Jordan123234/awesome-cybersecurity-datasets
๐ก๏ธ AUTHORITATIVE 2026 FORK & INTERACTIVE CATALOG This dataset is an official mirror of the curated Awesome Cybersecurity Datasets list. ๐ View the Official Interactive Searchable Catalog ๐ป Contribute on the Official GitHub Repository Awesome Cybersecurity Datasets ๐ก๏ธ AUTHORITATIVE 2026 FORK The original Awesome-Cybersecurity-Datasets repository was abandoned in 2021 and left to rot. This is the actively maintained, state-of-the-art continuation by SystemHelpdesk. Weโฆ See the full description on the dataset page: https://huggingface.co/datasets/Jordan123234/awesome-cybersecurity-datasets.
๐ก๏ธ AUTHORITATIVE 2026 FORK & INTERACTIVE CATALOG This dataset is an official mirror of the curated Awesome Cybersecurity Datasets list. ๐ [View the Official Interactive Searchable Catalog](https://jordanricky1604-ship-it.github.io/Awesome-Cybersecurity-Datasets/) ๐ป [Contribute on the Official GitHub Repository](https://github.com/jordanricky1604-ship-it/Awesome-Cybersecurity-Datasets)
Awesome Cybersecurity Datasets 
๐ก๏ธ AUTHORITATIVE 2026 FORK The original Awesome-Cybersecurity-Datasets repository was abandoned in 2021 and left to rot. This is the actively maintained, state-of-the-art continuation by SystemHelpdesk. We have purged dead links and added the critical datasets (LLMs, modern malware, cloud) required for 2026 threat research. ๐ [View the Interactive, Searchable Version](https://jordanricky1604-ship-it.github.io/Awesome-Cybersecurity-Datasets/) ๐ค [Hugging Face Dataset Mirror](https://huggingface.co/Jordan123234) ๐ [Kaggle Dataset Mirror](https://www.kaggle.com/rickyjordan) ๐ [Dev.to Technical Guides](https://dev.to/jordanricky1604-ship-it)
A curated list of amazingly awesome Cybersecurity datasets.
Please contribute to this list with new datasets by sending me a pull request.
Happy learning!
Contents
- ๐ Maintainer's Choice: Featured Dataset
- Network traffic
- Malware
- WebApps
- Software
- URLs & Domain Names
- Host
- Fraud
- Honeypots
- Binaries
- Phishing
- Passwords
- MISC
- Generative AI & LLM Security
- Modern Malware Benchmarks
- Cloud & Container Security
- Software Supply Chain
- Governance, Risk, and Compliance (C-Suite)
- Web3 & Smart Contracts
- Automotive & IoT Security
๐ Maintainer's Choice: Featured Dataset
Datasets
Network traffic
- Comprehensive, Multi-Source Cyber-Security Events - This data set represents 58 consecutive days of de-identified event data collected from five sources within Los Alamos National Laboratory's corporate, internal computer network.
- User-Computer Authentication Associations in Time - This anonymized data set encompasses 9 continuous months and represents 708,304,516 successful authentication events from users to computers collected from the Los Alamos National Laboratory (LANL) enterprise network.
- Canadian Institute for Cybersecurity datasets - Used around the world by universities, private industry and independent researchers.
- KDD Cup 1999 Data - This database contains a standard set of data to be audited, which includes a wide variety of intrusions simulated in a military network environment.
- NSL-KDD Dataset - Often viewed as the "corrected" version of the original KDD Cup 1999 dataset. It removes the massive number of duplicate records found in the original, providing a more rigorous benchmark.
- 2017-SUEE-data-set - The data sets contain traffic in and out of the web server of the Student Union for Electrical Engineering (Fachbereichsvertretung Elektrotechnik) at Ulm University. Internal hosts are hosts from within the university network, some of them are cable bound, others connect through one of two wifi services on campus (eduroam and welcome). The data was mixed with attack traffic.
- CTU-13 Dataset - A Labeled Dataset with Botnet, Normal and Background traffic.
- PCAP files - Malware Traffic, Network Forensics, SCADA/ICS Network Captures, Packet Injection Attacks / Man-on-the-Side Attacks...
- pcapt - Big repository of PCAP files.
- Project Sonar - Produces multiple UDP datasets every month. This data is gathered by sending protocol-specific UDP probes across the entire IPv4 address space. The types of probes sent each week continues to expand as the project matures.
Malware
- UNSW-NB15 data set - This data set has nine families of attacks, namely, Fuzzers, Analysis, Backdoors, DoS, Exploits, Generic, Reconnaissance, Shellcode and Worms. The Argus, Bro-IDS tools are utilised and twelve algorithms are developed to generate totally 49 features with the class label.
- Malware Training Sets - Today (please refers to blog post date) the collected classified datasets is composed by the following samples: APT1 292 Samples, Crypto 2024 Samples, Locker 434 Samples, Zeus 2014 Samples.
- The Drebin Dataset - The dataset contains 5,560 applications from 179 different malware families. The samples have been collected in the period of August 2010 to October 2012 and were made available to us by the MobileSandbox project.
- Stratosphere IPS - Malware captures, Normal captures, mixed captures...
- Microsoft Malware Classification Challenge - You are provided with a set of known malware files representing a mix of 9 different families. Each malware file has an Id, a 20 character hash value uniquely identifying the file, and a Class, an integer representing one of 9 family names.
Software
- JavaScript Vulnerability dataset - Dataset constructed from the vulnerability information in public databases of the Node Security Project and the Snyk platform, and code fixing patches from GitHub.
WebApps
- Web Attack Payloads - A collection of web attack payloads.
- Machine-Learning-driven-Web-Application-Firewall - Set of good and bad queries to a web application firewall.
- Internet-Wide Scan Data Repository - The Censys Projects publishes daily snapshots of what we know about each IPv4 host, Alexa Top Million website, and known X.509 certificate. These datasets contain structured, non-ephemeral JSON records that identify a host's configuration.
- 500K HTTP Headers - Recently we crawled the Top 500K sites (as ranked by Alexa). Following requests from readers we are making available the HTTP Headers for research purposes.
- HTTP DATASET CSIC 2010 - The HTTP dataset CSIC 2010 contains thousands of web requests automatically generated. It can be used for the testing of web attack protection systems. It was developed at the Information Security Institute of CSIC (Spanish Research National Council).
- OpenAppSec WAF Comparison Dataset - A modern dataset of millions of requests and tens of thousands of malicious payloads explicitly designed to test modern WAF evasion techniques.
- 30-Day ModSecurity Production Dataset - Real malicious HTTP requests blocked by the OWASP ModSecurity Core Rule Set (CRS) on a live production server.
- Common Crawl - The Common Crawl corpus contains petabytes of data collected over the last 7 years. It contains raw web page data, extracted metadata and text extractions.
- AZSecure-data - The AZSecure-data PORTAL currently provides access to Web forums, Internet phishing websites, Twitter data, and other data.
URLs & Domain Names
- Malicious URLs Dataset - The data set consists of about 2.4 million URLs (examples) and 3.2 million features.
- Feodo Tracker - List of Feodo botnet C&C servers.
- URLhaus - A project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.
- Alexa Top 1 Million - CSV dataset with the most popular sites by Alexa.
- Tranco List - The modern academic standard replacing Alexa. It provides a hardened, daily-updated ranking by aggregating Cloudflare, Chrome UX, and other sources to prevent manipulation.
- Cloudflare Radar Domain Rankings - Based on live 1.1.1.1 resolver data, highly relevant for modern traffic popularity.
- OpenDNS Top Domains List - The OpenDNS Top Domains List is the top 10,000 domain names our resolvers all over the globe are receiving queries for, sorted by popularity.
- StopForumSpam - The data provided here represents what we believe will only ever ben used to abuse. IP Addresses, domains and usernames listed here will be returned in API results as "blacklisted".
Host
- The ADFA Intrusion Detection Datasets - This dataset provides a contemporary Linux dataset for evaluation by traditional HIDS. This dataset provides a contemporary Windows dataset for evaluation by HIDS.
- Public Security Log Sharing Site - This site contains various free shareable log samples from various systems, security and network devices, applications, etc. The logs are collected from real systems, some contain evidence of compromise and other malicious activity. Wherever possible, the logs are NOT sanitized, anonymized or modified in any way (just as they came from the logging system).
- Aktaion2 Data - The project is meant to be a learning/teaching tool on how to blend multiple security signals and behaviors into an expressive framework for intrusion detection.
Fraud
- Credit Card Fraud - The datasets contains transactions made by credit cards in September 2013 by european cardholders. This dataset presents transactions that occurred in two days, where we have 492 frauds out of 284,807 transactions. The dataset is highly unbalanced, the positive class (frauds) account for 0.172% of all transactions.
Honeypots
- DDS Dataset Collection - A tar/gzip CSV file from a collection of AWS honeypots. A zip CSV file of domains and a high level classification of dga or legit along with a subclass of either legit, cryptolocker, gox or newgoz.
- Threat_Research - Centralized repository to dump threat research data gathered from my network of honeypots.
Binaries
- The ember dataset - A collection of 1.1 million sha256 hashes from PE files that were scanned sometime in 2017. This repository makes it easy to reproducibly train the benchmark model, extend the provided feature set, or classify new PE files with the benchmark model.
Phishing
- Phishing Websites Data Set - In this dataset, we shed light on the important features that have proved to be sound and effective in predicting phishing websites. In addition, we propose some new features.
Passwords
- Yahoo Password Frequency Corpus - This dataset includes sanitized password frequency lists collected from Yahoo in May 2011.
- RockYou2024 - A massive compilation of nearly 10 billion plaintext credentials aggregated from thousands of recent data breaches. It is the absolute standard for penetration testing wordlists.
- Have I Been Pwned (Pwned Passwords) - The industry-standard k-anonymity dataset for checking breached credentials securely without exposing passwords.
MISC
- SecRepo - Samples of Security Related Data.
Generative AI & LLM Security
- Tencent/AI-Infra-Guard - A full-stack AI red teaming platform including modern LLM jailbreak evaluation datasets, agent security scanning, and vulnerability assessments (Updated 2026).
- JailbreakBench - The industry-standard repository for tracking state-of-the-art LLM jailbreaks and defenses. Features a continuously updated dataset of adversarial prompts.
- LLM Jailbreak Taxonomy & Simulation - Contains a taxonomy of 40 modern adversarial attack patterns, experiment notebooks, and simulation harnesses calibrated to 2025-2026 attack success rates.
- Jailbreak_LLMs - A massive, highly-cited dataset of 15,140 prompts in the wild, including 1,405 specifically categorized as jailbreak prompts.
- Awesome-Jailbreak-on-LLMs - An actively maintained, curated list of research papers, defense frameworks, and detection methods for modern LLMs.
Modern Malware Benchmarks
- SOREL-20M - The Sophos-ReversingLabs 20 Million dataset. Released in late 2020, this is the modern benchmark for training PE malware detection models.
- Malware Families Catalog - A structured dataset of 2,900+ curated malware families with MITRE ATT&CK mapping and hunting queries. Available in JSONL and Parquet.
- BODMAS - Blue Hexagon Open Dataset for Malware Analysis. Features timestamped malware samples and behavioral vectors for temporal drift analysis.
Cloud & Container Security
- Kubernetes Dataset - Network flow data of CVE exploits and container escapes in Kubernetes clusters.
- Cloud Monitoring Dataset - Microsoft's massive cloud telemetry dataset for anomaly detection.
- Mordor - The Mordor project provides pre-recorded, high-quality security events (JSON) generated by simulated adversarial techniques, heavily featuring cloud environments (AWS/Azure).
- Flaws.cloud Logs - Log datasets from the famous AWS security challenges, providing real-world CloudTrail and S3 access logs of cloud compromise.
Software Supply Chain
- Backstabber's Knife Collection - A curated dataset of open-source software supply chain attacks, containing malicious packages collected from NPM, PyPI, and RubyGems.
Governance, Risk, and Compliance (C-Suite)
- VERIS Community Database (VCDB) - A public, open-source repository of security incidents documented using the VERIS framework. This dataset powers the annual Verizon Data Breach Investigations Report (DBIR) and is critical for enterprise risk modeling.
- CERT Insider Threat Dataset - Synthetic logs of simulated malicious insider behavior within sociotechnical networks, developed by Carnegie Mellon University (SEI) for User Behavior Analytics (UBA) and insider threat training.
Web3 & Smart Contracts
- FORGE-Artifacts - High-quality curated dataset of smart contract audits and vulnerabilities constructed via LLMs.
- Smart Contract Vuln Dataset - Large-scale Solidity dataset with line-level annotations.
- SCV-List - Focuses on advanced, unconventional vulnerabilities in DeFi protocols.
Automotive & IoT Security
- Car-Hacking-Dataset - Famous CAN bus intrusion detection dataset featuring DoS, fuzzy, and spoofing attacks.
ICS & Critical Infrastructure Security
- HAI (HIL-based Augmented ICS) Security Dataset - Industrial control system operational data collected from a testbed augmented with Hardware-In-the-Loop (HIL) simulators. Contains multiple attack scenarios.
- WUSTL-IIOT Dataset - A dataset specifically built to emulate real-world industrial systems, focusing on reconnaissance attacks and network scanning in ICS testbeds.
- ICS-Security-Tools/pcaps - A massive repository containing a wide variety of PCAP files specifically for ICS/SCADA network traffic, including DNP3, Profinet, and Siemens S7Comm.
Deepfake & Synthetic Media Detection
- DeepfakeBench - A comprehensive benchmark dataset containing state-of-the-art (SOTA) image and video detection methods for standardized evaluation.
- FaceForensics++ - One of the most common datasets, consisting of 1,000 original videos manipulated using Deepfakes, Face2Face, FaceSwap, and NeuralTextures.
- Celeb-DF (v2) - A large-scale, high-quality dataset containing 590 real videos and 5,639 deepfake videos, known for being extremely challenging due to high visual quality.
