NEW200+ connectorsnow onboarded — pipe any security source into OCSF effortlessly.Read the announcement
Consulting
About us
Book a demoStart now
Back to home
Solutions · By role

Write detections once.
Run them everywhere.

Stop rebuilding the same logic for every log format. With every source normalised to OCSF before it lands, your detections target one stable schema — clean, versioned, and portable across your entire stack.

Start now Book a demo
1 schema
every source mapped to OCSF
0 parsers
to write or maintain
Git-native
detections as code
The problem

Detection engineers spend more time on plumbing than on detection.

Every new source means a new parser, a new field map, and another rule rewrite. A vendor quietly renames a field and your coverage breaks in silence. The work that actually matters — catching adversaries — waits behind weeks of schema wrangling.

Without Derwent Labs
Per-source parsers that break on every vendor update
Detections coupled to one SIEM's proprietary field names
No safe way to test logic against real samples before shipping
What you get

With Derwent Labs in front of your stack

Detections as code

Author, review, and version rules in Git against a stable OCSF target. Promote from sandbox to production with a pull request.

Test before you ship

Replay real historical events against new logic in the sandbox. Catch false positives before they ever page an analyst.

Coverage that travels

Because the data model never shifts, a detection written today still fires when you add a source — or swap SIEMs — tomorrow.

The outcome

Your team writes detections. Derwent Labs keeps the data underneath them clean, consistent, and current.

70%
less rule maintenance
Same day
to ship new coverage
OCSF 1.7
the target you write against
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF. Stop maintaining parsers. Stop rewriting detections. Start shipping signal.