Miningbeat: A syscall-based Linux host telemetry dataset for intrusion detection
收藏资源简介:
Combining fine-grained host telemetry with comprehensive ground-truth labels and expert-derived contextual security information, this work presents a structured dataset of Linux host telemetry collected under controlled experimental conditions. Using operational workloads interleaved with adversarial activities mapped to the MITRE ATT&CK framework, this dataset integrates low-level system call events with host resource utilization, process attributes, and contextual security features describing privilege transitions, file sensitivity, permission changes, and network activity. To support a complete, timestamped, and labeled dataset for temporal analyses of normal and malicious activity, benign behavior was generated through representative user and system workloads, including software development, web browsing, file operations, backups, and controlled stress tests, while attack incidents were produced using Atomic Red Team to emulate multiple adversarial techniques. This dataset is designed for host-based intrusion detection, streaming anomaly detection, behavioral modeling, digital forensics, explainable security analytics, and concept drift, providing a reproducible resource for studying Linux host telemetry.



