{"adoption": {"forks": 262, "observed_at": "2026-08-28T04:05:38.980676+00:00", "stars": 1805}, "canonical_url": "https://ross.abutalabs.com/products/security-datasets", "card": {"archived": false, "artifact_type": "dataset", "description": "Re-play Security Events", "domain": ["security", "developer-tools", "data-science"], "enriched": true, "function": ["security", "testing", "data-science"], "health_score": 20, "homepage": null, "language": "PowerShell", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["OTRF/Security-Datasets"], "name": "OTRF/Security-Datasets", "platform": ["cross-platform", "python"], "pushed_at": "2024-03-20T20:19:19+00:00", "repo": "OTRF/Security-Datasets", "stars": 1805, "tags": ["threat-hunting", "mitre-attack", "detection-analytics", "adversary-simulation", "infosec", "ctf", "sigma", "security-datasets"], "topics": [], "urls": [], "use_cases": ["find sample security event logs to test detection rules", "replay attack datasets to validate sigma detections", "get labeled data for security data science research", "simulate adversary techniques for threat hunting practice", "build MITRE ATT&CK mapped detection analytics", "practice security analysis with real-world data", "find datasets for a security CTF"], "what_it_is": "An open-source collection of malicious and benign security event datasets from different platforms, maintained by the Open Threat Research community. It supports threat detection research, adversary technique simulation, and validation of detection analytics with real labeled data.", "when_to_avoid": ["you need a live intrusion detection or SIEM product rather than static datasets", "you need production-scale streaming security telemetry", "you need guaranteed up-to-date datasets for the latest attack techniques"], "when_to_choose": ["you need realistic labeled security telemetry to develop or validate detection analytics", "you want to test threat hunting skills against known attack data", "you need datasets mapped to MITRE ATT&CK, Sigma, or Atomic Red Team", "you are building security data science features and need labeled and unlabeled data"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/security-datasets", "repo": "OTRF/Security-Datasets", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:38.980676+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:21:32.788380+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4fe95fb46ada0c6d364fd4a1ee2b91774560dc17b3bf7a2a1fe0c7cc18f66ae2", "fetched_at": "2026-08-28T04:05:38.980676+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/Security-Datasets"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3016, "days_push": 896, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}