Sage Cross-Vendor AI-Agent Shell-Behavior Corpus
收藏资源简介:
Companion dataset to the paper "Sage: An Unprivileged LLM-Assisted SSH Honeypotfor Eliciting and Capturing Autonomous AI-Agent Behavior." A verified, labeled corpus of SSH-honeypot telemetry (2026-06-16 to 2026-06-18)characterizing how autonomous LLM agents behave inside a shell. It contains196,820 records across four JSONL streams (sessions, commands, privesc,attacker_profiles) from 47 sources: ten controlled agents spanning six modelsand three vendors (Anthropic Opus 4.8/4.7/4.6 and Sonnet 4.6, OpenAI GPT-5.5,Zhipu GLM-5.1), three wild agents confirmed by capability-gap actuation, sixautomated bruteforce sources, and residual interactive traffic. Each recordcarries a ground_truth label {label, model, vendor} recorded at launch forcontrolled runs. Source IPs are pseudonymized and third-party credentialsredacted; see DATASHEET.md and manifest.json. Reproducible via make_release.py.



