# OTRF/Security-Datasets

Re-play Security Events

Repository: https://github.com/OTRF/Security-Datasets
Canonical: https://ross.abutalabs.com/products/security-datasets
Language: PowerShell
License: MIT
License Family: permissive
Last push: 2024-03-20T20:19:19+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3016, "days_push": 896, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1805, forks 262 (observed 2026-08-28T04:05:38.980676+00:00)

## What it is
An open-source collection of malicious and benign security event datasets from different platforms, maintained by the Open Threat Research community. It supports threat detection research, adversary technique simulation, and validation of detection analytics with real labeled data.

## Use cases
- find sample security event logs to test detection rules
- replay attack datasets to validate sigma detections
- get labeled data for security data science research
- simulate adversary techniques for threat hunting practice
- build MITRE ATT&CK mapped detection analytics
- practice security analysis with real-world data
- find datasets for a security CTF

## When to choose
- you need realistic labeled security telemetry to develop or validate detection analytics
- you want to test threat hunting skills against known attack data
- you need datasets mapped to MITRE ATT&CK, Sigma, or Atomic Red Team
- you are building security data science features and need labeled and unlabeled data

## When to avoid
- you need a live intrusion detection or SIEM product rather than static datasets
- you need production-scale streaming security telemetry
- you need guaranteed up-to-date datasets for the latest attack techniques

## Facets
- artifact type: dataset
- maturity: active
- function: security, testing, data-science
- domain: security, developer-tools, data-science
- platform: cross-platform, python
- tags: threat-hunting, mitre-attack, detection-analytics, adversary-simulation, infosec, ctf, sigma, security-datasets

## Member repositories
- OTRF/Security-Datasets (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:38.980676+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:32.788380+00:00, confidence not recorded.
  - readme: https://github.com/OTRF/Security-Datasets (fetched 2026-08-28T04:05:38.980676+00:00, sha 4fe95fb46ada)
- Data as of 2026-08-30T08:39:29.467469+00:00.
