WinLOLBIN-GT: A Behavioural Ground Truth Dataset for ML-Based Detection of Windows LOLBIN Abuse
收藏资源简介:
Windows Living-Off-the-Land Binary Ground Truth (WinLOLBIN-GT) is a labelled behavioural ground truth dataset developed to support machine learning-based detection of Windows Living-Off-the-Land Binary (LOLBin) abuse. The dataset was constructed using a controlled laboratory testbed, where benign administrative activity and malicious LOLBin execution patterns were generated, captured, validated, and labelled. Each event reflects realistic System Monitor (Sysmon) Event ID 1 process creation behaviour, including command-line structure, parent-child process relationships, file paths, user context, and mapped behavioural indicators. The dataset contains 10,006,645 processed rows, consisting of 55 behavioural features and one model_text training field, alongside 10,000,000 unprocessed rows. The labelling scheme uses 0 for benign activity and 1 for malicious activity. Every malicious row is mapped to a MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) technique identifier. The dataset sources include the Living Off the Land Binaries and Scripts (LOLBAS) Project catalogue, Atomic Red Team test procedures, a Living Off the Land Libraries (libLOL) attacker command library, and publicly available threat intelligence reports. Windows Living-Off-the-Land Binary Ground Truth (WinLOLBIN-GT) was used to train machine learning models for Windows Living-Off-the-Land Binary (LOLBin) abuse detection and was evaluated in a Security Information and Event Management (SIEM) deployment setting. The trained model correctly detected unseen Windows Living-Off-the-Land Binary (LOLBin) attack activity with 99% accuracy under the controlled testbed evaluation. The dataset generation scripts are available at: https://github.com/daniyyell-dev/WinLOLBIN-GT-dataset
Windows本机生存二进制文件真值数据集(Windows Living-Off-the-Land Binary Ground Truth,简称WinLOLBIN-GT)是一款带标注的行为基准真值数据集,旨在支持基于机器学习的Windows本机生存二进制文件(Living-Off-the-Land Binary,简称LOLBin)滥用检测。该数据集基于受控实验室测试床构建,在其中生成、捕获、验证并标注了良性管理员活动与恶意LOLBin执行行为模式。每条事件均对应真实的系统监视器(System Monitor,简称Sysmon)事件ID 1进程创建行为,涵盖命令行结构、父子进程关系、文件路径、用户上下文以及映射的行为指标。 该数据集包含10,006,645条已处理行,涵盖55个行为特征与1个model_text训练字段,同时附带10,000,000条未处理行。该标注方案以0代表良性活动,以1代表恶意活动。每条恶意行均映射至MITRE对抗战术、技术与通用知识(MITRE ATT&CK)技术标识符。该数据集的来源包括本机生存二进制文件与脚本(LOLBAS)项目目录、原子红队(Atomic Red Team)测试规程、本机生存库(libLOL)攻击者命令库,以及公开可得的威胁情报报告。 Windows本机生存二进制文件真值数据集(WinLOLBIN-GT)被用于训练针对LOLBin滥用检测的机器学习模型,并在安全信息与事件管理(SIEM)部署环境中完成了评估。在受控测试床评估中,该训练完成的模型以99%的准确率正确检测到了未见过的LOLBin攻击活动。该数据集的生成脚本可通过以下链接获取:https://github.com/daniyyell-dev/WinLOLBIN-GT-dataset



