Writing · Pillar
OCSF & schema.
Normalization, mapping, and the anti-patterns from migrations gone sideways. Schema-on-read vs schema-on-write, OCSF reverse mapping, flattening detection logic.
Depth tier for ch4 (Well-connected) · 12 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are about to read the frame (Orientation), the argument (Depth), or the narrowest first-party finding (Evidence). The durability tag flags whether a number is durable architecture or an Evidence-pinned result tied to a version or price and meant to be re-run.
- Start here OrientationEvidence-pinned
Schema-on-read vs schema-on-write.
Splunk at $31K/month for 1 TB/day. Elasticsearch with ECS at $8–12K. Hybrid lakehouse (raw on cheap object storage, OCSF on warm) at $7.5K with parity on detection-engineer workflows. The schema-on-read tax compounds at retention scale.
Read →
- DepthEvidence-pinned
What two practitioners told me at RSA.
A field report, not a benchmark. Two RSA conversations where practitioners described both halves of the open architecture already running in production: petabyte-scale OCSF normalization on one side, columnar storage-and-query economics on the other. The mapping labor is the real cost, the numbers are attributed and discounted honestly, and field reports are weighed for what they can and can't tell you.
Read →
- DepthDurable
OCSF ontological grounding: D3FEND for federal-ready.
OCSF anchored to MITRE D3FEND gives the ontology you need for federal-grade detection. What works today, what's still aspirational, and where the gaps sit.
Read →
- DepthDurable
How much ontology does security data actually need?
Security keeps being told its telemetry needs a formal ontology underneath it. Measured rather than asserted, D3FEND grounding is reciprocal at the class level but roof-only beneath, and the architecture that would make a richer one pay off is adjacent and virtual, not embedded. Use the formal model at design time as a validation oracle, the columnar schema at runtime. Keep McComb diagnosis, drop the triplestore prescription; AI maps, humans model.
Read →
- DepthEvidence-pinned
OCSF reverse mapping.
Answering the legal-team objection. When OCSF normalization erases the original-event fidelity required for chain-of-custody, here's how reverse-mapping preserves the evidentiary record.
Read →
- DepthEvidence-pinned
OCSF and operational technology.
OCSF has no native fields for Modbus, DNP3, BACnet, or S7comm. The Issue #1515 proposal adds six fields under an ics namespace, anchored on production-validated Zeek-to-OCSF mapping work. The architecture argument for IT/OT convergence at the schema layer.
Read →
- DepthDurable
The field-mapping anti-pattern.
Field-by-field mapping during SIEM-to-lakehouse migration looks like the safe play and drops detection coverage on the way. Five patterns that break and what to do instead.
Read →
- DepthDurable
Flattening away your detection logic.
Migrating from SIEM to lakehouse is semantic translation. Treating it as schema conversion is how detection coverage breaks: flattening CloudTrail's nested JSON silently broke a privilege-escalation detection for six weeks at a financial services firm.
Read →
- EvidenceEvidence-pinned
LLM-assisted OCSF mapping.
What the migration tax actually looks like when you use LLMs to translate vendor schemas to OCSF. Where it accelerates, where it produces silent-loss errors, and how to validate.
Read →
- EvidenceEvidence-pinned
Six schemas into OCSF: the mapping is the hard part.
Field-level crosswalks of Splunk CIM, Google Chronicle UDM, Microsoft Sentinel ASIM, Elastic ECS, OpenTelemetry, and Zeek into OCSF 1.8.0. The empty cells are the finding: five recurring seams, most of them the standard's own (missing disposition, missing certificate class, an invented-severity contract).
Read →
- EvidenceEvidence-pinned
From field mappings to the controls layer.
Up one layer from the schema crosswalks: OCSF class to digital artifact to D3FEND defense to ATT&CK offense to NIST 800-53 / SCF control. Measured hop by hop (79 D3FEND techniques to 402 controls via 606 SKOS edges; 98% of the defensive matrix reaching a governance control through ATT&CK), and honest about the one direct link that does not exist.
Read →
- EvidenceEvidence-pinned
The blind quadrant over AI systems.
MITRE's own D3FEND dashboard scored ATLAS at 0.0% coverage over AI systems, one of three frameworks at zero. Working the mapping under an exhaust-existing-vocabulary discipline (the BFO placement rule that keeps model, event, and defensive-method apart) moves 117 of 140 techniques into the matrix, acceptance-tested 0 to 117 in MITRE's own container with every other framework byte-identical. Only five techniques genuinely need a new artifact noun, and three independent communities (D3FEND, the BOM standards, OCSF) turn out to have found the same missing vocabulary.
Read →