Cyber Attack Manifestations – Log Data Set (CAM-LDS)
This repository contains synthetic log data and network traffic generated as consequences of cyber attacks. The data set was collected in the virtual test environment AttackBed at the AIT Austrian Institute of Technology. It in
This repository contains synthetic log data and network traffic generated as consequences of cyber attacks. The data set was collected in the virtual test environment AttackBed at the AIT Austrian Institute of Technology. It includes attacks corresponding to 13 tactics and 81 distinct techniques from MITRE ATT&CK. The data is labeled with technique identifiers and suitable for evaluation of log and alert interpretation approaches. The network topology of AttackBed is based on Linux and represents a small enterprise, including security zones (Internet, DMZ, LAN), file shares, video surveillance system, repository server, DNS, firewall, user workstations, etc. Check out our Github page for scripts to utilize this data set for LLM-based attack interpretation and some prompt-response samples. For more information on the generation of the data and a detailed description of all attack scenarios, please check out our publication [1]. Please cite that publication if you use the data.
Note that the data set focuses on attack manifestations; therefore, there no normal/benign user behavior simulation was active during collection. All logs and alerts generated during the attack intervals are thus consequences of cyber attacks or part of idle system activities. In each simulation run we collect logs (audit, authentication, Apache access and error, syslog, package management, cron, ZoneMinder, FTP, Puppet, Docker, Nextcloud, mail, system performance metrics, etc.) and netflows as well as alerts from host-based (Wazuh) and network-based (Suricata) intrusion detection systems. Due to their large size, we provide network packet captures of the CAM-LDS in a separate repository.
The data set comprises of seven scenarios, each representing an attack chain. Thereby, some scenarios involve variants of certain attack steps, which are simulated separately. The following enumeration provides an overview of all scenarios and some highlighted attack steps (lists are not exhaustive).
- Scenario 1: Video Server Exploit
- Scans (dnsenum, nmap, nikto, ffuf, linpeas), Exploits (Zoneminder/CVE-2023-26035), Privilege Escalation (logrotate race condition, PwnKit/CVE-2021-4034, reverse shells, local accounts), Persistence (PAM, SSH key, useradd), Discovery (credentials, devices)
- 18 simulation runs (6 variants for Privilege Escalation and 3 variants for Persistence)
- Scenario 2: Linux Malware
- Command and Control (implant, rootkit), Discovery (processes, configurations, credentials, policies, configurations), Exfiltration (archives), Scans (nmap)
- 2 simulation runs (2 variants for Command and Control)
- Scenario 3: Lateral Mov
📤 Share this page
Found this useful? Share it with your network.
Files are hosted on the source repository. Click download to access the full dataset.