datasets
Training and evaluation data, with the modality, task and licence stated up front. Listed live from the Hugging Face Hub.
mitre-stix-cve-exploitdb-dataset-alpaca-chatml-harmony
MITRE+NVD+ExploitDB Dataset (Alpaca/ChatML/Harmony)
A dataset for training AI assistants/agents on vulnerability analysis and pentesting Q&A. It is built by the pentestds pipeline, which fetches and merges data from MITRE CVE, NVD (CVSS enrichment), ExploitDB, and a small set of HuggingFace datasets. Provenance is recorded for every entry, and the pipeline emits Alpaca, ChatML, and Harmony JSONL files.
Dataset Summary
This dataset is designed for training AI agents to… See the full description on the dataset page: https://huggingface.co/datasets/jason-oneal/mitre-stix-cve-exploitdb-dataset-alpaca-chatml-harmony.mit_restaurant[mit_restaurant NER dataset](https://groups.csail.mit.edu/sls/downloads/)mitre-attack-en
MITRE ATT&CK Enterprise - Complete English Dataset
Comprehensive dataset of the MITRE ATT&CK Enterprise framework on Hugging Face. Data extracted automatically from official STIX 2.1 sources.
Description
This dataset covers the entire MITRE ATT&CK Enterprise framework:
14 tactics with full descriptions
691 techniques and sub-techniques (216 techniques + 475 sub-techniques)
44 mitigations with associated techniques
172 threat groups (APTs) with their known techniques
30… See the full description on the dataset page: https://huggingface.co/datasets/AYI-NEDJIMI/mitre-attack-en.mitre-attack-synthetic-scenarios
MITRE ATT&CK Synthetic Scenario Logs v3.0
Expanded Dataset: 30 scenarios × 8 events = 240 synthetic events
Axis
Coverage
Environment
endpoint, cloud, SaaS, identity, CI/CD, OT/IoT
Actor Type
external_apt, ransomware, insider, compromised_vendor, careless_admin, automated_threat
Intent
exfiltration, impact, fraud, persistence, reconnaissance, cryptomining, espionage
Detection Source
EDR, IAM, SIEM, DLP, DNS, proxy, cloud_audit, email_gateway, CASB, NDR, PAM, firewall… See the full description on the dataset page: https://huggingface.co/datasets/koushikcs09/mitre-attack-synthetic-scenarios.mitre-attack-techniques-qa
MITRE ATT&CK Techniques QA
A question–answer dataset covering 475 MITRE ATT&CK Enterprise techniques and sub-techniques,
designed for training and evaluating security-focused language models, RAG assistants for SOC
analysts, and red/blue/purple-team education.
Dataset Summary
Property
Value
Records
475
Language
English
Techniques (parent) covered
222 / 222 (all non-deprecated Enterprise parents)
Sub-techniques covered
253 (selection across the… See the full description on the dataset page: https://huggingface.co/datasets/ismailtasdelen/mitre-attack-techniques-qa.security-attacks-MITREcyber_MITRE_attack_tactics-and-techniquesThe dataset is question answering for MITRE tactics and techniques for version 15. Data sources are:
Tactics
Techniques
mit_restaurantMitre_Attacks_Framework_Dataset
MITRE ATT&CK Enterprise Dataset
Overview
This dataset provides a comprehensive collection of MITRE ATT&CK Enterprise techniques (v14.1) in JSONL format, designed for cybersecurity professionals, red teams, and threat hunters.
Each entry maps to a specific ATT&CK technique, including its ID, name, description, real-world example, and source.
The dataset is structured for seamless integration into security tools such as SIEMs, threat intelligence platforms, or custom red… See the full description on the dataset page: https://huggingface.co/datasets/darkknight25/Mitre_Attacks_Framework_Dataset.mitre-attack-fr
MITRE ATT&CK Enterprise - Dataset Francophone Complet
Premier dataset francophone complet du framework MITRE ATT&CK Enterprise sur Hugging Face. Données extraites automatiquement des sources STIX 2.1 officielles avec traductions françaises professionnelles.
Description
Ce dataset couvre l'intégralité du framework MITRE ATT&CK Enterprise avec :
14 tactiques traduites en français avec descriptions détaillées
691 techniques et sous-techniques (216 techniques + 475… See the full description on the dataset page: https://huggingface.co/datasets/AYI-NEDJIMI/mitre-attack-fr.cyber_MITRE_CTI_dataset_v15This dataset is a specialized resource designed for training and evaluating question-answering models in the context of Cyber Threat Intelligence (CTI), specifically targeting the identification of tactics and techniques based on natural language descriptions of cyber-attacks. The dataset is derived from the MITRE ATT&CK framework (version 15) and contains annotated pairs of sentences and their corresponding tactics and techniques. The primary goal is to assist automated systems in… See the full description on the dataset page: https://huggingface.co/datasets/sarahwei/cyber_MITRE_CTI_dataset_v15.Mitre-ATTACK-reasoning-datasetcybersec_mitre_attack_tactics_techniques_instruction_dataCVE-TO-MITRE
MITRE CVE Community Pack
A comprehensive dataset for training multi-label classifiers to predict MITRE ATT&CK techniques from vulnerability descriptions.
Dataset Description
This dataset contains vulnerability descriptions paired with MITRE ATT&CK technique labels, designed for training and evaluating multi-label text classification models in the cybersecurity domain.
Key Features
Dual-source data: 10,000 real CVE descriptions and 10,000 synthetic… See the full description on the dataset page: https://huggingface.co/datasets/SpongeBOB9684/CVE-TO-MITRE.CyberSecEval-MITREmitre-attack-commandsCTI-to-MITRE-datasetmit-restaurant['AMENITY', 'CUISINE', 'DISH', 'HOURS', 'LOCATION', 'PRICE', 'RATING', 'RESTAURANT_NAME']
mitre-attack-ttp-labeled-instructions
MITRE ATT&CK TTP Mapping Dataset
Training and evaluation data for mapping adversarial behavior descriptions (CTI reports,
CTF writeups, CISA advisories) to MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs).
Built as my individual contribution to a research project conducted at LORIA (supervised by Jean-Yves Marion). This dataset was developed and used to fine-tune skyylord/qwen3-emb-0.6b-ttp with CachedMultipleNegativesRankingLoss and ANCE-style hard negative re-mining.… See the full description on the dataset page: https://huggingface.co/datasets/skyylord/mitre-attack-ttp-labeled-instructions.encoded-MITREmitre-attack-groups
RelayShield MITRE ATT&CK Group-Technique Mapping
A structured slice of MITRE ATT&CK Enterprise data: 189 named threat actor groups, each mapped to its associated ATT&CK techniques and software, with descriptions and source citations.
This is a cleaned, machine-readable export of MITRE's public STIX bundle — useful if you want group→technique mappings without parsing STIX yourself.
Fields
Field
Type
Description
group_id
string
MITRE ATT&CK group ID (e.g.… See the full description on the dataset page: https://huggingface.co/datasets/relayshieldadmin/mitre-attack-groups.mitre_cit_v14
Cloud Matrix Data
Description
This dataset contains information related to cybersecurity techniques, as cataloged by the MITRE ATT&CK framework(v14).
The data includes details such as unique identifiers, names, descriptions, URLs to more information, associated tactics, detection methods, applicable platforms, and data sources for detection. It also specifies whether a technique is a sub-technique of another and lists defenses that the technique may bypass.… See the full description on the dataset page: https://huggingface.co/datasets/voyagar/mitre_cit_v14.mit-restaurantmitre_attackmitre-linux-attck-commandsMitre_Attacks_Framework_Dataset
MITRE ATT&CK Enterprise Dataset
Overview
This dataset provides a comprehensive collection of MITRE ATT&CK Enterprise techniques (v14.1) in JSONL format, designed for cybersecurity professionals, red teams, and threat hunters.
Each entry maps to a specific ATT&CK technique, including its ID, name, description, real-world example, and source.
The dataset is structured for seamless integration into security tools such as SIEMs, threat intelligence platforms, or custom red… See the full description on the dataset page: https://huggingface.co/datasets/JR87/Mitre_Attacks_Framework_Dataset.mitre-bash-commandsMITRE_Attack_Commandsmit-restaurantcyber_MITRE_tactic_CTI_dataset_v16
cyber_MITRE_tactic_CTI_dataset_v16
This dataset contains procedural descriptions from the MITRE ATT&CK framework (v16, Enterprise version). Each entry includes a text column detailing a specific attack method, while the corresponding label indicates the tactic associated with the procedure. The dataset is designed for text classification tasks, aimed at identifying and categorizing attack behaviors based on the described methods.
Data Instances
An example looks as… See the full description on the dataset page: https://huggingface.co/datasets/sarahwei/cyber_MITRE_tactic_CTI_dataset_v16.
