Add files using upload-large-folder tool
Browse files
README.md
CHANGED
|
@@ -88,7 +88,6 @@ This dataset supports research in:
|
|
| 88 |
| Benign traffic and labeled attacks never overlapped in time (benign from 26 July 2024, incident leads ending 18 July 2024) | `signals` is the live capture labeled **in place**: 7,728 live rows are leads of 1584 incidents observed during the capture, surrounded by their ordinary traffic. Historical incident leads moved to a separate `incident_signals` table with an `origin` column so the two timelines cannot be confused. |
|
| 89 |
| Usernames existed on signals but credential nodes only inside incident objects | `692,375` **user → host** edges (`USER_ACTION`) join `CREDENTIAL` nodes to the hosts they act on; incident `cred` nodes and live `username` fields share the same `USER-NNNN` tokens. |
|
| 90 |
| Handful of negative timestamps (Precinct date-parse failures) | Every lead timestamp is validated; 861 were repaired (invalid values from the artifact timeuuid / `rt=` field / incident time; year-rollover errors shifted back by whole years), with the source recorded in `timestamp_source`. No timestamp in either table is outside 2000–2030. |
|
| 91 |
-
| Precinct sometimes raised one incident several times over the same triggering signals | One incident is kept per set of triggering signals (9,204 duplicates collapsed): the one Precinct worked on — an analyst decision first, then the most analysis cycles and the highest suspicion. The others' ids are listed in `duplicate_incident_ids` in `incidents.jsonl` and the attack reports. |
|
| 92 |
| README counts drifted from the uploaded files | This card is rendered from the build's `metadata.json`; `signals/metadata.json` and `graph/metadata.json` are uploaded alongside. |
|
| 93 |
| Incident nodes were keyed by Precinct uuids, disconnected from the live graph | Incident host/credential nodes use the same node ids as live signals (sanitized IP / `user:USER-NNNN`), so incident subgraphs overlay the live graph. |
|
| 94 |
| Aho-Corasick sweep occasionally corrupted uuids (`id_raw`) inside incidents | Record identifiers are protected from the sweep; leads can be joined to live rows on `artifact_id`. |
|
|
@@ -112,22 +111,32 @@ Selection parameters are in `build/subset_stats.json`.
|
|
| 112 |
|
| 113 |
## Versions
|
| 114 |
|
| 115 |
-
This is **v2.1.0**
|
| 116 |
|
| 117 |
-
|
| 118 |
-
|
| 119 |
-
|
| 120 |
-
|
|
|
|
|
|
|
|
|
|
| 121 |
|
| 122 |
-
Tokens are
|
| 123 |
-
|
| 124 |
|
| 125 |
```python
|
| 126 |
from datasets import load_dataset
|
| 127 |
|
| 128 |
-
signals = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train")
|
|
|
|
| 129 |
```
|
| 130 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 131 |
## Quick Start
|
| 132 |
|
| 133 |
```python
|
|
|
|
| 88 |
| Benign traffic and labeled attacks never overlapped in time (benign from 26 July 2024, incident leads ending 18 July 2024) | `signals` is the live capture labeled **in place**: 7,728 live rows are leads of 1584 incidents observed during the capture, surrounded by their ordinary traffic. Historical incident leads moved to a separate `incident_signals` table with an `origin` column so the two timelines cannot be confused. |
|
| 89 |
| Usernames existed on signals but credential nodes only inside incident objects | `692,375` **user → host** edges (`USER_ACTION`) join `CREDENTIAL` nodes to the hosts they act on; incident `cred` nodes and live `username` fields share the same `USER-NNNN` tokens. |
|
| 90 |
| Handful of negative timestamps (Precinct date-parse failures) | Every lead timestamp is validated; 861 were repaired (invalid values from the artifact timeuuid / `rt=` field / incident time; year-rollover errors shifted back by whole years), with the source recorded in `timestamp_source`. No timestamp in either table is outside 2000–2030. |
|
|
|
|
| 91 |
| README counts drifted from the uploaded files | This card is rendered from the build's `metadata.json`; `signals/metadata.json` and `graph/metadata.json` are uploaded alongside. |
|
| 92 |
| Incident nodes were keyed by Precinct uuids, disconnected from the live graph | Incident host/credential nodes use the same node ids as live signals (sanitized IP / `user:USER-NNNN`), so incident subgraphs overlay the live graph. |
|
| 93 |
| Aho-Corasick sweep occasionally corrupted uuids (`id_raw`) inside incidents | Record identifiers are protected from the sweep; leads can be joined to live rows on `artifact_id`. |
|
|
|
|
| 111 |
|
| 112 |
## Versions
|
| 113 |
|
| 114 |
+
This is **v2.1.0**. It corrects v2.0.0, which stays available at the `v2.0.0` tag:
|
| 115 |
|
| 116 |
+
| Changed since v2.0.0 | |
|
| 117 |
+
|---|---|
|
| 118 |
+
| Duplicate incidents | Precinct sometimes raised one incident several times over the same triggering signals. One is kept per set — the one Precinct worked on: an analyst decision first, then the most analysis cycles and the highest suspicion — and the others' ids are listed in `duplicate_incident_ids` (9,204 collapsed). |
|
| 119 |
+
| `Disrupted` | `disposition_category` is `automated`: Precinct's engine sets it, and no analyst action is recorded on these incidents. |
|
| 120 |
+
| Year-rollover timestamps | Late-December events that Precinct dated a year late are shifted back (835 lead rows, `timestamp_source = lead.observed_at.year_repaired`); `incidents.jsonl` keeps the originals in `_*_raw` fields. |
|
| 121 |
+
| Organization tokens | An incident `org` field holding the organization's display name carries the organization's own token, as `_org_id` does. |
|
| 122 |
+
| `suspicious` rows | Carry the MITRE techniques of their matched rules' set roles. |
|
| 123 |
|
| 124 |
+
Tokens are shared with v2.0.0 (this build reused its PII registry), apart from the incident `org` fields above
|
| 125 |
+
and fewer than 200 values, mostly email addresses, whose registry entries were re-created and renumbered.
|
| 126 |
|
| 127 |
```python
|
| 128 |
from datasets import load_dataset
|
| 129 |
|
| 130 |
+
signals = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train") # v2.1.0
|
| 131 |
+
signals_v2_0 = load_dataset("witfoo/precinct6-cybersecurity", "signals", split="train", revision="v2.0.0") # previous release
|
| 132 |
```
|
| 133 |
|
| 134 |
+
The 2026-05 release (v1) is not kept for download. Re-verifying it against the v2 tooling showed that
|
| 135 |
+
some values had escaped sanitization — device and account names survived inside JSON-escaped Windows
|
| 136 |
+
event text and in `stream_name` — so it was withdrawn rather than preserved at a tag. Its tokens are not
|
| 137 |
+
comparable with v2: each used its own registry, so `HOST-0042` there is a different machine from
|
| 138 |
+
`HOST-0042` here.
|
| 139 |
+
|
| 140 |
## Quick Start
|
| 141 |
|
| 142 |
```python
|