Schema Field Reference Guide

This guide lists the available fields in the Nebulock OCSF (Open Cybersecurity Schema Framework) schema that you can use when creating reference tables and detection rules.

See also:

Reference Tables Guide for how to create and manage reference tables.
Create and Deploy Detection Rules for more information about detection rules.

Last updated: September 29th, 2026

What This Guide Contains

Fields are organized by category. Each field includes:

  • Field name for use in detection rule logic
  • Description of what the field contains
  • Providers that populate this field

Provider Coverage

The Providers field shows which security tools populate each field:

  • crowdstrike - CrowdStrike Falcon
  • sentinel_one - SentinelOne
  • microsoft_defender - Microsoft Defender for Endpoint
  • jamf_protect - Jamf Protect
  • elastic - Elastic Defend
  • okta - Okta
  • duo - Duo Security
  • falco - Falco Cloud Security
  • cloudtrail - AWS CloudTrail
  • azure_event_hub - Microsoft Entra ID (Azure AD)
  • gcp_pubsub - Google Cloud Platform

Use this information to ensure fields are populated by your active integrations before building detection rules around them.

Field Categories

58 fields - Cloud provider context, API operations, and container runtime details. Includes AWS CloudTrail events, Azure/GCP API activity, container orchestration, and cloud account metadata.

28 fields - User identity, authentication protocols, and actor context. Includes user attributes, session details, effective permissions, authentication protocols, and Kerberos ticket encryption.

43 fields - Process and script execution details including command lines, hashes, parent-child relationships, code signatures, and script content.

37 fields - Network connections, DNS queries, HTTP requests, and TLS sessions. Includes source/destination IPs, domains, geolocation, DNS resolution chains, HTTP user agents, and TLS certificates.

30 fields - Host identity and peripheral devices. Includes hostname, IP, OS details, hardware serial numbers, USB devices, removable media, and device characteristics.

16 fields - File operations and transfers including names, paths, hashes, extensions, mount operations, renames, and FTP/SFTP transfers.

14 fields - Installed software and browser extensions including names, versions, vendors, permissions, installation methods, and product codes.

12 fields - Windows registry operations including hives, keys, values, and data types.

6 fields - Security alert metadata including MITRE ATT&CK techniques, severity, detection sources, and alert titles.

29 fields - Cross-cutting event fields including event type, provider, activity name, status, severity, logon types, privileges, MFA flags, user/group identifiers, resource names, and email threat indicators.



Did this page help you?