type -type_id: 48. #1502
- Set
-
Dictionary Attributes
Improved
-
Event Classes
- Added
auth_factorsas an attribute to theAccount Changeclass and updated related activity names. #1455 - Added
Invokeas anactivity_idvalue for theModule Activityclass. #1497 - Added
launch_type_idandlaunch_typeas attributes to theProcess Activityevent class. #1517 - Added descriptions to values of
activity_idenum inProcess Activityevent class. #1517 - Added missing context classification to
windows_service_activity.win_service. #1531 - Added missing requirement to
process_activity.launch_type. #1531 - Added
cumulative_trafficattribute to the baseNetworkevent. Updatedtrafficdescription. #1529
- Added
-
Objects
- Added
type,type_uid, andvendor_id_listto theperipheral_deviceobject. #1471 - Relaxed the
classattribute requirement tooptionalin theperipheral_deviceobject. #1471 - Set the
vendor_namerequirement torecommendedin theperipheral_deviceobject. #1471 - Added
reporterto themetadataobject. #1476 - Added
event_uidandtype_uidto theobservableobject. #1503 - Set
load_type_idrequirement torecommendedin themoduleobject. #1497 - Added
at_least_oneconstraint onload_type_idandfunction_namein themoduleobject. #1497 - Modified descriptions in the
moduleobject to accommodateModule Activity: Invokeevent. #1497 - Added
function_invocationto themoduleobject. #1497 - Relaxed the
fileattribute requirement tooptionalin thejobobject. #1509 - Relaxed the
nameanduidrequirement torecommendedwithat_least_oneconstraint in theextensionobject. #1511 - Added
hosting_process,service_fileandservice_dll_fileto thewin_serviceobject. - Added
hosted_services, array to theprocessobject. - Added
source,type,log_source,original_event_uid,log_format,transmit_timetometadata.log_formattologger#1483 - Added
start_time,end_timeandtimespanto thenetwork_trafficobject. Updatednetwork_trafficdescription. #1529
- Added
-
Dictionary Attributes
- Added
Local (4)enum to thedirection_idattribute. #1475 - Added
Atom (38)enum as an availabletype_idforwin_resourceobject. #1477 - Updated reference descriptions/urls for win_resource types, including
Directory (1),Event (2),Timer (3),Device (4),Mutant (5),File (7),Token (8),Thread (9),Section (10),WindowStation (11),Driver (15),IoCompletion (16),Controller (17),SymbolicLink (18),WmiGuid (19),Process (20),Profile (21),Desktop (22),KeyedEvent (23),Adapter (24),Callback (27),Semaphore (28),Job (29),ALPC Port (32),SAM_ALIAS (33),SAM_GROUP (34),SAM_USER (35),SAM_DOMAIN (36),SAM_SERVER (37), andAtom (38). #1477 - Added
hosted_servicesto the Windows extension to theprocessobject. - Added multiple values to the
state_idenum attribute for thedigital_signatureobject. #1520 - Added
WFP Filter (39),WFP Callout (40),WFP Layer (41),WFP Sub-layer (42),WFP Provider (43)andWFP Provider Context (44)WindowsFilteringPlatform-related enums as an availabletype_idsforwin_resourceobject. #1530 - Added
cumulative_trafficofnetwork_traffictype. #1529
- Added
Misc
1.6.0
[v1.6.0] - Aug 1st, 2025
Added
-
Event Classes
- Added
IAM Analysis Findingevent class to the Findings category. #1389
- Added
-
Dictionary Attributes
- Added
from_list,from_mailboxes,reply_to_list,return_path,senderandsender_mailbox. #1454 - Added
access_level,programmatic_credentials,last_authentication_time,access_analysis_result,last_used_time,accessors,granted_privileges,identity_activity_metrics,password_last_used_time,access_type,permission_analysis_results,additional_restrictions,unused_privileges_count,condition_keys,applications,role,role_id. #1389 - Added
reg_binary_data,reg_integer_data,reg_string_data,reg_string_list_datato Windows extension. #1468 - Added
is_src_dst_assignment_knownas a boolean. #1464
- Added
-
Objects
Improved
-
Event Classes
- Added
DisconnectandReconnectactivities in theRDP Activityclass. #1415 - Added
useras an attribute to theRDP Activityclass. #1419 - Added
raw_data_hashas an attribute tobase_event. #1420 - Added
Add Subgroup, andRemove Subgroupactivities in theGroup Managementclass. #1447 - Added
MTA Relayactivity andto/fromattributes to theEmail Activityclass. #1454 - Added
http_requestandhttp_responseobjects to theFile Hosting ActivityClass #1458 - Added
Account Switchactivity_id to theAuthenticationclass. Addedaccount_switch_typeandaccount_switch_type_idattributes to theAuthenticationclass. #1460 - Added
is_src_dst_assignment_knownattribute toNetwork Activityclass. #1464
- Added
-
Objects
- Added more
algorithm_idvalues and references to thefingerprintobject. #1412 - Added xxHash H3's 64-bit and 128-bit variants to
algorithm_idon thefingerprintobject. #1420 - Added
Servicetousertype_idenum. #1428 - Added
Deletedtofindingstatus_idenum. #1437 - Added
statustorelated_eventobject. #1434 - Added
attack_graphtofinding_info. #1436 - Added
Executable Filetofiletype_idenum. Addedis_readonlyas an optional attribute. #1438 - Added
ptid(typelong_t) toprocessand deprecatedtid(typeinteger_t) #1450 - Added
state_idandstatetoanalytic. #1448 - Added
from_list,from_mailboxes,reply_to_list,return_path,senderandsender_mailboxattributes toemailobject. #1454 - Added
role,role_idtoresource_detailsobject,typetopolicyobject, #1389 - Added
is_truncatedanduntruncated_sizetometadata,loggerobjects. #1461 - Added
open_portsto thenetwork_interfaceobject. #1466 - Added
reg_binary_data,reg_integer_data,reg_string_data,reg_string_list_datatoreg_valueobject in Windows extension. #1468
- Added more
Misc
- Fixed spelling errors throughout the project and added spell checking to the CI linter workflow. #1411
- Improved description of the
Application Errorclass. #1424 - Fixed links to ocsf-docs repo #1453
- Set
device.uidas an Observable type - type_id: 47 #1446 - Improved descriptions of
src_endpointanddst_endpointattributes inNetwork Activityclass. #1464 - Improved the description of the
bytestring_tdata type. #1468
Deprecated
- Deprecated usage of
groupattribute in favor ofgroupsin thedatabucketobject. #1344 - Deprecated usage of
credential_uidattribute in favor ofprogrammatic_credentialsin theuserobject. #1389 - Deprecated usage of items
3and4in thetype_idenum inaccountobject, in favor of thetype_idenum in theuserobject. #1389 - Deprecated item
9(REG_QWORD_LITTLE_ENDIAN) in thetype_idenum in thereg_valueobject. Its presence was an error. #1468
1.5.0
[v1.5.0] - April 28th, 2025
Added
-
Event Classes
-
Dictionary Attributes
- Added
boot_uidas astring_t. #1335 - Added
cpidas auuid_t. #1246 - Added
raw_data_sizeas along_t. #1347 - Added
assessmentsas an array ofassessmentobjects. #1343 - Added
meets_criteriaas aboolean_t. #1343 - Added
display_nameattribute as astring_t. #1341 - Added
is_directedas aboolean_t,relationas astring_t,query_language&query_language_ida sibling pair. #1343 - Added
resource_relationshipof typegraph,nodesof typenode,edgesof typeedge. #1343 - Added
fix_coverageasstring_tandfix_coverage_idasint_t. #1350 - Added
eid,iccid, andmeidasstring_t. #1346 - Added
is_backed_up,is_mobile_account_active, andis_sharedasboolean_t. #1346 - Added
detection_pattern_typeandetection_pattern_type_idas astring_tandint_trespectively. #1310 - Added
external_idas anstring_t. #1310 - Added
intrusion_setsas an arraystring_t. #1310 - Added
uploaded_timeas antimestamp_t. #1310 - Added
isp_orgasstring_t. #1351 - Added
ldapprotocol toauth_protocol_idenum. #1359 - Added
observation_parameter,observation_type,observed_patternasstring_tandoccurrencesas an array ofoccurrence_details. #1358 - Added
analysis_targetsas an array of typeanalysis_target. #1371 - Added
num_volumes,num_infectedasint_t,unique_malware_count,volumeasstring_t. #1373 - Added
end_columnandstart_columnasinteger_t. #1357 - Added
dependency_chain,exploit_requirement, andexploit_typeasstring_t. #1357 - Added
exploit_ref_url,license_url,package_manager_url, anduriasurl_t. #1357 - Added
transformation_info_list#1392 - Added
authentication_tokenasauthentication_token,kerberos_flagsasstring_tandis_renewableasboolean_t. #1391 - Added
ticketsas an array ofticketobjects. #1402 - Added
is_readasboolean_t. #1406 - Added
query_typeandquery_type_idasstringandinteger_trespectively. #1382 - Added
tcp_state_idasinteger_t. #1382 - Added
query_evidenceas typequery_evidence. #1382 - Added
checksas typecheck. #1369
- Added
-
Objects
- Added
assessmentobject to capture evaluations/assessments of configurations/signals. #1343 - Added
node,edge,graphobjects. #1343 - Added
anomaly,anomaly_analysis,baseline,observationobjects. #1358 - Added
traitobject. #1363 - Added
mitigationobject. #1348 - Added
analysis_targetobject. #1371 - Added
malware_scan_infoobject. #1373 - Added
applicationobject. #1357 - Added
campaignobject #1310 - Added
threat_actorobject #1310 - Added
transformation_info#1392 - Added
authentication_tokenobject. #1391 - Added
query_evidenceobject. #1382 - Added
checkobject #1369
- Added
-
Observables
- Added
process_entity.uidas an Observable type -type_id: 39. #1380 - Added
email.subjectandemail.uidas an Observable types -type_id: 40andtype_id: 41. #1380 - Added
message_uidas Observable type -type_id: 42. #1380 - Added
reg_value.nameas an Observable type -type_id: 43. #1380 - Added
advisory.uidas Observable typetype_id: 44. #1357 - Updated
resource_details.uid,web_resource.uid, andwin_resource.uidto be observabletype_id: 10#1394 - Added
file_path_tas an Observable type -type_id: 45and marked fields as this type #1381lineagedictionary attributeaffected_package.pathobject attributefile.pathobject attributeimage.pathobject attributekernel.pathobject attributemalware.pathobject attributeprocess_entity.pathobject attribute
- Added
extensions/windows/reg_key_path_tas an Observable type -type_id: 46and marked fields as this type #1381reg_key.pathobject attributereg_value.pathobject attribute
- Added
Improved
-
Event Classes
- Added
assessmentstoconfig_state. #1343 - Added
raw_data_sizetobase_event. #1347 - Added
anomaly_analysestodetection_finding. #1358 - Added
Detectvalue foractivity_idin Remediation events. #1362 - Added
resourcestouser_access. #1374 - Added
malware_scan_info,malwaretodetection_finding. #1373 - Added
authentication_tokentoauthentication. #1391
- Added
-
Objects
- Added
boot_uidtodeviceobject. #1335 - Relaxed constraint to provide
email_addr,phone_number, orsecurity_questionsonauth_factor. #1339 - Added
cpidtoprocess_entityobject. #1246 - Added
boot_uidtodeviceobject. #1335 - Added
meets_criteriaandpolicytoassessmentobject. #1343 - Added
assessmentstocomplianceobject. #1343 - Added
datatopolicyobject. #1343 - Added
display_nameattribute to theuserandldap_personobjects. #1341 - Added
resource_relationshiptoresource_detailsobject. #1343 - Added
fix_coverage,fix_coverage_idtovulnerabilityobject. #1350 - Added
eid,iccid,is_backed_up,is_mobile_account_active,is_shared, andmeidtodevice. #1346 - Added
is_backed_uptoresource_details. #1346 - Added
isp,isp_orgtonetwork_endpoint&whoisobjects. #1351 - Reduced requirement of
standardsto recommended in thecomplianceobject. #1352 - Updated MITRE
attack,tactic,technique,subtechniquecaptions, descriptions, references to include MITRE ATLAS. Used standard requirements for_entityextended objects. #1355. - Added
name,resources,uid,verdict, andverdict_idtoevidences. #1337 - A...
- Added
v1.4.0
[v1.4.0] - January 31st, 2025
Added
-
Categories
- Added new
Unmanned SystemsCategory. #1169
- Added new
-
Event Classes
- Added
OSINT Inventory Infoevent class to the Discovery category. #1154 - Added
Script Activityevent class to the System category. #1159 - Added
Startup Item Queryevent class. #1119 - Added
Drone Flights Activityevent class to the Unmanned Systems category. #1169 - Added
Cloud Resources Inventory Infoevent class to the Discovery category. #1250 - Added
Airborne Broadcast Activityevent class to the Unmanned Systems category. #1253 - Added
Application Errorevent class to the Application Activity category. #1299
- Added
-
Profiles
- Added
incidentprofile. #1293
- Added
-
Dictionary Attributes
- Added
has_mfaas aboolean_t. #1155 - Added
environment_variablesas an array ofenvironment_variableobject. #1172 - Added
forward_addras anemail_t. #1179 - Added
related_cves,related_cwesas arrays ofcve,cweobjects respectively. #1176 - Added
exploit_last_seen_timeas atimestamp_t. #1176 - Added
is_alertas aboolean_t. #1179 - Added
working_directoryas astring_t. #1195 - Added
is_deletedas aboolean_t. #1196 - Added
body_lengthas aninteger_t. #1200 - Added
is_publicas aboolean_t. #1208 - Added
tags,control_parametersas an array ofkey_value_objectobject. #1219 - Added
community_uidas astring_t. #1202 - Added
locationto themanaged_entityobject. #1169 - Added
unmanned_system_operatorto the dictionary, extendsuser. #1169 - Added
locationsto the dictionary, an array type of thelocationobject, used within the newoperating_areaobject. #1169 - Added
altitude_ceiling,altitude_floor,geodetic_altitude,aerial_height,horizontal_accuracy,pressure_altitude,radius,speed,track_direction, andvertical_speedall to supportoperating_areaandunmanned_aerial_systemobjects. #1169 - Added
imei_listas an arraystring_t. #1225 - Added
is_encryptedasboolean_t;column_name,cell_name,storage_class,key_uid,json_pathasstring_t&column_number,row_number,page_number,record_index_in_arrayasinteger_t. #1245 - Added
group_provisioning_enabled,scim_group_schema,user_provisioning_enabled,scim_user_schema,scopes,idle_timeout,login_endpoint,logout_endpoint, andmetadata_urlentries to the dictionary to support the newscimandssoobjects. #1239 - Added new
11: Basic Authenticationenum value toauth_protocol_id. #1239 - Added
valuesas an array ofstring_t. #1251 - Added
filesurlsandmessage_trace_uid. #1259 - Added
kernel_releaseas astring_t. #1249 - Added
os_machine_uuidas auuid_t. #1268 - Added
sbom,author,related_component,relationship,relationship_idandsoftware_componentto support SBOMs. #1262 - Added
related_events_countas anint_t. #1271 - Added
event_uidas astring_t. #1312 - Added
debugattribute as astring_tarray, used in themetadataobject. #1308 - Added
ancestryas a list ofprocess_entity. #1317 - Added
internal_nameas astring_t. #1322 - Added
cc_mailboxes,from_mailbox,to_mailboxes,delivered_to_listandreply_to_mailboxes. #1307 - Added
flag_historyandbytes_missedattributes. #1316
- Added
-
Objects
- Added
environment_variableobject. #1172, #1288 - Added
advisoryobject. #1176 - Added a generic
key_value_objectobject. #1219 - Added
unmanned_aerial_systemandunmanned_system_operating_areaobjects. #1169 - Added a
long_stringobject. #1228 - Added
discovery_details,encryption_details,occurrence_detailsobjects. #1245 - Added
scimobject. #1239 - Added
ssoobject. #1239 - Added
vendor_attributesobject. #1257 - Added
aircraftobject. #1253 - Added
software_componentandsbomobjects. #1262 - Added
drive_typeanddrive_type_idobjects. #1287 - Added
cpu_architectureandcpu_architecture_idobjects. #1278 - Added
process_entityobject. #1317
- Added
Improved
-
Event Classes
- Added
evidencestocompliance_findingclass. #1157 - Added
is_alerttodetection_findinganddata_security_findingclasses. #1178 - Added
risk_detailstodata_security_findingclass. #1178 - Removed constraint from
group_managementclass. #1193 - Added
Archived|5as an enum item tostatus_idattribute in Findings classes. #1219 - Added a
Traceactivity_idto theEmail Activityclass. #1252 - Added a
message_trace_uidto theEmail Activityclass. #1259 - Added
vendor_attributesto allFindingsCategory classes. #1257 - Added
sbomtoSoftware Inventory Infoclass. #1262 - Relaxed requirements on the
dst_endpointattribute in thenetwork_activityevent class and added anat_least_oneconstraint withsrc_endpointanddst_endpoint. #1274 - Relaxed requirements on the
http_requestandhttp_responseattributes in thehttp_activityevent class and added anat_least_oneconstraint with these attributes. #1274 - Added
hostprofile tobase_eventand removed this profile elsewhere in the event hierarchy. #1280 - Added the
actorattribute to the IAM base event. #1280 - Added
security_controlprofile tobase_eventand removed this profile elsewhere in the event hierarchy. #1281 - Added
policiestoAccount Changeclass. #1282 - Added
Unlockactivity toaccount_changeclass. #1285 - Added
incidentprofile tofindingto affect classes that extend it. #1293 - Added
keyboard_infoobject to RDP event class. #1313 - Added attributes and a new Activity ID to the
File Hosting Activityclass for network file share services and authorization check result. Activity ID added:17- "Access Check". Optionalcontextgroup attributes added:access_list,access_mask,access_result,share,share_type, andshare_type_id. [#...
- Added
v1.3.0
[v1.3.0] - August 1st, 2024
Added
-
Categories
- Added
Remediationcategory. #1066
- Added
-
Event Classes
- Added
Event Log Activityevent class to the System Activity category. #1014 - Added
Remediation Activity,File Remediation Activity,Process Remediation Activity,Network Remediation Activityevent classes to the Remediation category. #1066 - Added
Windows Service Activityevent class to the System Activity category via Windows extension. #1103 - Added
Software Inventory Infoevent class to the Discovery category. #1134
- Added
-
Profiles
- Added
osintProfile based on theosintobject. #992
- Added
-
Objects
- Added
d3fend,d3f_tactic,d3f_techniqueMITRE objects. #1066 - Added
ja4_fingerprintobject. #834 - Added
ja4_fingerprint_listas a list ofja4_fingerprintobjects. #834 - Added
ticketobject. #1068 - Added
osintobject. #992 - Added
signaturesobject, an array ofsignatureobjects. #992 - Added
whoisobject. #992 - Added
domain_contactand array-typeddomain_contactsobject for use withwhoisobject. #992 - Added
Windows Serviceobject to the Windows extension. #1103 - Added
timespanobject. #1125
- Added
Improved
-
Categories
n/a -
Event Classes
- Added
file_resultto File Hosting Activity. #1045 - Added entries to
injection_type_idenum (Process Activity) andactivity_idenum (Memory Activity). #1060 - Added a
Restart,Enable,Disable, andUpdateactivity_idto theApplication Lifecycleclass. #1064 - Added
ja4_fingerprint_listto base network event class. #834 - Added
tickettoIncident Findingevent class. #1068 - Added new activities
Enroll,Activate,Deactivate,Suspend, andResumeto theEntity Managementclass. #1095 - Added new activity
ListentoNetwork Activityand relax requirement ofsrc_endpoint. #1147 - Added
state,state_idtoDevice Config State Change. #1143 - Added
resourcesattribute toVulnerability FindingandCompliance Finding. #1150
- Added
-
Profiles
n/a -
Objects
- Added
exttoFileobject. #1046 - Added
account,device,email,url,usertoevidencesin detection finding. #1000 - Added
state_id,statetoDigital Signatureobject. #1069 - Added
domaintoUniform Resource Locatorobject. #1096 - Added
reg_keyandreg_valuetoEvidence Artifactsobject. #1078 - Added
type_idand associated entity objects toManaged Entity. #1094 - Added
vendor_name,type,type_idto objectpackage. #1093 - Added
router,ids, andipsentries totype_idenum in theEndpointobject. #1121 - Added
jobtoEvidence Artifactsobject. #1130 - Added
ipto objectload_balancer. #1138 - Added
cpe_nameandhashtoSoftware Packageobject. #1142 - Added
avg_timespanto thekb_articleobject. #1125 - Added
created_time,desc,short_desc,reputation,src_urltoenrichmentobject. #1149 - Added
compliance_references,compliance_standardsto thecomplianceobject. #1110
- Added
Bugfixes
- Fixed the host profile construction in
patch_stateevent class. #1087 - Removed the optional requirement overrides for
nameanduidin_resourceas they are part of a constraint. #1087 - Fixed declarations of
data_lifecycle_state_id,integrity,opcode_id,risk_level, andanalytic.type_id. #1111
Deprecated
- Deprecated
resourceinVulnerability FindingandCompliance Findingevent classes in favor ofresources. #1150
Breaking changes
n/a
Misc
- Colorized validator output #1048
- Updated the GitHub workflow for the
ocsf-validatorto print colorized output.
- Updated the GitHub workflow for the
- Clarify how to reference profiles in metadata #1056
- Updated the description of
metadata.profilesto clarify the correct way to reference a profile in that list.
- Updated the description of
- Added a
gitignorefile. #1071 - New Extension registration for Cisco #1074
- Cleaned up MITRE trademarks and registrations for captions and descriptions.
- Declared enums in dictionary.json have sane "0" (Unknown) and "99" (Other) declarations and descriptions where appropriate #1111
- Adds support for
suppress_checkscontrols in attributes to allow tools to automatically validate conventions #1063- Updated several attributes that do not follow conventions to disable linting for them
- Added
credential_uidas an Observable type -type_id: 19. #1137 - New Extension registration for US Gov #1140
- Enum definitions are now refactored such that generic enum descriptions have "See specific usage" in the description #1146
v1.2.0
[v1.2.0] - April 23rd, 2024
Added
-
Categories
n/a
-
Event Classes
- Added
Data Security Findingevent class. #953 - Added
File Queryevent class. #967 - Added
Folder Queryevent class. #967 - Added
Group Queryevent class. #967 - Added
Job Queryevent class. #967 - Added
Kernel Object Queryevent class. #967 - Added
Module Queryevent class. #967 - Added
Network Connection Queryevent class. #967 - Added
Networks Queryevent class. #967 - Added
Peripheral Device Queryevent class. #967 - Added
Prefetch Queryevent class. #967 - Added
Process Queryevent class. #967 - Added
Registry Key Queryevent class. #967 - Added
Registry Value Queryevent class. #967 - Added
Service Queryevent class. #967 - Added
Session Queryevent class. #967 - Added
User Queryevent class. #967 - Added
Tunnel Activityevent class. #1012
- Added
-
Profiles
- Added
data_classificationprofile. #998
- Added
-
Objects
-
Observables
- Added
port_tsubnet_tcmd_linecountrypidcwe.uidcve.uiduser_agentenum items. #1035
- Added
-
Platform Extensions
n/a
Improved
-
Categories
n/a
-
Event Classes
- Added
auth_factorsarray to Authentication event class. #949 - Modified all classes such that primary attributes are at least recommended. #974
- Added
src_endpoint,http_requestattributes to all IAM category classes. #976 - Added
autonomous_systemtonetwork_endpointobjects. #978 - Added
List,EncryptandDecryptactivities todatastoreevent class. #989 - Added
fileattribute tohttp,rdp,ssh, andftpevent classes. #985 - Added a
Preauthactivity_idto theAuthenticationclass. #1018 - Added the
Security Controlprofile to theDatastore Activityclass. #1030 - Added
risk_detailsto Detection Finding. #1032
- Added
-
Profiles
n/a
-
Objects
- Expanded
type_idenum inanalyticobject to account for more use-cases: #9535 - Fingerprinting6 - Tagging7 - Keyword Match8 - Regular Expressions9 - Exact Data Match10 - Partial Data Match11 - Indexed Data Match
- Added
lat,long,geohashattributes tolocationobject. #971. - Added
risk_score,risk_level_id,risk_leveltouserobject. Issue #972. - Added
app_name,app_uidtoactorobject. Issue #966, PR #979. - Added
container,database,databucketto theevidencesobject. #984 - Added
ownertoendpointobject. #987 - Added
is_appliedBoolean attribute topolicyobject. #987 - Added
agent_listas an array ofagentobjects. #987 - Added
policiesobject as an array ofpolicyobjects. #987 - Added
agent_listtoendpointobject. #987 - Added
labelsto theAccountobject. #1028 - Added
data_classificationprofile todatabase,databucket,email,file,metadata,product,resource_detailsandweb_resourceobjects. #998
- Expanded
-
Platform Extensions
n/a
Bugfixes
- Changed datatype of
priorityattribute, frominteger_ttostring_t#959 - Extended
email_tregexp to allow characters from RFC5322 before @. - Updated
logon_type_idenum to include0asUnknown. Added enum item1asSystem. #1055
Deprecated
- Deprecated
coordinatesattribute in favor of specificlat,longattributes. #971 - Deprecated
invoked_byattribute in theActorobject in favor ofapp_name. #979.
Breaking changes
n/a
Misc
- New Extension registration for Sedara. #951
- Corrected punctuation for the
transmit_timeattribute. #1001 - New ways to define observables in the metaschema. #982 and #993
- (Current) Dictionary types using
observableproperty in dictionary types. This allows defining all occurrences of attributes of this type as an observable. - (Current) Objects using top-level
observableproperty. This allows defining all occurrences attributes whose type is this object as an observable. - (New) Dictionary attributes using
observableproperty in attribute. This allows defining all occurrences of this attribute as an observable. - (New) Object-specific attributes using
observableproperty class's attributes. This allows defining object attributes as observables only within instances of this specific object. - (New) Event class-specific attributes using
observableproperty class's attributes. This allows defining class attributes as observables only within instances of this specific class. - (New) Event class-specific attribute paths using top-level
observablesproperty. Theobservablesproperty holds an object mapping from a dotted attribute path to an observabletype_id. This allows defining an observable only within instances of this specific class, and only for the attributes at these paths, even for attributes that are within nested objects and arrays. This can also be used for top-level class attributes, which can be more convenient that defining a class attribute observable for classes that extend another, but don't otherwise change an attribute definition.
- (Current) Dictionary types using
- Metaschema improvements. #993
- Detect unexpected top-level properties in object and event class definitions. This was added at this point to detect invalid observable definitions: invalid
observableproperty in event classes, and invalidobservablesproperty in objects. - Remove hard-coded list of categories from
metaschema/categories.schema.json, leaving this to theocsf-validator. This change makes testing with alternate schemas that may add extra categories easier, as well as making it possible to validate private extensions that contain new categories.
- Detect unexpected top-level properties in object and event class definitions. This was added at this point to detect invalid observable definitions: invalid
- Metaschema error reporting #1027
- Updated the definition of
objectandeventso that metaschema errors reported by the validator with nested properties correctly attribute the error to the property with the error, rather than the top-level class.
- Updated the definition of
OCSF Schema Release v1.1.0
[v1.1.0] - January 25th, 2024
Added
-
Categories
n/a -
Event Classes
- Added
User Inventory Infoevent class. #667 - Added
Vulnerability Findingevent class. #698 - Added
NTP Activityevent class #705 - Added
OS Patch Stateevent class. #746 - Added
Datastore Activityevent class 6005. #874 - Added
Detection Findingevent class. #877 - Added
Incident Findingevent class. #903 - Added
Device Config Sate Changeevent class. #914 - Added
Scan Activityevent class. #915 - Added
File Hosting Activityevent class. #917
- Added
-
Profiles
-
Objects
Improved
-
Categories
-
Event Classes
- Added
MFA EnableandDisabletoactivity_idto the Account Change event class. #724 - Added
Service Ticket Renewtoactivity_idof the Authentication event class. #765 - Added
urlattribute to Network Activity event class. #857 - Added
http_request,http_response,tlsattributes,network_proxyprofile to Web Resources Activity event class. #895 - Adjusted requirement of
dst_endpointfromrequiredtorecommendedin the DNS Activity event class. #901 - Added
CreateandDeletetoactivity_idof the Group Management event class. #929
- Added
-
Profiles
-
Objects
- Added
url_stringattribute to theproductand theweb_resourceobjects. #675 - Added
typeandtype_idattributes to theendpointobject. #690 - Added
cwe,desc,referencesandtitletocveobject. #698 - Added
affected_packageobject andaffected_packagesattribute tovulnerabilityobject. #698 - Added
purltopackageobject. #698 - Added
cpe_nameattribute to theproductand os objects. #713 #731 - Added
containeranddatatoresponseandrequestobjects. #738 - Added
groupto theapiobject. #738 - Added
namespaceto theresource_detailsobject. #738 - Added
log_levelto themetadataobject. #738 - Added
lengthto thehttp_requestobject. #768 - Added
is_exploit_availableto thevulnerabilityobject. #777 - Added
domainattribute to thegroupobject. #871 - Adjusted attribute requirements in
dns_query,dns_answerobjects. #879 - Added firewall, router, switch, hub to endpoint
type_idenum. #921 - Added
is_vpnto thesessionobject. #922 - Added
statetonetwork_connection_infoobject. #932
- Added
Bugfixes
n/a
Deprecated
- Deprecated
cwe_uidandcwe_urlattributes and removed fromcveobject. #678 - Deprecated
http_statusattribute fromHTTP Activityevent to be replaced byhttp_response.code. #767 - Deprecated
findingobject in favor offinding_infoobject. #769 - Deprecated
proxyattribute from the dictionary, in favor ofNetwork Proxyprofile. #856 - Deprecated
group_nameattribute. #873 - Deprecated
Security Findingclass to be replaced by the new specific classes according to the use-case:Vulnerability Finding,Compliance Finding,Detection Finding,Incident Finding. #877 - Deprecated
Web Resources Access Activityevent class. #890 - Deprecated
Network File Activityevent class in favor ofFile Hosting Activity#917 - Deprecated
extension_listin TLS object in favor oftls_extension_list. #936
Breaking changes
n/a
Misc
- New Extension registration for SentinelOne. #706
- Added json-schema based metaschema validation to ensure correctness, consistency of the JSON definitions. #736 #830 #867 #892
- Increased
max_lenforsubnet_ttype from40to42. #745 - Improved the regex for
ip_ttype. #745 - Updated the
datetime_tvalidation regex to enable validation of timestamps, and to ensure that timestamps not matchingRFC-3339are not considered valid. #753 - Added version information to the native extensions. #881
- Updated caption and description of Observable type -
File Hashto readHash. #900 - New Extension registration for DataBee. #912
- Changed data-type of
type_uidtolong_tfromint_t. #928
OCSF Schema Release v1.0.0
The OCSF Schema Release v1.0.0!
Note: New release package was cut from the v1.0.0 branch. See Issue #793 for details