k3nn3dy/blueteam-v1
Blue_team_v1 Synthetic fine-tuning dataset generated with Dataset Genie 0.1.0 on 2026-09-22T12:08:10+00:00. Domain brief Blue-team is broad. Cover these deliberately, spread across difficulty tiers: Platforms, not one vendor. Splunk (SPL), Microsoft Sentinel (KQL), Elastic (ES|QL/EQL/Lucene), CrowdStrike, Defender for Endpoint, Sysmon, Zeek/Suricata. Identity: Entra ID, Okta, Active Directory/Kerberos. Cloud: AWS (CloudTrail/GuardDuty), Azure, GCP. OS: Windows… See the full description on the dataset page: https://huggingface.co/datasets/k3nn3dy/blueteam-v1.
Blueteamv1
Synthetic fine-tuning dataset generated with Dataset Genie 0.1.0 on 2026-09-22T12:08:10+00:00.
Domain brief
Blue-team is broad. Cover these deliberately, spread across difficulty tiers:
Platforms, not one vendor. Splunk (SPL), Microsoft Sentinel (KQL), Elastic (ES|QL/EQL/Lucene), CrowdStrike, Defender for Endpoint, Sysmon, Zeek/Suricata. Identity: Entra ID, Okta, Active Directory/Kerberos. Cloud: AWS (CloudTrail/GuardDuty), Azure, GCP. OS: Windows event IDs, Linux auditd/syslog, Kubernetes audit. Map to MITRE ATT&CK. Ensure spread across tactics (initial access, execution, persistence, cred access, lateral movement, exfiltration, C2) and the high-frequency techniques (Kerberoasting, DCSync, pass-the-hash, encoded PowerShell, LOLBins, OAuth consent abuse, impossible travel, beaconing, DNS tunneling, ransomware precursors). Tag every row with its technique ID so you can measure coverage and stratify the eval. The blue-team workflow, end to end. Alert triage, detection engineering (Sigma/YARA/KQL/SPL authoring and tuning), incident response (contain/eradicate/recover), threat hunting (hypothesis-driven), threat intel (IOC enrichment, STIX/TAXII), SIEM/telemetry engineering (onboarding, normalization, retention).
Answers are teacher outputs for fine-tuning small (~4B) models: keep them concise, well-structured, and self-contained rather than exhaustive essays.
Files
| Format | Trainer | Train rows | Eval rows |
|---|---|---|---|
sft/ | SFTTrainer + trainonresponses_only | 1337 | 70 |
alpaca/ | SFTTrainer + alpaca prompt template | 1337 | 70 |
Every file is JSON Lines: one UTF-8 JSON object per line, \n line endings, no \u escapes. Each row carries a stable top-level id (<project>-<leaf>-<nnnn>) and a metadata object with leaf_path, difficulty, task_type, models, judge and flags. Split: 95 / 5 stratified by leaf, seed 42. Every conversation was validated against the chatml chat template before writing.
Provenance
Models per stage (OpenRouter slugs)
| Stage | Model |
|---|---|
| taxonomy | openai/gpt-4.1-mini |
| prompts | openai/gpt-4.1-mini |
| responses | deepseek/deepseek-chat-v3-0324 |
| judge | openai/gpt-4.1-mini |
Provider pinning
| Slot | provider_order | allow_fallbacks |
|---|---|---|
| taxonomy | (any) | True |
| prompts | (any) | True |
| judge | (any) | True |
| responses[0] | (any) | True |
Judge rubric
| Criterion | Weight | Description |
|---|---|---|
| Correctness | 40 | Facts and commands are accurate. |
| Actionability | 25 | Gives concrete next steps. |
| Style adherence | 20 | Matches the requested style and system prompt. |
| Safety | 15 | Redirects unsafe/out-of-scope requests appropriately. |
Weighted score normalised to 0–5. Low-score threshold: 3.0. Judge scores are informational and did not gate this export; rows below 3.0 are kept and flagged low_score in their metadata.
Counts
By leaf
| Leaf | Rows |
|---|---|
| Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Decide escalation steps for ransomware precursor alerts correlated from Elastic SIEM and CrowdStrike telemetry | 8 |
| Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Explain the context enrichment process for alerts triggered by impossible travel detections in Microsoft Sentinel | 8 |
| Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Prioritize alerts involving Kerberoasting attempts detected via Splunk correlation searches | 8 |
| Alert Triage and Incident Prioritization / Correlation and Context Enrichment / Procedure to enrich and correlate OAuth consent abuse alerts using Okta and Azure AD telemetry | 8 |
| Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Decide escalation path for detected encoded PowerShell execution with suspicious parent process | 8 |
| Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Explain rationale for assigning incident severity based on DNS tunneling detection in network telemetry | 8 |
| Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Prioritize alerts for possible Kerberoasting activity in Active Directory logs | 8 |
| Alert Triage and Incident Prioritization / Escalation and Incident Assignment / Procedure for assigning incident ownership after identifying impossible travel alerts in Entra ID logs | 8 |
| Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Decide on noise reduction strategy for frequent Okta impossible travel login alerts | 8 |
| Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Explain initial validation steps for AWS GuardDuty DNS tunneling detection | 8 |
| Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Procedure to triage Microsoft Sentinel alert indicating Kerberoasting activity in Active Directory | 8 |
| Alert Triage and Incident Prioritization / Initial Alert Validation and Noise Reduction / Validate Splunk alert for encoded PowerShell execution on Windows hosts | 8 |
| Alert Triage and Incident Prioritization / Severity and Impact Assessment / Assess severity of a Splunk alert triggered by Kerberoasting activity in Active Directory | 8 |
| Alert Triage and Incident Prioritization / Severity and Impact Assessment / Decide prioritization for multiple simultaneous alerts including impossible travel and OAuth consent abuse in Entra ID | 8 |
| Alert Triage and Incident Prioritization / Severity and Impact Assessment / Explain impact of detected encoded PowerShell execution on a Windows host using Sysmon logs | 8 |
| Alert Triage and Incident Prioritization / Severity and Impact Assessment / Procedure to evaluate ransomware precursor indicators from AWS GuardDuty findings and correlate with Azure Sentinel logs | 8 |
| Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Decide on containment steps after detecting ransomware precursor behaviors via CloudTrail logs | 8 |
| Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Explain how GuardDuty detects DNS tunneling activities within AWS environments | 8 |
| Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Procedure to enrich GuardDuty findings with STIX/TAXII threat intelligence feeds | 8 |
| Cloud Security Monitoring and Logging / AWS CloudTrail and GuardDuty Integration / Triage unusual AWS CloudTrail API calls indicating potential unauthorized access | 8 |
| Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Decide on alert prioritization strategy for Azure Sentinel alerts related to beaconing and DNS tunneling C2 techniques | 8 |
| Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Detect impossible travel anomalies using Azure Sentinel with Entra ID logs | 8 |
| Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Explain how to tune Azure Security Center alerts to reduce false positives for ransomware precursor activities | 8 |
| Cloud Security Monitoring and Logging / Azure Security Center and Sentinel Monitoring / Procedure to investigate and contain OAuth consent abuse detected in Azure Sentinel | 8 |
| Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Deciding on alert prioritization for anomalous GCP IAM permission changes detected in audit logs | 8 |
| Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Detecting impossible travel events in Azure AD sign-in logs using KQL | 8 |
| Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Explaining OAuth consent abuse risks and detection methods in Okta environments | 8 |
| Cloud Security Monitoring and Logging / Cloud Identity and Access Management (IAM) Monitoring / Procedure to investigate and contain suspicious AWS IAM role assumption activity via CloudTrail logs | 8 |
| Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Deciding on alert prioritization for anomalous GCP Compute Engine instance creations across regions | 8 |
| Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Detecting unauthorized service account key creation in GCP Cloud Audit Logs | 8 |
| Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Explaining GCP Cloud Audit Logs entries related to suspicious IAM role escalations | 8 |
| Cloud Security Monitoring and Logging / GCP Cloud Audit Logs Analysis / Procedure to investigate unusual data exfiltration patterns via GCP Cloud Storage access logs | 8 |
| Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Decide on alert escalation for CrowdStrike detection of Kerberoasting attempts with low confidence score | 8 |
| Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Explain false positive causes in Microsoft Sentinel KQL rule detecting impossible travel events | 8 |
| Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Procedure to tune Elastic EQL rule for reducing noise in DNS tunneling detection alerts | 8 |
| Detection Engineering and Rule Authoring / Alert Triage and False Positive Reduction Techniques / Triage alert for suspicious encoded PowerShell execution flagged by Splunk SPL rule | 8 |
| Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Decide which MITRE ATT&CK technique ID best maps to a CrowdStrike detection of pass-the-hash lateral movement | 8 |
| Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Explain how to tune a Defender for Endpoint alert for suspicious LOLBins usage to reduce false positives | 8 |
| Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Triage an alert from Defender for Endpoint indicating possible ransomware precursor behavior using event correlation | 8 |
| Detection Engineering and Rule Authoring / Detection Rule Development for Endpoint Security (CrowdStrike, Defender) / Write a detection rule in CrowdStrike Falcon to identify encoded PowerShell execution indicative of malware delivery | 8 |
| Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Decide which EQL query modifications are needed to detect DNS tunneling activity in Elastic SIEM | 8 |
| Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Explain how to tune a KQL rule in Microsoft Sentinel to reduce false positives for impossible travel alerts | 8 |
| Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Triage an alert generated by a CrowdStrike rule detecting Kerberoasting attempts using event logs | 8 |
| Detection Engineering and Rule Authoring / SIEM Query Languages and Syntax (SPL, KQL, EQL) / Write a Splunk SPL query to detect encoded PowerShell execution using command-line arguments | 8 |
| Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Detecting DNS tunneling via unusual query patterns in Zeek logs | 8 |
| Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Explaining detection logic for lateral movement using SMB traffic analysis in Suricata | 8 |
| Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Triaging beaconing alerts from Zeek connection logs for potential C2 activity | 8 |
| Detection Engineering and Rule Authoring / Threat Detection Using Network Traffic Analysis (Zeek, Suricata) / Tuning Suricata rules to reduce false positives on common LOLBins network behaviors | 8 |
| Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Decide on alert prioritization for suspicious privilege escalation events across Microsoft Sentinel and Splunk | 8 |
| Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Detecting Kerberoasting attempts via anomalous service ticket requests in Active Directory logs | 8 |
| Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Explain OAuth consent abuse impact and detection methods in Entra ID environments | 8 |
| Identity and Access Management Systems / Access Control and Privilege Escalation Monitoring / Procedure to investigate and contain DCSync attacks detected through Okta and AD audit logs | 8 |
| Identity and Access Management Systems / Active Directory and Kerberos Authentication / Decide on the legitimacy of an unusual authentication event flagged by impossible travel detection | 8 |
| Identity and Access Management Systems / Active Directory and Kerberos Authentication / Detect and triage suspicious Kerberoasting requests in Active Directory logs | 8 |
| Identity and Access Management Systems / Active Directory and Kerberos Authentication / Explain the process and risks of a DCSync attack using compromised credentials | 8 |
| Identity and Access Management Systems / Active Directory and Kerberos Authentication / Procedure to contain and remediate pass-the-hash lateral movement in a Windows domain | 8 |
| Identity and Access Management Systems / Cloud Identity Providers and Federation / Decide on appropriate alert tuning to reduce false positives in GCP Identity-Aware Proxy logs | 8 |
| Identity and Access Management Systems / Cloud Identity Providers and Federation / Detecting anomalous OAuth consent abuse in Okta logs | 8 |
| Identity and Access Management Systems / Cloud Identity Providers and Federation / Explain the process of federated authentication flow using SAML in Azure AD | 8 |
| Identity and Access Management Systems / Cloud Identity Providers and Federation / Procedure to investigate and contain a suspected DCSync attack via Active Directory federation | 8 |
| Identity and Access Management Systems / Identity Threat Detection and Mitigation / Deciding on containment actions after detecting DCSync activity via Microsoft Sentinel KQL analytics | 8 |
| Identity and Access Management Systems / Identity Threat Detection and Mitigation / Detecting Kerberoasting attacks in Active Directory using Splunk SPL queries | 8 |
| Identity and Access Management Systems / Identity Threat Detection and Mitigation / Explaining OAuth consent abuse scenarios and mitigation strategies in Okta environments | 8 |
| Identity and Access Management Systems / Identity Threat Detection and Mitigation / Procedure for investigating and responding to impossible travel alerts in Entra ID logs | 8 |
| Incident Response and Remediation / Containment Strategies and Isolation Techniques / Decide on containment steps for a Linux server detected with suspicious lateral movement via SSH | 8 |
| Incident Response and Remediation / Containment Strategies and Isolation Techniques / Explain how to use Splunk SPL queries to identify and contain beaconing C2 traffic | 8 |
| Incident Response and Remediation / Containment Strategies and Isolation Techniques / Isolate a Windows host showing ransomware precursor behaviors using Defender for Endpoint | 8 |
| Incident Response and Remediation / Containment Strategies and Isolation Techniques / Triage an alert from Azure Sentinel indicating possible OAuth consent abuse and recommend isolation actions | 8 |
| Incident Response and Remediation / Malware Analysis and Reverse Engineering / Analyze encoded PowerShell script extracted from ransomware sample to identify execution flow and persistence mechanism | 8 |
| Incident Response and Remediation / Malware Analysis and Reverse Engineering / Determine containment steps after detecting beaconing behavior linked to malware C2 communication in Windows event logs | 8 |
| Incident Response and Remediation / Malware Analysis and Reverse Engineering / Follow procedure to reverse engineer a suspicious Linux ELF binary found during incident response to identify credential access techniques | 8 |
| Incident Response and Remediation / Malware Analysis and Reverse Engineering / Triage alert triggered by YARA rule matching known LOLBins usage in suspicious process execution | 8 |
| Incident Response and Remediation / Recovery and Post-Incident Hardening / Deciding on the next containment steps after ransomware encryption detected on Windows endpoints | 8 |
| Incident Response and Remediation / Recovery and Post-Incident Hardening / Explaining the process of applying security patches and configuration hardening post-incident in Kubernetes clusters | 8 |
| Incident Response and Remediation / Recovery and Post-Incident Hardening / Restoring Active Directory services after a DCSync attack to prevent further credential theft | 8 |
| Incident Response and Remediation / Recovery and Post-Incident Hardening / Triage of suspicious lateral movement alerts indicating possible Pass-the-Hash technique in Microsoft Sentinel logs | 8 |
| Incident Response and Remediation / System and Network Forensics / Analyze Windows event logs to identify lateral movement via pass-the-hash attack | 8 |
| Incident Response and Remediation / System and Network Forensics / Decide on next steps after identifying impossible travel alerts in Microsoft Sentinel with Entra ID telemetry | 8 |
| Incident Response and Remediation / System and Network Forensics / Develop a procedure to contain and eradicate ransomware precursor activity detected in Elastic SIEM | 8 |
| Incident Response and Remediation / System and Network Forensics / Explain how to use Zeek logs to detect DNS tunneling as a C2 technique | 8 |
| MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Decide on alert priority for suspicious PowerShell encoded command execution in Defender for Endpoint telemetry | 8 |
| MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Detecting DNS tunneling beaconing patterns in Splunk logs | 8 |
| MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Explain OAuth consent abuse impact and detection methods in Microsoft Sentinel | 8 |
| MITRE ATT&CK Techniques and Tactics / Command and Control Mechanisms / Procedure to contain and eradicate a ransomware C2 channel using Elastic SIEM | 8 |
| MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Deciding on containment steps after detecting OAuth consent abuse in Okta logs with CrowdStrike telemetry | 8 |
| MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Detecting Kerberoasting attempts using Splunk SPL queries on Active Directory logs | 8 |
| MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Explaining the process and risks of DCSync attacks in Microsoft Sentinel (KQL) alerts | 8 |
| MITRE ATT&CK Techniques and Tactics / Credential Access Methods / Procedure for investigating pass-the-hash lateral movement using Elastic EQL across Windows event IDs and Sysmon telemetry | 8 |
| MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Deciding containment steps after detecting Splunk alert for drive-by compromise initial access | 8 |
| MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Detecting phishing email initial access via Microsoft Sentinel with KQL queries | 8 |
| MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Explaining the use of OAuth consent abuse for initial access in cloud environments | 8 |
| MITRE ATT&CK Techniques and Tactics / Initial Access Techniques / Procedure to tune Sigma rules in Elastic SIEM to detect exploitation of public-facing applications | 8 |
| MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Deciding on alert prioritization for suspicious RDP lateral movement events across AWS CloudTrail and Defender for Endpoint | 8 |
| MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Detecting Pass-the-Hash lateral movement using Windows event logs in Splunk | 8 |
| MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Explaining the use of LOLBins for lateral movement in Linux environments monitored by Elastic EQL | 8 |
| MITRE ATT&CK Techniques and Tactics / Lateral Movement Strategies / Procedure to contain and eradicate Kerberoasting attacks detected via Microsoft Sentinel KQL queries | 8 |
| Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Decide if a series of Sysmon Event ID 10 process access events indicate pass-the-hash lateral movement | 8 |
| Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Detect encoded PowerShell execution via Sysmon Event ID 1 process creation logs | 8 |
| Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Explain how Sysmon Event ID 3 network connections can reveal beaconing behavior | 8 |
| Operating System and Endpoint Telemetry / Endpoint Detection with Sysmon / Procedure to tune Sysmon configuration for reducing noisy event IDs while maintaining detection coverage | 8 |
| Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Decide if a spike in Kubernetes audit logs for pod deletion indicates ransomware activity | 8 |
| Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Detect unauthorized creation of privileged Kubernetes service accounts | 8 |
| Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Explain the impact of a Kubernetes audit log showing frequent failed exec commands in pods | 8 |
| Operating System and Endpoint Telemetry / Kubernetes Audit Logging / Procedure to investigate suspicious RBAC role binding changes logged in Kubernetes audit | 8 |
| Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Deciding if a spike in kernel module loads logged by auditd represents benign activity or potential rootkit installation | 8 |
| Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Detecting suspicious sudo command usage from Linux auditd logs indicating possible privilege escalation | 8 |
| Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Explaining the significance of repeated failed SSH login attempts in syslog and their relation to brute force attacks | 8 |
| Operating System and Endpoint Telemetry / Linux Auditd and Syslog Monitoring / Procedure to investigate and contain a Linux host showing unusual process execution patterns detected via auditd | 8 |
| Operating System and Endpoint Telemetry / Windows Event ID Analysis / Analyze Windows Event ID 4624 logs for impossible travel detection across global IPs | 8 |
| Operating System and Endpoint Telemetry / Windows Event ID Analysis / Decide if a series of Event ID 5140 network share accesses indicates lateral movement or benign activity | 8 |
| Operating System and Endpoint Telemetry / Windows Event ID Analysis / Explain the significance of Event ID 4688 process creation with encoded PowerShell command line | 8 |
| Operating System and Endpoint Telemetry / Windows Event ID Analysis / Procedure to investigate Event ID 4769 Kerberos service ticket requests indicating potential Kerberoasting | 8 |
| SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Decide on the best Elastic query approach to detect DNS tunneling activity across multiple hosts | 8 |
| SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Explain how to tune an EQL query to reduce false positives in detecting encoded PowerShell execution | 8 |
| SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Triage an alert triggered by a Lucene query identifying impossible travel login events | 8 |
| SIEM Platforms and Query Languages / Elastic Stack EQL and Lucene Query Usage / Write an EQL query to detect Kerberoasting attempts using Elastic audit logs | 8 |
| SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Authoring a KQL query to identify encoded PowerShell execution events | 8 |
| SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Deciding on tuning parameters for alert thresholds in Sentinel to reduce false positives in lateral movement detection | 8 |
| SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Detecting impossible travel anomalies using KQL queries in Microsoft Sentinel | 8 |
| SIEM Platforms and Query Languages / Microsoft Sentinel KQL Query Development / Explaining the logic behind a KQL query designed to detect Kerberoasting attacks | 8 |
| SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Explain the Use of Field Aliasing and Timestamp Normalization in Microsoft Sentinel KQL Queries | 8 |
| SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Identify Missing AWS CloudTrail Events Affecting GuardDuty Alert Accuracy in Elastic SIEM | 8 |
| SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Normalize Windows Security Event Logs for Kerberos Authentication Failures in Splunk | 8 |
| SIEM Platforms and Query Languages / SIEM Data Ingestion and Normalization Techniques / Triage Suricata Network Logs for DNS Tunneling Indicators After Data Ingestion and Normalization | 8 |
| SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Decide on SPL query modifications to reduce false positives in ransomware precursor detection | 8 |
| SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Explain SPL query logic for identifying impossible travel login events | 8 |
| SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Optimize SPL query to detect Kerberoasting attempts using service ticket requests | 8 |
| SIEM Platforms and Query Languages / Splunk SPL Query Writing and Optimization / Triage alert triggered by SPL query detecting encoded PowerShell execution | 8 |
| Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Deciding whether a beaconing pattern identified in CrowdStrike telemetry indicates C2 communication or benign periodic updates | 8 |
| Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Detecting anomalous PowerShell encoded command execution in Windows event logs using behavioral baselines | 8 |
| Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Explaining the significance of impossible travel alerts across geographically distant logins in Entra ID | 8 |
| Threat Hunting Methodologies / Behavioral Analytics and Anomaly Detection / Procedure for tuning Sigma rules to reduce false positives in DNS tunneling detection on Zeek telemetry | 8 |
| Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Detecting anomalous OAuth consent abuse patterns in Entra ID logs to identify potential lateral movement | 8 |
| Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Explaining threat hunting hypothesis formulation using AWS CloudTrail and GuardDuty data for ransomware precursor detection | 8 |
| Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Hypothesis-driven hunt for Kerberoasting activity using Windows event logs and Active Directory data | 8 |
| Threat Hunting Methodologies / Hypothesis-Driven Threat Hunting / Triaging unusual DNS tunneling indicators from Zeek network telemetry to confirm C2 communication | 8 |
| Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Explain how to onboard and normalize Zeek network logs for DNS tunneling detection | 8 |
| Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Identify missing AWS CloudTrail events impacting threat hunting telemetry completeness | 8 |
| Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Normalize Windows Event IDs for lateral movement detection using Sysmon and Active Directory logs | 8 |
| Threat Hunting Methodologies / Telemetry Data Collection and Normalization / Triage alerts caused by inconsistent normalization of Microsoft Sentinel logs affecting credential access detection | 8 |
| Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Decide on containment steps after detecting impossible travel alerts from Okta identity logs indicating potential credential compromise | 8 |
| Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Develop a threat hunting procedure to identify DNS tunneling beaconing in Zeek network logs mapped to C2 techniques | 8 |
| Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Explain how to leverage Sigma rules to detect encoded PowerShell execution across multiple platforms | 8 |
| Threat Hunting Methodologies / Threat Hunting with MITRE ATT&CK Framework / Hunt for Kerberoasting activity using Windows event logs and identify suspicious service ticket requests | 8 |
| Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Decide on action when automated enrichment returns conflicting reputation scores for a suspicious IP in Elastic SIEM | 8 |
| Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Explain enrichment process of CrowdStrike alerts using STIX/TAXII threat intelligence | 8 |
| Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Investigate IOC false positive from automated threat feed in Microsoft Sentinel | 8 |
| Threat Intelligence Integration and Enrichment / Automated Enrichment with External Intelligence Sources / Procedure to integrate new external IOC feed into Splunk SOAR playbook for automated alert enrichment | 8 |
| Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Decide on IOC prioritization when multiple conflicting sources report OAuth consent abuse indicators in Elastic SIEM | 8 |
| Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Explain the process of enriching AWS GuardDuty findings with STIX/TAXII threat intelligence feeds | 8 |
| Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Extract and normalize IOCs from CrowdStrike alerts for Kerberoasting activity | 8 |
| Threat Intelligence Integration and Enrichment / IOC Extraction and Normalization / Procedure to normalize and integrate Zeek DNS tunneling indicators into Microsoft Sentinel for alert correlation | 8 |
| Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Decide which STIX/TAXII threat feed attributes best support detection of OAuth consent abuse in Azure AD environments | 8 |
| Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Explain the process of mapping STIX indicators to Sigma detection rules for Splunk alert enrichment | 8 |
| Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Identify false positive alerts from STIX/TAXII IOC feeds in Microsoft Sentinel during incident triage | 8 |
| Threat Intelligence Integration and Enrichment / STIX/TAXII Data Sharing Frameworks / Procedure to onboard and normalize new TAXII threat intelligence feeds into Elastic SIEM for improved detection coverage | 7 |
| Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Develop a procedure to tune Elastic EQL rules for reducing false positives in ransomware precursor detection | 8 |
| Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Explain the enrichment process of IOC data using STIX/TAXII in a Microsoft Sentinel environment | 8 |
| Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Perform threat feed correlation to detect impossible travel anomalies across AWS CloudTrail logs | 8 |
| Threat Intelligence Integration and Enrichment / Threat Feed Correlation and Prioritization / Prioritize alerts by correlating multiple threat feeds with Splunk SPL queries | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Asking for a ready-to-run ransomware builder tool for Linux systems | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Request for source code of a zero-day exploit targeting Microsoft Sentinel | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Request to generate a phishing kit with credential harvesting scripts for Okta login pages | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Exploit Development Code / Seeking a custom C2 beaconing implant source code for AWS CloudTrail evasion | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Asking how to configure a DNS tunneling C2 channel for malware communication on a corporate network | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Request for step-by-step instructions to set up a malware C2 server using Metasploit for real attacks | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Requesting a script to automate beaconing behavior for a ransomware C2 infrastructure | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Malware Command and Control Setup / Seeking advice on evading detection while establishing a Suricata-based C2 command channel for offensive operations | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for a detailed phishing email template targeting cloud service users to bypass MFA | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for phishing email template designed to exploit OAuth consent abuse for unauthorized access | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for phishing email template to impersonate a corporate executive for credential theft | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Phishing Email Templates / Request for spear-phishing email template including malicious attachment to deploy ransomware | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Asking for a ready-to-use Kerberoasting attack script against Active Directory environment | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Inquiry about obtaining a custom ransomware deployment script targeting Azure cloud VMs | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Request for a PowerShell script to perform unauthorized lateral movement using pass-the-hash technique on Windows domain | 8 |
| Unauthorized Offensive Hacking Techniques / Requests for Unauthorized Network Intrusion Scripts / Request for a Suricata rule bypass script to evade detection of DNS tunneling C2 traffic | 8 |
By difficulty
| Difficulty | Rows |
|---|---|
| hard | 383 |
| medium | 672 |
| easy | 352 |
Filtering
| Rule | Setting |
|---|---|
| exact_dup | True |
| near_dup | True (cosine ≥ 0.92) |
| refusal | False |
| pii | False |
| length | True (40–12000 chars) |
| language | True (en) |
Rows removed by filters:
- —none
Refusals held out of the dataset: 1.
Licence
cc-by-4.0
Generation
- —Generated: 2026-09-22T12:08:10+00:00
- —Dataset Genie version: 0.1.0
- —Reproduce with
genie run generation_config.yaml(the config sits next to this card).
