Skip to content

Reference documentation for the Open Cybersecurity Schema Framework (OCSF). Provides hierarchical navigation of event classes, objects, attributes, and profiles across OCSF versions.

  • 🗂️ Schema Navigation: Hierarchical reference to event classes, objects, and profiles across OCSF versions
  • 📚 Core Concepts: Learn attributes, objects, classes, profiles, and extensions
  • 📖 Versioned References: Auto-generated documentation for each OCSF release
  • 🤖 Guide Subagent: Fast answers to OCSF schema questions

Use the plugin manager UI in Claude Code.

  1. Run /plugin in Claude Code Enter
  2. Go to Marketplaces Tab
  3. Select + Add Marketplace Enter
  4. Type tenzir/claude-plugins Enter
  5. Install ocsf from the plugin list
TypeNameDescription
Skillunderstanding-ocsfUnderstand the OCSF schema. Use when working with OCSF, looking up
Agentocsf:guideAnswer questions about the OCSF (Open Cyber Security Schema Framework). Use when the user asks about OCSF classes, objects, attributes, profiles, or event normalization.

Delegate OCSF questions to the guide for fast, accurate answers:

@ocsf:guide What class should I use for SSH login events?
@ocsf:guide What's the difference between actor and user objects?
@ocsf:guide Which profile adds container context to events?