ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

OCSF Schema

Results 193 ocsf-schema issues
Sort by recently updated
recently updated
newest added

Hi, When trying to transform a Group created event, the assumption is - this would belong in "Group Management 3006". However, this class does not contain activity events which show...

bug
enhancement
question
iam
v1.1.0

When developing custom extensions for OCSF the generated value for `type_uid` can be out of range for classic 32-bit integer (max positive value is `2,147,483,647`). As an example, we (S1...

bug
v1.1.0

A key point of discussion in the 10/04/2023 System Activity Workstream Sync was consolidation. As OCSF grows, so does its complexity. For instance, consumers would like to avoid having profile...

enhancement
v1.4.0 or later

Background: I have some MS events in the pipeline surrounding **[clearing of the audit log](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102)**. They are very useful for ‘covering tracks’ detections, but we don’t have a class that...

enhancement
non_breaking
v1.2.0 and later

While applying consistency to Boolean attribute naming using `is_` via #841, we found some areas for improvement of the general dictionary descriptions for most of the boolean attributes. A Boolean...

enhancement
grammar_consistency
v1.2.0

Some input we gathered regarding the new `ldap_person` object (which replaces the `Person` profile via #813: - There are a few required attributes from the 3 LDAP classes we would...

enhancement
v1.2.0 and later

**Issue Description** Several activity classes defined in the OCSF schema currently lack a dedicated field for describing the resources affected by the respective activities. This omission limits the ability to...

enhancement
system_activity

Hi, During development of a python json schema parser, we noticed a few naming inconsistencies which required edge cases (Could not use the Elixir json schema generator). Below are those...

grammar_consistency

I have about 30 or so Cisco VPN Events to map to OCSF. Today, we do not have any class associated specifically with VPN sessions. After some discussion, one idea...

network_activity
non_breaking
v1.2.0 and later

The `network.json` file is the category base for the Network Activity. It defines the `activity_id` attribute that shouldn't assume all extended classes share the same values. (There is a behavior...

network_activity
non_breaking
v1.1.0