ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

OCSF Schema

Results 151 ocsf-schema issues
Sort by recently updated
recently updated
newest added

[categories.json](https://github.com/ocsf/ocsf-schema/blob/main/categories.json) appears to be an enumerated list of items, but the items are called "attributes" as if they were properties of an object.: ``` { "caption": "Categories", "name": "category", "description":...

#### Related Issue: #986 #### Description of changes: - Adds `owner` to `device`, `endpoint`, and `network_endpoint`. - Adds a new `agent` object that defines various sensors and agent. - Adds...

#### Related Issue: #### Description of changes: The _query Discovery classes were in the 1.1.0 section, but they were not released with 1.1.0 at which time they were _info classes....

#### Related Issue: * https://github.com/ocsf/ocsf-schema/issues/960 * https://github.com/ocsf/ocsf-schema/issues/964 #### Description of changes: Metaschema changes. * Add class and object attribute observables. * Remove hard-coded list of categories from `metaschema/categories.schema.json`, leaving this...

enhancement
non_breaking
v1.2.0 and later

#### Related Issue: #989 #### Description of changes: - Added `List`, `Encrypt` and `Decrypt` activities to `datastore` event class.

#### Related Issue: #988 #### Description of changes: - Added `threat_intelligence` object. - Added `threat_intelligence` Profile based on `threat_intelligence` object. - Added `signatures` object, an array of `signature` objects. -...

#### Related Issue: #985 #### Description of changes: - Created file profile - Added `file` profile to `api activity`, `web_resources_activity` and all `network` event classes.

network_activity
non_breaking
application_activity

The logs within the network and API category event classes could have enriched file information. Create a file profile and apply to these categories.

network_activity
application_activity

Add additional activity ids such as `Enumerate`, `Encrypt` and `Decrypt` to the datastore event class.

non_breaking
application_activity

**BLUF**: Add a new Profile for `threat_intelligence` that encompasses several existing, and some new, OCSF objects to provide conditional enrichment via cyber threat intelligence, open source intelligence, and/or analyst commentary....