Sign in to view source links and access this dataset
Description
A large-scale, labeled cybersecurity dataset derived from production Security Operations Center (SOC) data processed by WitFoo Precinct version 6.x. The dataset contains 2.1 million sanitized security events (signal logs) and provenance graphs (13,119 incident graphs with 35,133 nodes and 634,190 edges) from real enterprise network monitoring across multiple organizations. Each incident has a natural-language threat-hunting description, and the dataset was created by author 'witfoo' and last updated on 2026-05-13.
Use Cases
Train anomaly detection models based on the 2.1 million sanitized security event logs.
Develop graph neural networks for security incident analysis using the 13,119 provenance graphs with nodes and edges.
Build natural language processing tools for threat hunting based on the incident descriptions.
Benchmark security operations automation tools against real-world, multi-organization SOC data.
Strengths
Contains 2.1 million sanitized security events, providing substantial volume for analysis.
Includes 13,119 detailed incident provenance graphs with 35,133 nodes and 634,190 edges.
Derived from real production Security Operations Center (SOC) data across multiple organizations.
Data is labeled, which supports supervised machine learning tasks.
Limitations
Column-level documentation is absent; field semantics must be inferred after download.
Row count for the event logs is unspecified beyond the total 2.1 million figure.
The description metadata is limited; actual data quality and completeness require manual inspection after download.
Provenance
Source
WitFoo Precinct version 6.x, processing production SOC data from multiple organizations.
Collection Method
Derived and sanitized from real enterprise network monitoring logs.
Freshness
Last updated 2026-05-13 04:20:55; freshness should be verified.
License is unknown; users must verify terms of use before downloading.