f15hb0wn commited on
Commit
879fe52
·
verified ·
1 Parent(s): 27053f1

Add files using upload-large-folder tool

Browse files
Files changed (1) hide show
  1. README.md +18 -9
README.md CHANGED
@@ -88,7 +88,6 @@ This dataset supports research in:
88
  | Benign traffic and labeled attacks never overlapped in time (benign from 26 July 2024, incident leads ending 18 July 2024) | `signals` is the live capture labeled **in place**: 7,728 live rows are leads of 1584 incidents observed during the capture, surrounded by their ordinary traffic. Historical incident leads moved to a separate `incident_signals` table with an `origin` column so the two timelines cannot be confused. |
89
  | Usernames existed on signals but credential nodes only inside incident objects | `692,375` **user → host** edges (`USER_ACTION`) join `CREDENTIAL` nodes to the hosts they act on; incident `cred` nodes and live `username` fields share the same `USER-NNNN` tokens. |
90
  | Handful of negative timestamps (Precinct date-parse failures) | Every lead timestamp is validated; 861 were repaired (invalid values from the artifact timeuuid / `rt=` field / incident time; year-rollover errors shifted back by whole years), with the source recorded in `timestamp_source`. No timestamp in either table is outside 2000–2030. |
91
- | Precinct sometimes raised one incident several times over the same triggering signals | One incident is kept per set of triggering signals (9,204 duplicates collapsed): the one Precinct worked on — an analyst decision first, then the most analysis cycles and the highest suspicion. The others' ids are listed in `duplicate_incident_ids` in `incidents.jsonl` and the attack reports. |
92
  | README counts drifted from the uploaded files | This card is rendered from the build's `metadata.json`; `signals/metadata.json` and `graph/metadata.json` are uploaded alongside. |
93
  | Incident nodes were keyed by Precinct uuids, disconnected from the live graph | Incident host/credential nodes use the same node ids as live signals (sanitized IP / `user:USER-NNNN`), so incident subgraphs overlay the live graph. |
94
  | Aho-Corasick sweep occasionally corrupted uuids (`id_raw`) inside incidents | Record identifiers are protected from the sweep; leads can be joined to live rows on `artifact_id`. |
@@ -112,22 +111,32 @@ Selection parameters are in `build/subset_stats.json`.
112
 
113
  ## Versions
114
 
115
- This is **v2.1.0**, a full regeneration that **replaces and withdraws the 2026-05 release**.
116
 
117
- The earlier release is not kept for download. Re-verifying it against this build's tooling showed
118
- that some values had escaped sanitization — device and account names survived inside JSON-escaped
119
- Windows event text and in `stream_name` — so it has been withdrawn rather than preserved at a tag.
120
- Anything built on it should be regenerated from v2.1.0.
 
 
 
121
 
122
- Tokens are not comparable between the two releases in any case: each build maps identifiers with its
123
- own registry, so `HOST-0042` in the old release is a different machine from `HOST-0042` here.
124
 
125
  ```python
126
  from datasets import load_dataset
127
 
128
- signals = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train") # v2.1.0
 
129
  ```
130
 
 
 
 
 
 
 
131
  ## Quick Start
132
 
133
  ```python
 
88
  | Benign traffic and labeled attacks never overlapped in time (benign from 26 July 2024, incident leads ending 18 July 2024) | `signals` is the live capture labeled **in place**: 7,728 live rows are leads of 1584 incidents observed during the capture, surrounded by their ordinary traffic. Historical incident leads moved to a separate `incident_signals` table with an `origin` column so the two timelines cannot be confused. |
89
  | Usernames existed on signals but credential nodes only inside incident objects | `692,375` **user → host** edges (`USER_ACTION`) join `CREDENTIAL` nodes to the hosts they act on; incident `cred` nodes and live `username` fields share the same `USER-NNNN` tokens. |
90
  | Handful of negative timestamps (Precinct date-parse failures) | Every lead timestamp is validated; 861 were repaired (invalid values from the artifact timeuuid / `rt=` field / incident time; year-rollover errors shifted back by whole years), with the source recorded in `timestamp_source`. No timestamp in either table is outside 2000–2030. |
 
91
  | README counts drifted from the uploaded files | This card is rendered from the build's `metadata.json`; `signals/metadata.json` and `graph/metadata.json` are uploaded alongside. |
92
  | Incident nodes were keyed by Precinct uuids, disconnected from the live graph | Incident host/credential nodes use the same node ids as live signals (sanitized IP / `user:USER-NNNN`), so incident subgraphs overlay the live graph. |
93
  | Aho-Corasick sweep occasionally corrupted uuids (`id_raw`) inside incidents | Record identifiers are protected from the sweep; leads can be joined to live rows on `artifact_id`. |
 
111
 
112
  ## Versions
113
 
114
+ This is **v2.1.0**. It corrects v2.0.0, which stays available at the `v2.0.0` tag:
115
 
116
+ | Changed since v2.0.0 | |
117
+ |---|---|
118
+ | Duplicate incidents | Precinct sometimes raised one incident several times over the same triggering signals. One is kept per set — the one Precinct worked on: an analyst decision first, then the most analysis cycles and the highest suspicion — and the others' ids are listed in `duplicate_incident_ids` (9,204 collapsed). |
119
+ | `Disrupted` | `disposition_category` is `automated`: Precinct's engine sets it, and no analyst action is recorded on these incidents. |
120
+ | Year-rollover timestamps | Late-December events that Precinct dated a year late are shifted back (835 lead rows, `timestamp_source = lead.observed_at.year_repaired`); `incidents.jsonl` keeps the originals in `_*_raw` fields. |
121
+ | Organization tokens | An incident `org` field holding the organization's display name carries the organization's own token, as `_org_id` does. |
122
+ | `suspicious` rows | Carry the MITRE techniques of their matched rules' set roles. |
123
 
124
+ Tokens are shared with v2.0.0 (this build reused its PII registry), apart from the incident `org` fields above
125
+ and fewer than 200 values, mostly email addresses, whose registry entries were re-created and renumbered.
126
 
127
  ```python
128
  from datasets import load_dataset
129
 
130
+ signals = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train") # v2.1.0
131
+ signals_v2_0 = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train", revision="v2.0.0") # previous release
132
  ```
133
 
134
+ The 2026-05 release (v1) is not kept for download. Re-verifying it against the v2 tooling showed that
135
+ some values had escaped sanitization — device and account names survived inside JSON-escaped Windows
136
+ event text and in `stream_name` — so it was withdrawn rather than preserved at a tag. Its tokens are not
137
+ comparable with v2: each used its own registry, so `HOST-0042` there is a different machine from
138
+ `HOST-0042` here.
139
+
140
  ## Quick Start
141
 
142
  ```python