Skip to content

Releases: ocsf/ocsf-schema

1.9.0

Choose a tag to compare

@floydtree floydtree released this 03 Aug 14:39
Immutable release. Only release title and notes can be modified.
856d462

[v1.9.0] - Aug 3rd, 2026

Added

  • Categories

  • Event Classes

    1. Added user_management and role_management. #1603
    2. Added clipboard_activity. #1655
    3. Added device_power_state_activity class to capture power state changes of a device. #1624
  • Profiles

    1. Added record_integrity profile that adds a cryptographic attestation over the event (integrity, authenticity, and non-repudiation), applied at the base event so any class can carry it. #1661
    2. Added optional delegation attribute to the ai_operation profile, linking data-plane actions to the delegated authority under which they were performed. #1665
  • Objects

    1. Added delegation object describing a durable authorization context issued by a principal to a delegate. #1665
    2. Added job_action object to describe an action that job can perform. #1597
    3. Added job_trigger object to describe a condition when job performs its action. #1597
    4. Added cpu_info object for CPUs (array name cpu_info_list). #1630
    5. Added iam_role object for user, role and group management. #1603
    6. Added clipboard and clipboard_item object for clipboard activity. #1655
    7. Added dns_resource_record object to represent an RFC 1035 resource record, used across Answer, Authority, and Additional sections. #1634
    8. Added dns_section object to represent a DNS message section containing supplementary resource records and an optional TSIG record. #1634
    9. Added tsig object to represent a TSIG (Transaction Signature) record with structured fields for security analytics: algorithm, key_name, error_id, and error. #1634
    10. Added download_info object with information pertaining to a downloaded file. #1658
    11. Added note object to capture a comment along with the user who made the comment and when the note was modified. #1670
    12. Added ai_agent object representing an autonomous AI agent, distinct from the existing agent object (which models security sensors such as EDR, DLP, APM). #1641
    13. Added attestation object carrying a fingerprint of and digital signatures over an event, with optional tamper-evident chain attributes (prev_event, chain_uid) and an authority_uid identifying the attesting party. #1661
    14. Added prev_event object referencing the previous event in a tamper-evident chain by its fingerprint (content binding) together with uid and type_uid (retrieval). #1661
    15. Added sensor_info object including the sensor_layer_id and related attributes. #1703
  • Observables

    1. Set iam_role.name (49) & iam_role.uid (50) as Observable types. #1603
  • Platform Extensions

  • Dictionary Attributes

    1. Added attestation_list, prev_event, authority_uid, and chain_uid attributes for the record_integrity profile. #1661
    2. Added com_class_uuid attribute to reflect Class Identifier of a Component Object Model. #1597
    3. Added event_codes that is a set of event identifiers. #1597
    4. Added log_sources that is a set of log systems. #1597
    5. Added job_actions that describes a set of actions that job can perform. #1597
    6. Added job_triggers that describes a set of conditions when job performs its actions. #1597
    7. Added updated_job that reflects the attempted or the actual updated job. #1597
    8. Added properties that is a set of characteristics associated with an entity. #1597
    9. Added speed_mhz for compute unit clock speed in MHz. #1630
    10. Added cpu_info_list as an array of cpu_info objects. #1630
    11. Added iam_role, iam_roles, updated_role, updated_group, updated_user attributes. #1603
    12. Added updated_entity, updated_resources, and updated_web_resources attributes for reporting intended or actual post-update state. #1618
    13. Added initiator and initiator_id attributes for identifying which endpoint initiated a network communication, with generic Unknown (0) and Other (99) enums. #1598
    14. Added transaction_id, query_additional, response_additional, authority, and key_name dictionary attributes for DNS Activity restructuring. #1634
    15. Added peripheral_devices for a set of peripherals. #1645
    16. Added serialization and serialization_id attributes to record the canonical serialization or signing-envelope scheme used to produce the signed bytes. #1662
    17. Added binary_data, contents, clipboard_native_type, string_data. #1655
    18. Added uid_numeric attribute to enable a unique identifier that is numeric to be represented natively using the long_t data type. #1643
    19. Added download_info attribute to file object. #1658
    20. Added notes attribute as an array of Note objects. #1670
    21. Added prompt_text and response_text attributes for capturing the input prompt text and model response text of an AI message. #1674
    22. Added ai_agent attribute referencing the new ai_agent object. #1641
    23. Added hosted_ai_agent_list attribute for enumerating AI agents hosted by a process or other runtime. #1641
    24. Added charter attribute (file type) for documents defining the role, scope, and operating bounds of an entity. #1641
    25. Added criticality_id dictionary attribute with a four-level criticality enum Low (1), Medium (2), High (3), and Very High (4), plus generic Unknown (0) and Other (99) enums, paired with the existing criticality sibling. #1693
    26. Added sensor_layer_id and sensor_layer sibling. #1703
    27. Added sensor_info_list as an array of type sensor_info for the analytic object. #1703
    28. Added delegation and issuer_uid attributes supporting the delegation object and ai_operation profile. #1665

Improved

  • Categories

  • Event Classes

    1. Added updated_job in Scheduled Job Activity class to reflect the actual or attempted state of the job upon update activity. #1597
    2. Added iam_role and role management support to group_management, authorize_session. Filled out the group_management class with complete lifecycle as well as added resources, policies to the discrete activities. #1603
    3. Added updated_* attributes to Entity Management and Web Resources Activity for class-specific update result reporting. #1618
    4. Added initiator_id and initiator to Network Activity with network-specific enums Source Endpoint (1) and Destination Endpoint (2), and updated src_endpoint and dst_endpoint descriptions to reflect bi-flow and asymmetric flow scenarios. #1598
    5. Added transaction_id, opcode_id/opcode, flag_ids/flags, authority, query_additional, and response_additional to DNS Activity. #1634
    6. Extended activity_id attribute in HTTP Activity to cover all methods in IANA HTTP Method Registry. #1654
    7. Added users to group_management to replace deprecated user. #1666
    8. Added application attribute to Application Lifecycle to replace the deprecated app attribute, resolving the mismatch where app (captioned "Application") was typed as the product object. #1702
    9. Added notes to finding and `incident_fin...
Read more

1.8.0

Choose a tag to compare

@mikeradka mikeradka released this 18 Mar 14:49
6fa6499

[v1.8.0] - Mar 16th, 2026

Added

  • Categories

  • Event Classes

  • Profiles

    1. Added ai_operation profile with essential attributes for AI operation event mapping. #1488
    2. Added macos/macos_users profile with egid and euid attributes. This profile is used by the process object. #1538
  • Objects

    1. Added ai_model object with core fields (name, ai_provider, version) for AI operation events. #1488
    2. Added message_context object for AI system interactions with role-based identification and token usage metrics (prompt_tokens, completion_tokens, total_tokens). #1488
    3. Added token object for API tokens, client tokens, and API keys used in API activity events. #1429
    4. Added gpu_info object for GPU's (array name gpu_info_list). #1527
    5. Added privilege_info object for describing specific privileges, actions, or permissions with usage status and type_id enum (Read, Write, Execute). #1581
    6. Added privilege_attack_info object for grouping privileges by potential MITRE ATT&CK techniques. #1581
    7. Added service_privilege_analysis object for privilege analysis results per cloud service or namespace. #1581
    8. Added packet object for network packets (array name packet_list). #1569
  • Observables

  • Platform Extensions

    1. Added macos extension (uid 3). This extension adds the macos/macos_users profile and patches the process object to add this profile. #1538
  • Dictionary Attributes

    1. Added ai_provider attribute for AI model identification. #1488
    2. Added ai_role_id, ai_role attributes for AI communication context with proper sibling relationship. #1488
    3. Added prompt_tokens, completion_tokens, total_tokens attributes for AI token usage metrics. #1488
    4. Added embedding_model attribute for AI retrieval systems. #1488
    5. Added imported_symbols attribute for reporting an executable file's imports. #1553
    6. Added Imphash (18) enum to the algorithm_id attribute of the fingerprint object. #1553
    7. Added token as a token object. #1429
    8. Added bus_type Derived from bus_type_id. #1527
    9. Added bus_type_id Identifier for the bus/interface standard. #1527
    10. Added cores Number of cores. #1527
    11. Added vram_size Installed VRAM. #1527
    12. Added vram_mode Derived from vram_type_id. #1527
    13. Added vram_mode_id Identifier for VRAM type. #1527
    14. Added total_queued_duration to track how long an event spent in a queue. #1536
    15. Added department and is_on_premises_sync_enabled for ldap and Entra ID support. #1584
    16. Added is_disabled and is_locked as type boolean_t with a "See specific usage" description. #1583
    17. Added all_privileges_unused boolean attribute indicating whether all privileges in a group are unused. #1581
    18. Added analyzed_privileges_count integer attribute for the total count of analyzed privileges. #1581
    19. Added attack singular attribute for MITRE ATT&CK details (complements existing attacks array). #1581
    20. Added is_unused boolean attribute indicating whether an item is unused. #1581
    21. Added privilege_attack_info, privilege_attack_info_list attributes for privilege-to-attack mappings. #1581
    22. Added privilege_info, privilege_info_list attributes for specific privilege information. #1581
    23. Added service_privilege_analysis, service_privilege_analysis_list attributes for service-level privilege analysis. #1581
    24. Added total_potential_attacks_count integer attribute for count of privileges mapping to attack techniques. #1581
    25. Added read_count, write_count, and execute_count integer attributes. #1581
    26. Added pool attribute of type group. #1521
    27. Added mac_vendor as string_t. #1575
    28. Added network_observation_point as type network_endpoint. #1571
    29. Added packet as a packet object. #1569
    30. Added packet_list as an array of packet objects. #1569
    31. Added encoding, encoding_id attributes for data encoding representation. #1569
    32. Added format, format_id attributes for data format identification. #1569
    33. Added source_id normalized identifier for the source. #1569
    34. Added sequence_number attribute for ordering within a sequence. #1569
    35. Added start_offset attribute for the starting offset. #1569
    36. Added end_offset attribute for the ending offset. #1569

Improved

  • Categories

  • Event Classes

    1. Add app_protocol_name to Network Activity class with clarified description for deep packet inspection. #1557
    2. Enhanced app_name description in Network Activity class to clarify network application identification by tools such as NBAR. #1557
    3. Added ai_operation profile to process_activity event class. #1578
    4. Added network_observation_point attribute to the base Network event. #1571
    5. Added packet_list to network event class. #1569
  • Profiles

  • Objects

    1. Extended database object with AI-specific database types (Vector (7), Knowledge Graph (8)) and embedding_model field for AI retrieval systems. #1488
    2. Added signatures to the file object. #1546
    3. Expanded on created_time attribute description within the related_event object. 1552
    4. Added imported_symbols attribute to the file object. #1553
    5. Updated fingerprint object description. Updated the descriptions of algorithm, algorithm_id, and value attributes in the fingerprint object. #1560
    6. Added fingerprints attribute to the network_endpoint object. #1560
    7. Added mac_vendor to the endpoint object. #1575
    8. Added token as an attribute to the api object. #1429
    9. Added created_time attribute back to the authentication_token object with improved description. #1429
    10. Added provider to the resource_details object via cloud profile. #1566
    11. Added resource attribute to the check object to describe details about the resource that the check evaluated. #1574
    12. Added total_queued_duration to the metadata object. #1536
    13. Added is_on_premises_sync_enabled to Account. Added department to ldap_person. Added ActiveDirectory Account to Account.type. #1584
    14. Added is_disabled and is_locked attributes to the account object. #1583
    15. Added analyzed_privileges_count, service_privilege_analysis_list, and total_potential_attacks_count attributes to the permission_analysis_result object for detailed privilege analysis. #1581
    16. Added macos/macos_users profile to the process object via macos extension patch. [#1538]...
Read more

1.7.0

Choose a tag to compare

@mikeradka mikeradka released this 14 Nov 21:43
dc6359b

[v1.7.0] - Nov 14th, 2025

Added

  • Event Classes

    1. Added Peripheral Activity event class to the System category. #1471
  • Objects

    1. Added reporter object. #1476
    2. Added Windows extension to the process object.
    3. Added the function_invocation and parameter objects. #1497
  • Observables

    1. Set network_endpoint.uid as an Observable type - type_id: 48. #1502
  • Dictionary Attributes

    1. Added vendor_id_list as a string_t array. #1471
    2. Added post_value, pre_value and return_value as string_t. #1497
    3. Added launch_type_id enum and launch_type sibling. #1517
    4. Added log_source log_source_uid log_format as string_t. #1483

Improved

  • Event Classes

    1. Added auth_factors as an attribute to the Account Change class and updated related activity names. #1455
    2. Added Invoke as an activity_id value for the Module Activity class. #1497
    3. Added launch_type_id and launch_type as attributes to the Process Activity event class. #1517
    4. Added descriptions to values of activity_id enum in Process Activity event class. #1517
    5. Added missing context classification to windows_service_activity.win_service. #1531
    6. Added missing requirement to process_activity.launch_type. #1531
    7. Added cumulative_traffic attribute to the base Network event. Updated traffic description. #1529
  • Objects

    1. Added type, type_uid, and vendor_id_list to the peripheral_device object. #1471
    2. Relaxed the class attribute requirement to optional in the peripheral_device object. #1471
    3. Set the vendor_name requirement to recommended in the peripheral_device object. #1471
    4. Added reporter to the metadata object. #1476
    5. Added event_uid and type_uid to the observable object. #1503
    6. Set load_type_id requirement to recommended in the module object. #1497
    7. Added at_least_one constraint on load_type_id and function_name in the module object. #1497
    8. Modified descriptions in the module object to accommodate Module Activity: Invoke event. #1497
    9. Added function_invocation to the module object. #1497
    10. Relaxed the file attribute requirement to optional in the job object. #1509
    11. Relaxed the name and uid requirement to recommended with at_least_one constraint in the extension object. #1511
    12. Added hosting_process, service_file and service_dll_file to the win_service object.
    13. Added hosted_services, array to the process object.
    14. Added source, type, log_source, original_event_uid,log_format, transmit_time to metadata. log_format to logger#1483
    15. Added start_time, end_time and timespan to the network_traffic object. Updated network_traffic description. #1529
  • Dictionary Attributes

    1. Added Local (4) enum to the direction_id attribute. #1475
    2. Added Atom (38) enum as an available type_id for win_resource object. #1477
    3. Updated reference descriptions/urls for win_resource types, including Directory (1), Event (2), Timer (3), Device (4), Mutant (5), File (7), Token (8), Thread (9), Section (10), WindowStation (11), Driver (15), IoCompletion (16), Controller (17), SymbolicLink (18), WmiGuid (19), Process (20), Profile (21), Desktop (22), KeyedEvent (23), Adapter (24), Callback (27), Semaphore (28), Job (29), ALPC Port (32), SAM_ALIAS (33), SAM_GROUP (34), SAM_USER (35), SAM_DOMAIN (36), SAM_SERVER (37), and Atom (38). #1477
    4. Added hosted_services to the Windows extension to the process object.
    5. Added multiple values to the state_id enum attribute for the digital_signature object. #1520
    6. Added WFP Filter (39), WFP Callout (40), WFP Layer (41), WFP Sub-layer (42), WFP Provider (43) and WFP Provider Context (44) WindowsFilteringPlatform-related enums as an available type_ids for win_resource object. #1530
    7. Added cumulative_traffic of network_traffic type. #1529

Misc

  1. Updated description for the peripheral_device object and the vendor_name attribute within it. #1471
  2. Corrected the deprecation note for the Web Resource Access Activity event class. #1492

1.6.0

Choose a tag to compare

@floydtree floydtree released this 01 Aug 19:10
d0cd8a0

[v1.6.0] - Aug 1st, 2025

Added

  • Event Classes

    1. Added IAM Analysis Finding event class to the Findings category. #1389
  • Dictionary Attributes

    1. Added from_list, from_mailboxes,reply_to_list, return_path, sender and sender_mailbox. #1454
    2. Added access_level, programmatic_credentials, last_authentication_time, access_analysis_result, last_used_time, accessors, granted_privileges, identity_activity_metrics, password_last_used_time, access_type, permission_analysis_results, additional_restrictions, unused_privileges_count, condition_keys, applications, role, role_id. #1389
    3. Added reg_binary_data, reg_integer_data, reg_string_data, reg_string_list_data to Windows extension. #1468
    4. Added is_src_dst_assignment_known as a boolean. #1464
  • Objects

    1. Added access_analysis_result, additional_restriction, identity_activity_metrics, permission_analysis_result, programmatic_credential. #1389
    2. Added port_info object. #1466

Improved

  • Event Classes

    1. Added Disconnect and Reconnect activities in the RDP Activity class. #1415
    2. Added user as an attribute to the RDP Activity class. #1419
    3. Added raw_data_hash as an attribute to base_event. #1420
    4. Added Add Subgroup, and Remove Subgroup activities in the Group Management class. #1447
    5. Added MTA Relay activity and to/from attributes to the Email Activity class. #1454
    6. Added http_request and http_response objects to the File Hosting Activity Class #1458
    7. Added Account Switch activity_id to the Authentication class. Added account_switch_type and account_switch_type_id attributes to the Authentication class. #1460
    8. Added is_src_dst_assignment_known attribute to Network Activity class. #1464
  • Objects

    1. Added more algorithm_id values and references to the fingerprint object. #1412
    2. Added xxHash H3's 64-bit and 128-bit variants to algorithm_id on the fingerprint object. #1420
    3. Added Service to user type_id enum. #1428
    4. Added Deleted to finding status_id enum. #1437
    5. Added status to related_event object. #1434
    6. Added attack_graph to finding_info. #1436
    7. Added Executable File to file type_id enum. Added is_readonly as an optional attribute. #1438
    8. Added ptid (type long_t) to process and deprecated tid (type integer_t) #1450
    9. Added state_id and state to analytic. #1448
    10. Added from_list, from_mailboxes,reply_to_list, return_path, sender and sender_mailbox attributes to email object. #1454
    11. Added role, role_id to resource_details object, type to policy object, #1389
    12. Added is_truncated and untruncated_size to metadata, logger objects. #1461
    13. Added open_ports to the network_interface object. #1466
    14. Added reg_binary_data, reg_integer_data, reg_string_data, reg_string_list_data to reg_value object in Windows extension. #1468

Misc

  1. Fixed spelling errors throughout the project and added spell checking to the CI linter workflow. #1411
  2. Improved description of the Application Error class. #1424
  3. Fixed links to ocsf-docs repo #1453
  4. Set device.uid as an Observable type - type_id: 47 #1446
  5. Improved descriptions of src_endpoint and dst_endpoint attributes in Network Activity class. #1464
  6. Improved the description of the bytestring_t data type. #1468

Deprecated

  1. Deprecated usage of group attribute in favor of groups in the databucket object. #1344
  2. Deprecated usage of credential_uid attribute in favor of programmatic_credentials in the user object. #1389
  3. Deprecated usage of items 3 and 4 in the type_id enum in account object, in favor of the type_id enum in the user object. #1389
  4. Deprecated item 9 (REG_QWORD_LITTLE_ENDIAN) in the type_id enum in the reg_value object. Its presence was an error. #1468

1.5.0

Choose a tag to compare

@mikeradka mikeradka released this 28 Apr 18:10
78bf68a

[v1.5.0] - April 28th, 2025

Added

  • Event Classes

    1. Added Application Security Posture Finding event class to the Findings category. #1357
    2. Added Live Evidence Info event class to Discovery category. #1382
  • Dictionary Attributes

    1. Added boot_uid as a string_t. #1335
    2. Added cpid as a uuid_t. #1246
    3. Added raw_data_size as a long_t. #1347
    4. Added assessments as an array of assessment objects. #1343
    5. Added meets_criteria as a boolean_t. #1343
    6. Added display_name attribute as a string_t. #1341
    7. Added is_directed as a boolean_t, relation as a string_t, query_language & query_language_id a sibling pair. #1343
    8. Added resource_relationship of type graph, nodes of type node, edges of type edge. #1343
    9. Added fix_coverage as string_t and fix_coverage_id as int_t. #1350
    10. Added eid, iccid, and meid as string_t. #1346
    11. Added is_backed_up, is_mobile_account_active, and is_shared as boolean_t. #1346
    12. Added detection_pattern_type an detection_pattern_type_id as a string_t and int_t respectively. #1310
    13. Added external_id as an string_t. #1310
    14. Added intrusion_sets as an array string_t. #1310
    15. Added uploaded_time as an timestamp_t. #1310
    16. Added isp_org as string_t. #1351
    17. Added ldap protocol to auth_protocol_id enum. #1359
    18. Added observation_parameter, observation_type, observed_pattern as string_t and occurrences as an array of occurrence_details. #1358
    19. Added analysis_targets as an array of type analysis_target. #1371
    20. Added num_volumes, num_infected as int_t, unique_malware_count, volume as string_t. #1373
    21. Added end_column and start_column as integer_t. #1357
    22. Added dependency_chain, exploit_requirement, and exploit_type as string_t. #1357
    23. Added exploit_ref_url, license_url, package_manager_url, and uri as url_t. #1357
    24. Added transformation_info_list #1392
    25. Added authentication_token as authentication_token, kerberos_flags as string_t and is_renewable as boolean_t. #1391
    26. Added tickets as an array of ticket objects. #1402
    27. Added is_read as boolean_t. #1406
    28. Added query_type and query_type_id as string and integer_t respectively. #1382
    29. Added tcp_state_id as integer_t. #1382
    30. Added query_evidence as type query_evidence. #1382
    31. Added checks as type check. #1369
  • Objects

    1. Added assessment object to capture evaluations/assessments of configurations/signals. #1343
    2. Added node, edge, graph objects. #1343
    3. Added anomaly, anomaly_analysis, baseline, observation objects. #1358
    4. Added trait object. #1363
    5. Added mitigation object. #1348
    6. Added analysis_target object. #1371
    7. Added malware_scan_info object. #1373
    8. Added application object. #1357
    9. Added campaign object #1310
    10. Added threat_actor object #1310
    11. Added transformation_info #1392
    12. Added authentication_token object. #1391
    13. Added query_evidence object. #1382
    14. Added check object #1369
  • Observables

    1. Added process_entity.uid as an Observable type - type_id: 39. #1380
    2. Added email.subject and email.uid as an Observable types - type_id: 40 and type_id: 41. #1380
    3. Added message_uid as Observable type - type_id: 42. #1380
    4. Added reg_value.name as an Observable type - type_id: 43. #1380
    5. Added advisory.uid as Observable type type_id: 44. #1357
    6. Updated resource_details.uid, web_resource.uid, and win_resource.uid to be observable type_id: 10 #1394
    7. Added file_path_t as an Observable type - type_id: 45 and marked fields as this type #1381
      • lineage dictionary attribute
      • affected_package.path object attribute
      • file.path object attribute
      • image.path object attribute
      • kernel.path object attribute
      • malware.path object attribute
      • process_entity.path object attribute
    8. Added extensions/windows/reg_key_path_t as an Observable type - type_id: 46 and marked fields as this type #1381
      • reg_key.path object attribute
      • reg_value.path object attribute

Improved

  • Event Classes

    1. Added assessments to config_state. #1343
    2. Added raw_data_size to base_event. #1347
    3. Added anomaly_analyses to detection_finding. #1358
    4. Added Detect value for activity_id in Remediation events. #1362
    5. Added resources to user_access. #1374
    6. Added malware_scan_info, malware to detection_finding. #1373
    7. Added authentication_token to authentication. #1391
  • Objects

    1. Added boot_uid to device object. #1335
    2. Relaxed constraint to provide email_addr, phone_number, or security_questions on auth_factor. #1339
    3. Added cpid to process_entity object. #1246
    4. Added boot_uid to device object. #1335
    5. Added meets_criteria and policy to assessment object. #1343
    6. Added assessments to compliance object. #1343
    7. Added data to policy object. #1343
    8. Added display_name attribute to the user and ldap_person objects. #1341
    9. Added resource_relationship to resource_details object. #1343
    10. Added fix_coverage, fix_coverage_id to vulnerability object. #1350
    11. Added eid, iccid, is_backed_up, is_mobile_account_active, is_shared, and meid to device. #1346
    12. Added is_backed_up to resource_details. #1346
    13. Added isp, isp_org to network_endpoint & whois objects. #1351
    14. Reduced requirement of standards to recommended in the compliance object. #1352
    15. Updated MITRE attack, tactic, technique, subtechnique captions, descriptions, references to include MITRE ATLAS. Used standard requirements for _entity extended objects. #1355.
    16. Added name, resources, uid, verdict, and verdict_id to evidences. #1337
    17. A...
Read more

v1.4.0

Choose a tag to compare

@mikeradka mikeradka released this 05 Feb 15:20
6109cc5

[v1.4.0] - January 31st, 2025

Added

  • Categories

    1. Added new Unmanned Systems Category. #1169
  • Event Classes

    1. Added OSINT Inventory Info event class to the Discovery category. #1154
    2. Added Script Activity event class to the System category. #1159
    3. Added Startup Item Query event class. #1119
    4. Added Drone Flights Activity event class to the Unmanned Systems category. #1169
    5. Added Cloud Resources Inventory Info event class to the Discovery category. #1250
    6. Added Airborne Broadcast Activity event class to the Unmanned Systems category. #1253
    7. Added Application Error event class to the Application Activity category. #1299
  • Profiles

    1. Added incident profile. #1293
  • Dictionary Attributes

    1. Added has_mfa as a boolean_t. #1155
    2. Added environment_variables as an array of environment_variable object. #1172
    3. Added forward_addr as an email_t. #1179
    4. Added related_cves, related_cwes as arrays of cve, cwe objects respectively. #1176
    5. Added exploit_last_seen_time as a timestamp_t. #1176
    6. Added is_alert as a boolean_t. #1179
    7. Added working_directory as a string_t. #1195
    8. Added is_deleted as a boolean_t. #1196
    9. Added body_length as an integer_t. #1200
    10. Added is_public as a boolean_t. #1208
    11. Added tags, control_parameters as an array of key_value_object object. #1219
    12. Added community_uid as a string_t. #1202
    13. Added location to the managed_entity object. #1169
    14. Added unmanned_system_operator to the dictionary, extends user. #1169
    15. Added locations to the dictionary, an array type of the location object, used within the new operating_area object. #1169
    16. Added altitude_ceiling, altitude_floor, geodetic_altitude, aerial_height, horizontal_accuracy, pressure_altitude, radius, speed, track_direction, and vertical_speed all to support operating_area and unmanned_aerial_system objects. #1169
    17. Added imei_list as an array string_t. #1225
    18. Added is_encrypted as boolean_t; column_name, cell_name, storage_class, key_uid, json_path as string_t & column_number, row_number, page_number, record_index_in_array as integer_t. #1245
    19. Added group_provisioning_enabled, scim_group_schema, user_provisioning_enabled, scim_user_schema, scopes, idle_timeout, login_endpoint, logout_endpoint, and metadata_url entries to the dictionary to support the new scim and sso objects. #1239
    20. Added new 11: Basic Authentication enum value to auth_protocol_id. #1239
    21. Added values as an array of string_t. #1251
    22. Added files urls and message_trace_uid. #1259
    23. Added kernel_release as a string_t. #1249
    24. Added os_machine_uuid as a uuid_t. #1268
    25. Added sbom, author, related_component, relationship, relationship_id and software_component to support SBOMs. #1262
    26. Added related_events_count as an int_t. #1271
    27. Added event_uid as a string_t. #1312
    28. Added debug attribute as a string_t array, used in the metadata object. #1308
    29. Added ancestry as a list of process_entity. #1317
    30. Added internal_name as a string_t. #1322
    31. Added cc_mailboxes, from_mailbox, to_mailboxes, delivered_to_list and reply_to_mailboxes. #1307
    32. Added flag_history and bytes_missed attributes. #1316
  • Objects

    1. Added environment_variable object. #1172, #1288
    2. Added advisory object. #1176
    3. Added a generic key_value_object object. #1219
    4. Added unmanned_aerial_system and unmanned_system_operating_area objects. #1169
    5. Added a long_string object. #1228
    6. Added discovery_details, encryption_details, occurrence_details objects. #1245
    7. Added scim object. #1239
    8. Added sso object. #1239
    9. Added vendor_attributes object. #1257
    10. Added aircraft object. #1253
    11. Added software_component and sbom objects. #1262
    12. Added drive_type and drive_type_id objects. #1287
    13. Added cpu_architecture and cpu_architecture_id objects. #1278
    14. Added process_entity object. #1317

Improved

  • Event Classes

    1. Added evidences to compliance_finding class. #1157
    2. Added is_alert to detection_finding and data_security_finding classes. #1178
    3. Added risk_details to data_security_finding class. #1178
    4. Removed constraint from group_management class. #1193
    5. Added Archived|5 as an enum item to status_id attribute in Findings classes. #1219
    6. Added a Trace activity_id to the Email Activity class. #1252
    7. Added a message_trace_uid to the Email Activity class. #1259
    8. Added vendor_attributes to all Findings Category classes. #1257
    9. Added sbom to Software Inventory Info class. #1262
    10. Relaxed requirements on the dst_endpoint attribute in the network_activity event class and added an at_least_one constraint with src_endpoint and dst_endpoint. #1274
    11. Relaxed requirements on the http_request and http_response attributes in the http_activity event class and added an at_least_one constraint with these attributes. #1274
    12. Added host profile to base_event and removed this profile elsewhere in the event hierarchy. #1280
    13. Added the actor attribute to the IAM base event. #1280
    14. Added security_control profile to base_event and removed this profile elsewhere in the event hierarchy. #1281
    15. Added policies to Account Change class. #1282
    16. Added Unlock activity to account_change class. #1285
    17. Added incident profile to finding to affect classes that extend it. #1293
    18. Added keyboard_info object to RDP event class. #1313
    19. Added attributes and a new Activity ID to the File Hosting Activity class for network file share services and authorization check result. Activity ID added: 17 - "Access Check". Optional context group attributes added: access_list, access_mask, access_result, share, share_type, and share_type_id. [#...
Read more

v1.3.0

Choose a tag to compare

@mikeradka mikeradka released this 01 Aug 20:20
c8bde8c

[v1.3.0] - August 1st, 2024

Added

  • Categories

    1. Added Remediation category. #1066
  • Event Classes

    1. Added Event Log Activity event class to the System Activity category. #1014
    2. Added Remediation Activity, File Remediation Activity, Process Remediation Activity, Network Remediation Activity event classes to the Remediation category. #1066
    3. Added Windows Service Activity event class to the System Activity category via Windows extension. #1103
    4. Added Software Inventory Info event class to the Discovery category. #1134
  • Profiles

    1. Added osint Profile based on the osint object. #992
  • Objects

    1. Added d3fend, d3f_tactic, d3f_technique MITRE objects. #1066
    2. Added ja4_fingerprint object. #834
    3. Added ja4_fingerprint_list as a list of ja4_fingerprint objects. #834
    4. Added ticket object. #1068
    5. Added osint object. #992
    6. Added signatures object, an array of signature objects. #992
    7. Added whois object. #992
    8. Added domain_contact and array-typed domain_contacts object for use with whois object. #992
    9. Added Windows Service object to the Windows extension. #1103
    10. Added timespan object. #1125

Improved

  • Categories

    n/a
  • Event Classes

    1. Added file_result to File Hosting Activity. #1045
    2. Added entries to injection_type_id enum (Process Activity) and activity_id enum (Memory Activity). #1060
    3. Added a Restart, Enable, Disable, and Update activity_id to the Application Lifecycle class. #1064
    4. Added ja4_fingerprint_list to base network event class. #834
    5. Added ticket to Incident Finding event class. #1068
    6. Added new activities Enroll, Activate, Deactivate, Suspend, and Resume to the Entity Management class. #1095
    7. Added new activity Listen to Network Activity and relax requirement of src_endpoint. #1147
    8. Added state, state_id to Device Config State Change. #1143
    9. Added resources attribute to Vulnerability Finding and Compliance Finding. #1150
  • Profiles

    n/a
  • Objects

    1. Added ext to File object. #1046
    2. Added account, device, email, url, user to evidences in detection finding. #1000
    3. Added state_id, state to Digital Signature object. #1069
    4. Added domain to Uniform Resource Locator object. #1096
    5. Added reg_key and reg_value to Evidence Artifacts object. #1078
    6. Added type_id and associated entity objects to Managed Entity. #1094
    7. Added vendor_name, type, type_id to object package. #1093
    8. Added router, ids, and ips entries to type_id enum in the Endpoint object. #1121
    9. Added job to Evidence Artifacts object. #1130
    10. Added ip to object load_balancer. #1138
    11. Added cpe_name and hash to Software Package object. #1142
    12. Added avg_timespan to the kb_article object. #1125
    13. Added created_time,desc, short_desc, reputation, src_url to enrichment object. #1149
    14. Added compliance_references, compliance_standards to the compliance object. #1110

Bugfixes

  1. Fixed the host profile construction in patch_state event class. #1087
  2. Removed the optional requirement overrides for name and uid in _resource as they are part of a constraint. #1087
  3. Fixed declarations of data_lifecycle_state_id, integrity, opcode_id, risk_level, and analytic.type_id. #1111

Deprecated

  1. Deprecated resource in Vulnerability Finding and Compliance Finding event classes in favor of resources. #1150

Breaking changes

n/a

Misc

  1. Colorized validator output #1048
    • Updated the GitHub workflow for the ocsf-validator to print colorized output.
  2. Clarify how to reference profiles in metadata #1056
    • Updated the description of metadata.profiles to clarify the correct way to reference a profile in that list.
  3. Added a gitignore file. #1071
  4. New Extension registration for Cisco #1074
  5. Cleaned up MITRE trademarks and registrations for captions and descriptions.
  6. Declared enums in dictionary.json have sane "0" (Unknown) and "99" (Other) declarations and descriptions where appropriate #1111
  7. Adds support for suppress_checks controls in attributes to allow tools to automatically validate conventions #1063
    • Updated several attributes that do not follow conventions to disable linting for them
  8. Added credential_uid as an Observable type - type_id: 19. #1137
  9. New Extension registration for US Gov #1140
  10. Enum definitions are now refactored such that generic enum descriptions have "See specific usage" in the description #1146

v1.2.0

Choose a tag to compare

@floydtree floydtree released this 23 Apr 16:16
7234a33

[v1.2.0] - April 23rd, 2024

Added

  • Categories

    n/a

  • Event Classes

    1. Added Data Security Finding event class. #953
    2. Added File Query event class. #967
    3. Added Folder Query event class. #967
    4. Added Group Query event class. #967
    5. Added Job Query event class. #967
    6. Added Kernel Object Query event class. #967
    7. Added Module Query event class. #967
    8. Added Network Connection Query event class. #967
    9. Added Networks Query event class. #967
    10. Added Peripheral Device Query event class. #967
    11. Added Prefetch Query event class. #967
    12. Added Process Query event class. #967
    13. Added Registry Key Query event class. #967
    14. Added Registry Value Query event class. #967
    15. Added Service Query event class. #967
    16. Added Session Query event class. #967
    17. Added User Query event class. #967
    18. Added Tunnel Activity event class. #1012
  • Profiles

    1. Added data_classification profile. #998
  • Objects

    1. Added auth_factor object. #949
    2. Added data_security object. #953
    3. Added autonomous_system object. #978
    4. Added agent object. #987
    5. Added data_classification object. #998
  • Observables

    1. Added port_t subnet_t cmd_line country pid cwe.uid cve.uid user_agent enum items. #1035
  • Platform Extensions

    n/a

Improved

  • Categories

    n/a

  • Event Classes

    1. Added auth_factors array to Authentication event class. #949
    2. Modified all classes such that primary attributes are at least recommended. #974
    3. Added src_endpoint, http_request attributes to all IAM category classes. #976
    4. Added autonomous_system to network_endpoint objects. #978
    5. Added List, Encrypt and Decrypt activities to datastore event class. #989
    6. Added file attribute to http, rdp, ssh, and ftp event classes. #985
    7. Added a Preauth activity_id to the Authentication class. #1018
    8. Added the Security Control profile to the Datastore Activity class. #1030
    9. Added risk_details to Detection Finding. #1032
  • Profiles

    n/a

  • Objects

    1. Expanded type_id enum in analytic object to account for more use-cases: #953
      • 5 - Fingerprinting
      • 6 - Tagging
      • 7 - Keyword Match
      • 8 - Regular Expressions
      • 9 - Exact Data Match
      • 10 - Partial Data Match
      • 11 - Indexed Data Match
    2. Added lat, long, geohash attributes to location object. #971.
    3. Added risk_score, risk_level_id, risk_level to user object. Issue #972.
    4. Added app_name, app_uid to actor object. Issue #966, PR #979.
    5. Added container, database, databucket to the evidences object. #984
    6. Added owner to endpoint object. #987
    7. Added is_applied Boolean attribute to policy object. #987
    8. Added agent_list as an array of agent objects. #987
    9. Added policies object as an array of policy objects. #987
    10. Added agent_list to endpoint object. #987
    11. Added labels to the Account object. #1028
    12. Added data_classification profile to database, databucket, email, file, metadata, product, resource_details and web_resource objects. #998
  • Platform Extensions

    n/a

Bugfixes

  1. Changed datatype of priority attribute, from integer_t to string_t #959
  2. Extended email_t regexp to allow characters from RFC5322 before @.
  3. Updated logon_type_id enum to include 0 as Unknown. Added enum item 1 as System. #1055

Deprecated

  1. Deprecated coordinates attribute in favor of specific lat, long attributes. #971
  2. Deprecated invoked_by attribute in the Actor object in favor of app_name. #979.

Breaking changes

n/a

Misc

  1. New Extension registration for Sedara. #951
  2. Corrected punctuation for the transmit_time attribute. #1001
  3. New ways to define observables in the metaschema. #982 and #993
    • (Current) Dictionary types using observable property in dictionary types. This allows defining all occurrences of attributes of this type as an observable.
    • (Current) Objects using top-level observable property. This allows defining all occurrences attributes whose type is this object as an observable.
    • (New) Dictionary attributes using observable property in attribute. This allows defining all occurrences of this attribute as an observable.
    • (New) Object-specific attributes using observable property class's attributes. This allows defining object attributes as observables only within instances of this specific object.
    • (New) Event class-specific attributes using observable property class's attributes. This allows defining class attributes as observables only within instances of this specific class.
    • (New) Event class-specific attribute paths using top-level observables property. The observables property holds an object mapping from a dotted attribute path to an observable type_id. This allows defining an observable only within instances of this specific class, and only for the attributes at these paths, even for attributes that are within nested objects and arrays. This can also be used for top-level class attributes, which can be more convenient that defining a class attribute observable for classes that extend another, but don't otherwise change an attribute definition.
  4. Metaschema improvements. #993
    • Detect unexpected top-level properties in object and event class definitions. This was added at this point to detect invalid observable definitions: invalid observable property in event classes, and invalid observables property in objects.
    • Remove hard-coded list of categories from metaschema/categories.schema.json, leaving this to the ocsf-validator. This change makes testing with alternate schemas that may add extra categories easier, as well as making it possible to validate private extensions that contain new categories.
  5. Metaschema error reporting #1027
    • Updated the definition of object and event so that metaschema errors reported by the validator with nested properties correctly attribute the error to the property with the error, rather than the top-level class.

OCSF Schema Release v1.1.0

Choose a tag to compare

@floydtree floydtree released this 25 Jan 21:57

[v1.1.0] - January 25th, 2024

Added

  • Categories

    n/a

  • Event Classes

    1. Added User Inventory Info event class. #667
    2. Added Vulnerability Finding event class. #698
    3. Added NTP Activity event class #705
    4. Added OS Patch State event class. #746
    5. Added Datastore Activity event class 6005. #874
    6. Added Detection Finding event class. #877
    7. Added Incident Finding event class. #903
    8. Added Device Config Sate Change event class. #914
    9. Added Scan Activity event class. #915
    10. Added File Hosting Activity event class. #917
  • Profiles

    1. Added Network Proxy Profile for the Network Activity and Application Activity classes. #705
    2. Added Load Balancer Profile for the Network Activity classes. #897
  • Objects

    1. Added new cwe object to cve and vulnerability objects. #678
    2. Added Firewall Rule object. #685
    3. Added new kb_article object to house Knowledgebase Article info. #709 #862 #924
    4. Added new epss object to the cve object. #741

Improved

  • Categories

    1. Improved Findings Category, with new and domain specific event classes (Vulnerability Finding, Compliance Finding, Detection Finding, Incident Finding), description updates across the board. #895 #907 #903 #698 #718
  • Event Classes

    1. Added MFA Enable and Disable to activity_id to the Account Change event class. #724
    2. Added Service Ticket Renew to activity_id of the Authentication event class. #765
    3. Added url attribute to Network Activity event class. #857
    4. Added http_request, http_response, tls attributes, network_proxy profile to Web Resources Activity event class. #895
    5. Adjusted requirement of dst_endpoint from required to recommended in the DNS Activity event class. #901
    6. Added Create and Delete to activity_id of the Group Management event class. #929
  • Profiles

    1. Improved security_control profile to include access control semantics, firewall properties. #851 #888 #889 #906
  • Objects

    1. Added url_string attribute to the product and the web_resource objects. #675
    2. Added type and type_id attributes to the endpoint object. #690
    3. Added cwe, desc, references and title to cve object. #698
    4. Added affected_package object andaffected_packages attribute to vulnerability object. #698
    5. Added purl to package object. #698
    6. Added cpe_name attribute to the product and os objects. #713 #731
    7. Added container and data to response and request objects. #738
    8. Added group to the api object. #738
    9. Added namespace to the resource_details object. #738
    10. Added log_level to the metadata object. #738
    11. Added length to the http_request object. #768
    12. Added is_exploit_available to the vulnerability object. #777
    13. Added domain attribute to the group object. #871
    14. Adjusted attribute requirements in dns_query, dns_answer objects. #879
    15. Added firewall, router, switch, hub to endpoint type_id enum. #921
    16. Added is_vpn to the session object. #922
    17. Added state to network_connection_info object. #932

Bugfixes

n/a

Deprecated

  1. Deprecated cwe_uid and cwe_url attributes and removed from cve object. #678
  2. Deprecated http_status attribute from HTTP Activity event to be replaced by http_response.code. #767
  3. Deprecated finding object in favor of finding_info object. #769
  4. Deprecated proxy attribute from the dictionary, in favor of Network Proxy profile. #856
  5. Deprecated group_name attribute. #873
  6. Deprecated Security Finding class to be replaced by the new specific classes according to the use-case: Vulnerability Finding, Compliance Finding, Detection Finding, Incident Finding. #877
  7. Deprecated Web Resources Access Activity event class. #890
  8. Deprecated Network File Activity event class in favor of File Hosting Activity #917
  9. Deprecated extension_list in TLS object in favor of tls_extension_list. #936

Breaking changes

n/a

Misc

  1. New Extension registration for SentinelOne. #706
  2. Added json-schema based metaschema validation to ensure correctness, consistency of the JSON definitions. #736 #830 #867 #892
  3. Increased max_len for subnet_t type from 40 to 42. #745
  4. Improved the regex for ip_t type. #745
  5. Updated the datetime_t validation regex to enable validation of timestamps, and to ensure that timestamps not matching RFC-3339 are not considered valid. #753
  6. Added version information to the native extensions. #881
  7. Updated caption and description of Observable type - File Hash to read Hash. #900
  8. New Extension registration for DataBee. #912
  9. Changed data-type of type_uid to long_t from int_t. #928

OCSF Schema Release v1.0.0

Choose a tag to compare

@mikeradka mikeradka released this 29 Sep 18:10

The OCSF Schema Release v1.0.0!

Note: New release package was cut from the v1.0.0 branch. See Issue #793 for details