OCSF Extensions Registry

September 11, 2026 ยท View on GitHub

The purpose of this file is to keep track of and avoid collisions in Extension names and uids.

Repository is optional. Use it when the extension schema is public (in the OCSF GitHub org or elsewhere). Leave it blank for private extensions or when the code is not published.

CaptionNameUIDNotesRepository
DefenXeedefenxee987The DefenXee vendor extension
Trellixtrellix988The Trellix schema extension
Synqlysynqly989The Synqly schema extension
US GOVusg1990The USG-1 schema extension
Ciscocisco991The Cisco schema extension
Sedarasedara992The Sedara schema extension
Scibersciber993The Sciber schema extension
DataBeedatabee994The Comcast DataBee schema extension
Symantecsymantec995The Symantec schema extensionocsf/symantec
SentinelOnes1996The SentinelOne schema extension
Splunksplunk997The Splunk schema extensionocsf/splunk
AWSaws998The Amazon Web Services schema extensionocsf/aws
Developmentdev999The development (TODO) schema extensionsocsf/dev-ext
Native Extensions defined in OCSF
Linuxlinux1The Linux extension defines Linux specific attributes, objects and classesextensions/linux
Windowswin2The Windows extension defines Windows specific attributes, objects and classesextensions/windows
macOSmacos3The macOS extension defines macOS specific attributes, profiles, objects and classesextensions/macos