CoolFace
Datasetpublic

k3nn3dy/blueteam-v1

Blue_team_v1 Synthetic fine-tuning dataset generated with Dataset Genie 0.1.0 on 2026-09-22T12:08:10+00:00. Domain brief Blue-team is broad. Cover these deliberately, spread across difficulty tiers: Platforms, not one vendor. Splunk (SPL), Microsoft Sentinel (KQL), Elastic (ES|QL/EQL/Lucene), CrowdStrike, Defender for Endpoint, Sysmon, Zeek/Suricata. Identity: Entra ID, Okta, Active Directory/Kerberos. Cloud: AWS (CloudTrail/GuardDuty), Azure, GCP. OS: Windows… See the full description on the dataset page: https://huggingface.co/datasets/k3nn3dy/blueteam-v1.

sourceHugging Facecc-by-4.0updated 2d agoView on Hugging Face
0likes20downloads
Dataset Card

Blueteamv1

Synthetic fine-tuning dataset generated with Dataset Genie 0.1.0 on 2026-09-22T12:08:10+00:00.

Domain brief

Blue-team is broad. Cover these deliberately, spread across difficulty tiers:

Platforms, not one vendor. Splunk (SPL), Microsoft Sentinel (KQL), Elastic (ES|QL/EQL/Lucene), CrowdStrike, Defender for Endpoint, Sysmon, Zeek/Suricata. Identity: Entra ID, Okta, Active Directory/Kerberos. Cloud: AWS (CloudTrail/GuardDuty), Azure, GCP. OS: Windows event IDs, Linux auditd/syslog, Kubernetes audit. Map to MITRE ATT&CK. Ensure spread across tactics (initial access, execution, persistence, cred access, lateral movement, exfiltration, C2) and the high-frequency techniques (Kerberoasting, DCSync, pass-the-hash, encoded PowerShell, LOLBins, OAuth consent abuse, impossible travel, beaconing, DNS tunneling, ransomware precursors). Tag every row with its technique ID so you can measure coverage and stratify the eval. The blue-team workflow, end to end. Alert triage, detection engineering (Sigma/YARA/KQL/SPL authoring and tuning), incident response (contain/eradicate/recover), threat hunting (hypothesis-driven), threat intel (IOC enrichment, STIX/TAXII), SIEM/telemetry engineering (onboarding, normalization, retention).

Answers are teacher outputs for fine-tuning small (~4B) models: keep them concise, well-structured, and self-contained rather than exhaustive essays.

Files

FormatTrainerTrain rowsEval rows
sft/SFTTrainer + trainonresponses_only133770
alpaca/SFTTrainer + alpaca prompt template133770

Every file is JSON Lines: one UTF-8 JSON object per line, \n line endings, no \u escapes. Each row carries a stable top-level id (<project>-<leaf>-<nnnn>) and a metadata object with leaf_path, difficulty, task_type, models, judge and flags. Split: 95 / 5 stratified by leaf, seed 42. Every conversation was validated against the chatml chat template before writing.

Provenance

Models per stage (OpenRouter slugs)

StageModel
taxonomyopenai/gpt-4.1-mini
promptsopenai/gpt-4.1-mini
responsesdeepseek/deepseek-chat-v3-0324
judgeopenai/gpt-4.1-mini

Provider pinning

Slotprovider_orderallow_fallbacks
taxonomy(any)True
prompts(any)True
judge(any)True
responses[0](any)True

Judge rubric

CriterionWeightDescription
Correctness40Facts and commands are accurate.
Actionability25Gives concrete next steps.
Style adherence20Matches the requested style and system prompt.
Safety15Redirects unsafe/out-of-scope requests appropriately.

Weighted score normalised to 0–5. Low-score threshold: 3.0. Judge scores are informational and did not gate this export; rows below 3.0 are kept and flagged low_score in their metadata.

Counts

By leaf

LeafRows
Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Decide escalation steps for ransomware precursor alerts correlated from Elastic SIEM and CrowdStrike telemetry8
Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Explain the context enrichment process for alerts triggered by impossible travel detections in Microsoft Sentinel8
Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Prioritize alerts involving Kerberoasting attempts detected via Splunk correlation searches8
Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Procedure to enrich and correlate OAuth consent abuse alerts using Okta and Azure AD telemetry8
Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Decide escalation path for detected encoded PowerShell execution with suspicious parent process8
Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Explain rationale for assigning incident severity based on DNS tunneling detection in network telemetry8
Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Prioritize alerts for possible Kerberoasting activity in Active Directory logs8
Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Procedure for assigning incident ownership after identifying impossible travel alerts in Entra ID logs8
Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Decide on noise reduction strategy for frequent Okta impossible travel login alerts8
Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Explain initial validation steps for AWS GuardDuty DNS tunneling detection8
Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Procedure to triage Microsoft Sentinel alert indicating Kerberoasting activity in Active Directory8
Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Validate Splunk alert for encoded PowerShell execution on Windows hosts8
Alert Triage and Incident Prioritization / Severity and Impact Assessment / Assess severity of a Splunk alert triggered by Kerberoasting activity in Active Directory8
Alert Triage and Incident Prioritization / Severity and Impact Assessment / Decide prioritization for multiple simultaneous alerts including impossible travel and OAuth consent abuse in Entra ID8
Alert Triage and Incident Prioritization / Severity and Impact Assessment / Explain impact of detected encoded PowerShell execution on a Windows host using Sysmon logs8
Alert Triage and Incident Prioritization / Severity and Impact Assessment / Procedure to evaluate ransomware precursor indicators from AWS GuardDuty findings and correlate with Azure Sentinel logs8
Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Decide on containment steps after detecting ransomware precursor behaviors via CloudTrail logs8
Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Explain how GuardDuty detects DNS tunneling activities within AWS environments8
Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Procedure to enrich GuardDuty findings with STIX/TAXII threat intelligence feeds8
Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Triage unusual AWS CloudTrail API calls indicating potential unauthorized access8
Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Decide on alert prioritization strategy for Azure Sentinel alerts related to beaconing and DNS tunneling C2 techniques8
Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Detect impossible travel anomalies using Azure Sentinel with Entra ID logs8
Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Explain how to tune Azure Security Center alerts to reduce false positives for ransomware precursor activities8
Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Procedure to investigate and contain OAuth consent abuse detected in Azure Sentinel8
Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Deciding on alert prioritization for anomalous GCP IAM permission changes detected in audit logs8
Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Detecting impossible travel events in Azure AD sign-in logs using KQL8
Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Explaining OAuth consent abuse risks and detection methods in Okta environments8
Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Procedure to investigate and contain suspicious AWS IAM role assumption activity via CloudTrail logs8
Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Deciding on alert prioritization for anomalous GCP Compute Engine instance creations across regions8
Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Detecting unauthorized service account key creation in GCP Cloud Audit Logs8
Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Explaining GCP Cloud Audit Logs entries related to suspicious IAM role escalations8
Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Procedure to investigate unusual data exfiltration patterns via GCP Cloud Storage access logs8
Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Decide on alert escalation for CrowdStrike detection of Kerberoasting attempts with low confidence score8
Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Explain false positive causes in Microsoft Sentinel KQL rule detecting impossible travel events8
Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Procedure to tune Elastic EQL rule for reducing noise in DNS tunneling detection alerts8
Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Triage alert for suspicious encoded PowerShell execution flagged by Splunk SPL rule8
Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Decide which MITRE ATT&CK technique ID best maps to a CrowdStrike detection of pass-the-hash lateral movement8
Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Explain how to tune a Defender for Endpoint alert for suspicious LOLBins usage to reduce false positives8
Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Triage an alert from Defender for Endpoint indicating possible ransomware precursor behavior using event correlation8
Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Write a detection rule in CrowdStrike Falcon to identify encoded PowerShell execution indicative of malware delivery8
Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Decide which EQL query modifications are needed to detect DNS tunneling activity in Elastic SIEM8
Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Explain how to tune a KQL rule in Microsoft Sentinel to reduce false positives for impossible travel alerts8
Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Triage an alert generated by a CrowdStrike rule detecting Kerberoasting attempts using event logs8
Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Write a Splunk SPL query to detect encoded PowerShell execution using command-line arguments8
Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Detecting DNS tunneling via unusual query patterns in Zeek logs8
Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Explaining detection logic for lateral movement using SMB traffic analysis in Suricata8
Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Triaging beaconing alerts from Zeek connection logs for potential C2 activity8
Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Tuning Suricata rules to reduce false positives on common LOLBins network behaviors8
Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Decide on alert prioritization for suspicious privilege escalation events across Microsoft Sentinel and Splunk8
Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Detecting Kerberoasting attempts via anomalous service ticket requests in Active Directory logs8
Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Explain OAuth consent abuse impact and detection methods in Entra ID environments8
Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Procedure to investigate and contain DCSync attacks detected through Okta and AD audit logs8
Identity and Access Management Systems / Active Directory and Kerberos Authentication / Decide on the legitimacy of an unusual authentication event flagged by impossible travel detection8
Identity and Access Management Systems / Active Directory and Kerberos Authentication / Detect and triage suspicious Kerberoasting requests in Active Directory logs8
Identity and Access Management Systems / Active Directory and Kerberos Authentication / Explain the process and risks of a DCSync attack using compromised credentials8
Identity and Access Management Systems / Active Directory and Kerberos Authentication / Procedure to contain and remediate pass-the-hash lateral movement in a Windows domain8
Identity and Access Management Systems / Cloud Identity Providers and Federation / Decide on appropriate alert tuning to reduce false positives in GCP Identity-Aware Proxy logs8
Identity and Access Management Systems / Cloud Identity Providers and Federation / Detecting anomalous OAuth consent abuse in Okta logs8
Identity and Access Management Systems / Cloud Identity Providers and Federation / Explain the process of federated authentication flow using SAML in Azure AD8
Identity and Access Management Systems / Cloud Identity Providers and Federation / Procedure to investigate and contain a suspected DCSync attack via Active Directory federation8
Identity and Access Management Systems / Identity Threat Detection and Mitigation / Deciding on containment actions after detecting DCSync activity via Microsoft Sentinel KQL analytics8
Identity and Access Management Systems / Identity Threat Detection and Mitigation / Detecting Kerberoasting attacks in Active Directory using Splunk SPL queries8
Identity and Access Management Systems / Identity Threat Detection and Mitigation / Explaining OAuth consent abuse scenarios and mitigation strategies in Okta environments8
Identity and Access Management Systems / Identity Threat Detection and Mitigation / Procedure for investigating and responding to impossible travel alerts in Entra ID logs8
Incident Response and Remediation / Containment Strategies and Isolation Techniques / Decide on containment steps for a Linux server detected with suspicious lateral movement via SSH8
Incident Response and Remediation / Containment Strategies and Isolation Techniques / Explain how to use Splunk SPL queries to identify and contain beaconing C2 traffic8
Incident Response and Remediation / Containment Strategies and Isolation Techniques / Isolate a Windows host showing ransomware precursor behaviors using Defender for Endpoint8
Incident Response and Remediation / Containment Strategies and Isolation Techniques / Triage an alert from Azure Sentinel indicating possible OAuth consent abuse and recommend isolation actions8
Incident Response and Remediation / Malware Analysis and Reverse Engineering / Analyze encoded PowerShell script extracted from ransomware sample to identify execution flow and persistence mechanism8
Incident Response and Remediation / Malware Analysis and Reverse Engineering / Determine containment steps after detecting beaconing behavior linked to malware C2 communication in Windows event logs8
Incident Response and Remediation / Malware Analysis and Reverse Engineering / Follow procedure to reverse engineer a suspicious Linux ELF binary found during incident response to identify credential access techniques8
Incident Response and Remediation / Malware Analysis and Reverse Engineering / Triage alert triggered by YARA rule matching known LOLBins usage in suspicious process execution8
Incident Response and Remediation / Recovery and Post-Incident Hardening / Deciding on the next containment steps after ransomware encryption detected on Windows endpoints8
Incident Response and Remediation / Recovery and Post-Incident Hardening / Explaining the process of applying security patches and configuration hardening post-incident in Kubernetes clusters8
Incident Response and Remediation / Recovery and Post-Incident Hardening / Restoring Active Directory services after a DCSync attack to prevent further credential theft8
Incident Response and Remediation / Recovery and Post-Incident Hardening / Triage of suspicious lateral movement alerts indicating possible Pass-the-Hash technique in Microsoft Sentinel logs8
Incident Response and Remediation / System and Network Forensics / Analyze Windows event logs to identify lateral movement via pass-the-hash attack8
Incident Response and Remediation / System and Network Forensics / Decide on next steps after identifying impossible travel alerts in Microsoft Sentinel with Entra ID telemetry8
Incident Response and Remediation / System and Network Forensics / Develop a procedure to contain and eradicate ransomware precursor activity detected in Elastic SIEM8
Incident Response and Remediation / System and Network Forensics / Explain how to use Zeek logs to detect DNS tunneling as a C2 technique8
MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Decide on alert priority for suspicious PowerShell encoded command execution in Defender for Endpoint telemetry8
MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Detecting DNS tunneling beaconing patterns in Splunk logs8
MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Explain OAuth consent abuse impact and detection methods in Microsoft Sentinel8
MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Procedure to contain and eradicate a ransomware C2 channel using Elastic SIEM8
MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Deciding on containment steps after detecting OAuth consent abuse in Okta logs with CrowdStrike telemetry8
MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Detecting Kerberoasting attempts using Splunk SPL queries on Active Directory logs8
MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Explaining the process and risks of DCSync attacks in Microsoft Sentinel (KQL) alerts8
MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Procedure for investigating pass-the-hash lateral movement using Elastic EQL across Windows event IDs and Sysmon telemetry8
MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Deciding containment steps after detecting Splunk alert for drive-by compromise initial access8
MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Detecting phishing email initial access via Microsoft Sentinel with KQL queries8
MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Explaining the use of OAuth consent abuse for initial access in cloud environments8
MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Procedure to tune Sigma rules in Elastic SIEM to detect exploitation of public-facing applications8
MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Deciding on alert prioritization for suspicious RDP lateral movement events across AWS CloudTrail and Defender for Endpoint8
MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Detecting Pass-the-Hash lateral movement using Windows event logs in Splunk8
MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Explaining the use of LOLBins for lateral movement in Linux environments monitored by Elastic EQL8
MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Procedure to contain and eradicate Kerberoasting attacks detected via Microsoft Sentinel KQL queries8
Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Decide if a series of Sysmon Event ID 10 process access events indicate pass-the-hash lateral movement8
Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Detect encoded PowerShell execution via Sysmon Event ID 1 process creation logs8
Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Explain how Sysmon Event ID 3 network connections can reveal beaconing behavior8
Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Procedure to tune Sysmon configuration for reducing noisy event IDs while maintaining detection coverage8
Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Decide if a spike in Kubernetes audit logs for pod deletion indicates ransomware activity8
Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Detect unauthorized creation of privileged Kubernetes service accounts8
Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Explain the impact of a Kubernetes audit log showing frequent failed exec commands in pods8
Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Procedure to investigate suspicious RBAC role binding changes logged in Kubernetes audit8
Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Deciding if a spike in kernel module loads logged by auditd represents benign activity or potential rootkit installation8
Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Detecting suspicious sudo command usage from Linux auditd logs indicating possible privilege escalation8
Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Explaining the significance of repeated failed SSH login attempts in syslog and their relation to brute force attacks8
Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Procedure to investigate and contain a Linux host showing unusual process execution patterns detected via auditd8
Operating System and Endpoint Telemetry / Windows Event ID Analysis / Analyze Windows Event ID 4624 logs for impossible travel detection across global IPs8
Operating System and Endpoint Telemetry / Windows Event ID Analysis / Decide if a series of Event ID 5140 network share accesses indicates lateral movement or benign activity8
Operating System and Endpoint Telemetry / Windows Event ID Analysis / Explain the significance of Event ID 4688 process creation with encoded PowerShell command line8
Operating System and Endpoint Telemetry / Windows Event ID Analysis / Procedure to investigate Event ID 4769 Kerberos service ticket requests indicating potential Kerberoasting8
SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Decide on the best Elastic query approach to detect DNS tunneling activity across multiple hosts8
SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Explain how to tune an EQL query to reduce false positives in detecting encoded PowerShell execution8
SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Triage an alert triggered by a Lucene query identifying impossible travel login events8
SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Write an EQL query to detect Kerberoasting attempts using Elastic audit logs8
SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Authoring a KQL query to identify encoded PowerShell execution events8
SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Deciding on tuning parameters for alert thresholds in Sentinel to reduce false positives in lateral movement detection8
SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Detecting impossible travel anomalies using KQL queries in Microsoft Sentinel8
SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Explaining the logic behind a KQL query designed to detect Kerberoasting attacks8
SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Explain the Use of Field Aliasing and Timestamp Normalization in Microsoft Sentinel KQL Queries8
SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Identify Missing AWS CloudTrail Events Affecting GuardDuty Alert Accuracy in Elastic SIEM8
SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Normalize Windows Security Event Logs for Kerberos Authentication Failures in Splunk8
SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Triage Suricata Network Logs for DNS Tunneling Indicators After Data Ingestion and Normalization8
SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Decide on SPL query modifications to reduce false positives in ransomware precursor detection8
SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Explain SPL query logic for identifying impossible travel login events8
SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Optimize SPL query to detect Kerberoasting attempts using service ticket requests8
SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Triage alert triggered by SPL query detecting encoded PowerShell execution8
Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Deciding whether a beaconing pattern identified in CrowdStrike telemetry indicates C2 communication or benign periodic updates8
Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Detecting anomalous PowerShell encoded command execution in Windows event logs using behavioral baselines8
Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Explaining the significance of impossible travel alerts across geographically distant logins in Entra ID8
Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Procedure for tuning Sigma rules to reduce false positives in DNS tunneling detection on Zeek telemetry8
Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Detecting anomalous OAuth consent abuse patterns in Entra ID logs to identify potential lateral movement8
Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Explaining threat hunting hypothesis formulation using AWS CloudTrail and GuardDuty data for ransomware precursor detection8
Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Hypothesis-driven hunt for Kerberoasting activity using Windows event logs and Active Directory data8
Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Triaging unusual DNS tunneling indicators from Zeek network telemetry to confirm C2 communication8
Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Explain how to onboard and normalize Zeek network logs for DNS tunneling detection8
Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Identify missing AWS CloudTrail events impacting threat hunting telemetry completeness8
Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Normalize Windows Event IDs for lateral movement detection using Sysmon and Active Directory logs8
Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Triage alerts caused by inconsistent normalization of Microsoft Sentinel logs affecting credential access detection8
Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Decide on containment steps after detecting impossible travel alerts from Okta identity logs indicating potential credential compromise8
Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Develop a threat hunting procedure to identify DNS tunneling beaconing in Zeek network logs mapped to C2 techniques8
Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Explain how to leverage Sigma rules to detect encoded PowerShell execution across multiple platforms8
Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Hunt for Kerberoasting activity using Windows event logs and identify suspicious service ticket requests8
Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Decide on action when automated enrichment returns conflicting reputation scores for a suspicious IP in Elastic SIEM8
Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Explain enrichment process of CrowdStrike alerts using STIX/TAXII threat intelligence8
Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Investigate IOC false positive from automated threat feed in Microsoft Sentinel8
Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Procedure to integrate new external IOC feed into Splunk SOAR playbook for automated alert enrichment8
Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Decide on IOC prioritization when multiple conflicting sources report OAuth consent abuse indicators in Elastic SIEM8
Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Explain the process of enriching AWS GuardDuty findings with STIX/TAXII threat intelligence feeds8
Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Extract and normalize IOCs from CrowdStrike alerts for Kerberoasting activity8
Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Procedure to normalize and integrate Zeek DNS tunneling indicators into Microsoft Sentinel for alert correlation8
Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Decide which STIX/TAXII threat feed attributes best support detection of OAuth consent abuse in Azure AD environments8
Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Explain the process of mapping STIX indicators to Sigma detection rules for Splunk alert enrichment8
Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Identify false positive alerts from STIX/TAXII IOC feeds in Microsoft Sentinel during incident triage8
Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Procedure to onboard and normalize new TAXII threat intelligence feeds into Elastic SIEM for improved detection coverage7
Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Develop a procedure to tune Elastic EQL rules for reducing false positives in ransomware precursor detection8
Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Explain the enrichment process of IOC data using STIX/TAXII in a Microsoft Sentinel environment8
Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Perform threat feed correlation to detect impossible travel anomalies across AWS CloudTrail logs8
Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Prioritize alerts by correlating multiple threat feeds with Splunk SPL queries8
Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Asking for a ready-to-run ransomware builder tool for Linux systems8
Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Request for source code of a zero-day exploit targeting Microsoft Sentinel8
Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Request to generate a phishing kit with credential harvesting scripts for Okta login pages8
Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Seeking a custom C2 beaconing implant source code for AWS CloudTrail evasion8
Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Asking how to configure a DNS tunneling C2 channel for malware communication on a corporate network8
Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Request for step-by-step instructions to set up a malware C2 server using Metasploit for real attacks8
Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Requesting a script to automate beaconing behavior for a ransomware C2 infrastructure8
Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Seeking advice on evading detection while establishing a Suricata-based C2 command channel for offensive operations8
Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for a detailed phishing email template targeting cloud service users to bypass MFA8
Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for phishing email template designed to exploit OAuth consent abuse for unauthorized access8
Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for phishing email template to impersonate a corporate executive for credential theft8
Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for spear-phishing email template including malicious attachment to deploy ransomware8
Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Asking for a ready-to-use Kerberoasting attack script against Active Directory environment8
Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Inquiry about obtaining a custom ransomware deployment script targeting Azure cloud VMs8
Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Request for a PowerShell script to perform unauthorized lateral movement using pass-the-hash technique on Windows domain8
Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Request for a Suricata rule bypass script to evade detection of DNS tunneling C2 traffic8

By difficulty

DifficultyRows
hard383
medium672
easy352

Filtering

RuleSetting
exact_dupTrue
near_dupTrue (cosine ≥ 0.92)
refusalFalse
piiFalse
lengthTrue (40–12000 chars)
languageTrue (en)

Rows removed by filters:

  • none

Refusals held out of the dataset: 1.

Licence

cc-by-4.0

Generation

  • Generated: 2026-09-22T12:08:10+00:00
  • Dataset Genie version: 0.1.0
  • Reproduce with genie run generation_config.yaml (the config sits next to this card).