Skip to content

Commit d689e04

Browse files
authored
Merge pull request #98 from fkie-cad/add-dataset-18-dedale
Add "DEDALE" dataset
2 parents f1b2070 + 029ef81 commit d689e04

File tree

2 files changed

+145
-0
lines changed

2 files changed

+145
-0
lines changed

content/all_datasets.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ before-content: gh_buttons.html
99
| Name | Network/Host Data | Year | Times Recently Cited¹ | TL;DR | Setting | OS Type | Labeled?² | Data Type/Source | Packed Size | Unpacked Size |
1010
| -------------------------------------------------------------------------------------------------- | :---------------: | --------: | ---------------------------------------: | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------- | --------------------- | :-------: | ------------------------------------------------------------------------------------ | ----------: | ------------: |
1111
| [CasinoLimit](../datasets/casinolimit) | Both | 2025 | 5738c305aa5ba87f895a618d304b1f1edcaa94bf | Syslogs and NetFlows collected from 114 individual CTF attempts, labeled with MITRE ATT&CK techniques. Does not feature benign behavior | Enterprise IT | Linux | 🟩 | NetFlows, Syslog, auditd | 3,6 GB | 54,4 GB |
12+
| [DEDALE](../datasets/dedale) | Both | 2025 | 376a3a697351a97d7df8bb971d06ee30efa64e99 | Labeled host and network logs collected from a testbed simulating a company network with 55 machines under attack by an APT, with a total runtime of four weeks | Enterprise IT | Windows, Linux | 🟩 | NetFlows, pcaps, Windows events, Linux events | - | 65 GB |
1213
| [AIT Alert Dataset](../datasets/ait_alert_dataset) | Both | 2023 | d3b80b4c1da53b09fa1498dae3f50edff2dfc371 | Alerts generated from the AIT log dataset, including labels. Only caveat is the lack of Windows machines | Enterprise IT | Linux | 🟩 | Wazuh, Suricata and AMiner alerts | 96 MB | 2,9 GB |
1314
| [FLNET2023](../datasets/flnet2023) | Network | 2023 | b38bf3c5231c9ff7e138df5f30f9ef5e6f0e1869 | Large dataset generated with CORE emulator based on ISP-like network topology. Features variety of attack types distributed across 40 routers | ISP-like | Undisclosed | 🟩 | pcaps, Custom network features | - | 176 GB |
1415
| [OTFR Security Datasets - LSASS Campaign](../datasets/otfr_lsass_campaign) | Both | 2023 | - | Very small simulation focusing on exploiting Windows' LSASS.exe. Lacking documentation, no labels and no user behavior | Single OS | Windows | 🟥 | pcaps, Windows events, Zeek logs | 423 MB | 1 GB |

0 commit comments

Comments
 (0)