End-to-end Advance Persistent Threat Dataset
收藏资源简介:
A Multi-Sensor Industrial Enterprise Nework with an Emulated APT Attack Dataset A multi-sensor, labeled intrusion detection dataset from a realistic converged IT/OT (Information Technology / Operational Technology) environment. The attack implemented in this dataset is an emulated Advanced Persistent Threat (APT) attack mimicking Sandworm APT Campaign. It contains 29 hours of continuous network traffic and system telemetry captured across 5 network zones, with per-event ground-truth labels mapped to 24 MITRE ATT&CK techniques (16 Enterprise + 5 ICS + 3 hybrid). This is a temporary repository for the purpose of an anonymous review. This repository will be retired after the review and published officially. Attacks The dataset captures a Sandworm-inspired multi-stage attack campaign across two stages: Stage 1 — IT Compromise (Day 1 evening): Spearphishing delivery, C2 establishment, credential dumping, Active Directory enumeration, lateral movement via SMB/WMI, and data staging. Stage 2 — OT Sabotage (Day 2 evening): Pivot to OT network, Modbus register enumeration, PLC parameter manipulation, point and tag identification, and data exfiltration. See README_ZENODO.PDF for further details of the attacks and general information of the dataset.



