Skip to content

Schema reference for OCSF version 1.5.0.

Event classes define the structure and semantics of security events. Each class represents a specific type of activity like authentication, file operations, or network connections. OCSF 1.5.0 includes 81 event classes organized by category.

Browse classes

Objects are reusable data structures embedded within event classes. They represent entities like users, devices, files, and network endpoints. OCSF 1.5.0 defines 161 objects.

Browse objects

Profiles are optional attribute sets that extend event classes with additional context. They enable consistent representation of cross-cutting concerns like host information or malware analysis. OCSF 1.5.0 includes 12 profiles.

Browse profiles

Extensions add platform-specific classes, objects, and attributes to the core schema. OCSF 1.5.0 includes 2 extensions.

Browse extensions

Types define the format and validation rules for attribute values. OCSF 1.5.0 defines 24 types.

Browse types