NEW200+ connectors now onboarded. Map any security source to OCSF with a single pipeline.Read the announcement
Consulting
About us
Book a demoStart now
Back to home
Solutions · By outcome

Write once.
Run everywhere.

When every source maps to OCSF before ingestion, your detections and automations stop being tied to one vendor. Adopt years of another team's work in minutes, or take yours with you.

Start now Book a demo
1 schema
to write detections against
5 min
to adopt shared content
0 rewrites
when you switch vendors
The problem

Your detection library is a form of vendor lock-in.

Rules written against Splunk field names don't run on Sentinel. Switch tools and years of detection engineering evaporates overnight. The content you built is a genuine asset, but today it's trapped.

Without Derwent Labs
Detections coupled to one SIEM's proprietary schema
Shared community content you can't actually run
Migrations that mean rewriting every rule by hand
What you get

With Derwent Labs in front of your stack

One schema, every backend

Detections target OCSF, not a vendor dialect, so the same logic runs on Splunk, Sentinel, Chronicle, or whatever comes next.

Adopt shared content instantly

Drop in a detection pack another team spent years refining and have it firing in five minutes.

Future-proof your library

Your detection engineering becomes a portable asset that outlives any single tooling decision.

The outcome

Your detection library outlives any vendor contract.

100%
detection portability
5 min
to import a pack
Zero
rules rewritten
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF, and you can stop maintaining parsers and rewriting detections every time a vendor changes a field.