遇见数据集

End-to-end Advance Persistent Threat Dataset

收藏
Zenodo2026-07-02 更新2026-08-02 收录
官方服务:

资源简介:

A Multi-Sensor Industrial Enterprise Nework with an Emulated APT Attack Dataset A multi-sensor, labeled intrusion detection dataset from a realistic converged IT/OT (Information Technology / Operational Technology) environment. The attack implemented in this dataset is an emulated Advanced Persistent Threat (APT) attack mimicking Sandworm APT Campaign. It contains 29 hours of continuous network traffic and system telemetry captured across 5 network zones, with per-event ground-truth labels mapped to 24 MITRE ATT&CK techniques (16 Enterprise + 5 ICS + 3 hybrid). This is a temporary repository for the purpose of an anonymous review. This repository will be retired after the review and published officially. Attacks The dataset captures a Sandworm-inspired multi-stage attack campaign across two stages: Stage 1 — IT Compromise (Day 1 evening): Spearphishing delivery, C2 establishment, credential dumping, Active Directory enumeration, lateral movement via SMB/WMI, and data staging. Stage 2 — OT Sabotage (Day 2 evening): Pivot to OT network, Modbus register enumeration, PLC parameter manipulation, point and tag identification, and data exfiltration. See README_ZENODO.PDF for further details of the attacks and general information of the dataset.

提供机构:
Zenodo
创建时间:
2026-07-02
二维码
社区交流群
二维码
科研交流群
商业服务