Sign in to view source links and access this dataset
Description
A large-scale, labeled cybersecurity dataset derived from production Security Operations Center (SOC) data processed by WitFoo Precinct version 6.x. It contains 2.1 million sanitized security events and provenance graphs, including 13,119 incident graphs with 35,133 nodes and 634,190 edges, from real enterprise network monitoring across multiple organizations. The dataset was authored by yteyte and last updated on 2026-06-26.
Use Cases
Train graph neural networks for incident detection and correlation based on the 634,190 edges connecting 35,133 nodes in provenance graphs.
Develop models for classifying security event types based on the 2.1 million labeled signal logs.
Benchmark anomaly detection algorithms using real-world enterprise network monitoring data from multiple organizations.
Research automated incident response and triage systems using the natural-language descriptions associated with each incident.
Strengths
Contains 2.1 million sanitized security events, providing substantial volume for model training.
Includes 13,119 detailed incident provenance graphs with 35,133 nodes and 634,190 edges, offering rich relational context.
Derived from real production SOC data across multiple enterprise organizations, enhancing realism.
Limitations
Column-level documentation is absent; field semantics must be inferred after download.
Row count for the primary event logs is unspecified beyond the total 2.1 million figure.
Last updated 2026-06-26 20:23:09; freshness should be verified as the date is in the future relative to typical current dates.
Provenance
Source
Production Security Operations Center (SOC) data processed by WitFoo Precinct version 6.x.
Collection Method
Derived and sanitized from real enterprise network monitoring across multiple organizations.
Freshness
Last updated 2026-06-26 20:23:09.
License is unknown; terms of use must be verified before application.