datasets
Training and evaluation data, with the modality, task and licence stated up front. Listed live from the Hugging Face Hub.
malware-samples
This dataset is part of the ULE-CIBERLAB Project: Transfer of knowledge in cybersecurity for the country's business fabric, funded by the European Union NextGeneration-EU, Recovery, Transformation and Resilience Plan, through INCIBE.
MALWARE-SAMPLES DATASET
Disclaimer: This repository contains real samples of malware that can be executed (.exe) and artifacts related with their execution in CAPEv2 sandbox (JSON/HTML reports, screenshots, dropped files). DO NOT execute any of… See the full description on the dataset page: https://huggingface.co/datasets/unileon-robotics/malware-samples.ember2018-malware
EMBER 2018 Malware Analysis Dataset
This dataset contains 1 million records of metadata and vectorized features for malware and benign software.
Visit https://github.com/elastic/ember for more information on the dataset.
Usage
dataset = load_dataset("cw1521/ember2018-malware", field="data")
input - vectorized features as a string
label - (0 for benign and 1 for malware)
Android-Malware-Datasetcommunity-malware-samples
This dataset is part of the ULE-CIBERLAB Project: Transfer of knowledge in cybersecurity for the country's business fabric, funded by the European Union NextGeneration-EU, Recovery, Transformation and Resilience Plan, through INCIBE.
MALWARE-SAMPLES DATASET
Disclaimer: This repository contains real samples of malware that can be executed (.exe) and artifacts related with their execution in CAPEv2 sandbox (JSON/HTML reports, screenshots, dropped files). DO NOT execute any of… See the full description on the dataset page: https://huggingface.co/datasets/unileon-robotics/community-malware-samples.malware-families-catalog
Mirrors and canonical source
This dataset is published identically across multiple platforms. The canonical source is the official SystemHelpDesk MSP site; all mirrors link back to it.
Canonical (SystemHelpDesk MSP): https://malware-families-catalog.systemhelpdesk.com/
Mirror (GitHub Pages): https://jordanricky1604-ship-it.github.io/malware-families-catalog/
GitHub repository: https://github.com/jordanricky1604-ship-it/malware-families-catalog
Hugging Face dataset:… See the full description on the dataset page: https://huggingface.co/datasets/Jordan123234/malware-families-catalog.full-dataset-of-combined-malware-samplesember2018-malware-v2
Ember 2018 Malware Dataset v2
This dataset can be used for classification of malware. It is stored in the jsonl format.
Dataset generated from Ember 2018 upload from https://www.kaggle.com/datasets/dhoogla/ember-2018-v2-features
Usage
-1.0 = Benign
0.0 = Unclassified
1.0 = Malware
cypher-malware-research-cc-by-nc
cypher-malware-research-cc-by-nc
Malware research samples bundle (CC-BY-NC-SA-4.0). 212 GB of CAPE sandbox dynamic analysis traces, trojans, ransomware, RATs, spyware, cryptojacking samples for defensive research. NoCommercial license. Separated from cypher-sft-v3-sources to keep that bundle commercial-clean.
⚠️ License — CC-BY-NC-SA-4.0 (NoCommercial)
This bundle is redistributed under CC-BY-NC-SA-4.0 from the original source
unileon-robotics/malware-samples… See the full description on the dataset page: https://huggingface.co/datasets/jescy525/cypher-malware-research-cc-by-nc.omnimcp_cyber_malware_sandbox_teaser
🔬 INSPECT THE DEEPSEEK-R1 REASONING CHAIN LIVE:
Zero hallucinations. Null syntax errors. 100% AST compiler validated.🌐 Live Interactive Reasoning & Code Inspector: https://emgena.com/trainingslager🎁 Claim your Free Starter Kit (Code: STARTER100): https://emgena.com/trainingslager🏷️ Launch Discount: Get 20 € OFF any 500-incident production suite with code LAUNCH20!
📜 Enterprise Compliance: EU AI Act Articles 50 & 53 certified • 100% DSGVO / GDPR clean • Commercial EULA… See the full description on the dataset page: https://huggingface.co/datasets/emgena/omnimcp_cyber_malware_sandbox_teaser.MalwareSource
MalwareSource
TLDR: Based on Fello's Github repo, theres malware on here so BE WARNED
This is an "mirror" but only of the source code folder of malwares, use with caution, full credits to him and for the original authors.
malware-top-100
Dataset Card for "malware-top-100"
More Information needed
malware-vxunderground-2024-code-decompiled
Malware Source Code and Decompiled C Pseudocode Dataset
Overview
This repository contains a curated dataset of malware source codes and C-like pseudocode obtained through automated decompilation using Ghidra, the reverse engineering framework developed by the NSA.
The dataset is intended for malware analysis, program analysis research, machine learning / LLM-based malware detection, and reverse engineering experiments.
Data Origin
The data is based on the… See the full description on the dataset page: https://huggingface.co/datasets/mikosovsky/malware-vxunderground-2024-code-decompiled.malware-datasetsPowershell_Malware_Detection_DatasetMalware-Families-Small-Datasetwin-exe-malware-analysis
Windows Executable Malware Analysis Dataset
This repository contains the dataset and JSON reports for the thesis research project:
LLM-Based Autonomous Agents for Dynamic Malware Analysis
The dataset was created to evaluate whether Qwen3-4B can classify Windows executables as benign or malicious using reduced CAPEv2 dynamic-analysis reports.
This thesis was part of the 2026 Research Project course from the Computer Science and Engineering Bachelor at TU Delft:… See the full description on the dataset page: https://huggingface.co/datasets/Thcrull/win-exe-malware-analysis.agent-skill-malware
Agent Skill Malware: Malicious vs Benign Agent Skills
Binary classification dataset of OpenClaw agent skill files (SKILL.md).
127 malicious + 223 benign = 350 samples, deduplicated by content hash.
Source
Malicious: Real skills from malicious campaigns targeting ClawHub (Feb 2026), extracted from the openclaw/skills GitHub archive. They use social engineering in markdown instructions to trick agents/users into running malware -- primarily AMOS (Atomic macOS Stealer)… See the full description on the dataset page: https://huggingface.co/datasets/yoonholee/agent-skill-malware.malware-top-100-jtrans
Dataset Card for "malware-top-100-jtrans"
More Information needed
5type_malware_datasetSMU_MalwareDetection
SMU_MalwareDetection PE Assembly Dataset
This dataset consists of assembly code fragments extracted from malicious and benign Portable Executable (PE) files. It was created to support deep learning-based malware classification. Assembly code was segmented using a sliding window technique to preserve contextual information.
⚠️ Note: Class Imbalance
This dataset has a class imbalance, with fewer benign samples (0 label) compared to malware samples (1 label).While… See the full description on the dataset page: https://huggingface.co/datasets/qwewerewq/SMU_MalwareDetection.malware-text-dbcommunity-malware-samples
This dataset is part of the ULE-CIBERLAB Project: Transfer of knowledge in cybersecurity for the country's business fabric, funded by the European Union NextGeneration-EU, Recovery, Transformation and Resilience Plan, through INCIBE.
MALWARE-SAMPLES DATASET
Disclaimer: This repository contains real samples of malware that can be executed (.exe) and artifacts related with their execution in CAPEv2 sandbox (JSON/HTML reports, screenshots, dropped files). DO NOT execute any of… See the full description on the dataset page: https://huggingface.co/datasets/nzeyzz/community-malware-samples.Malwaremalware_analysis
Malware Analysis Dataset
This dataset contains memory forensics analysis data for malware research, including both benign and ransomware samples analyzed with Volatility Framework.
Structure
Dataset Repository (this repo)
Scripts: Volatility automation scripts (Automating_Volatility.py, Volshell_Automation.py, vboxelf.py)
YARA Rules: malware_rules.yar for malware detection
Scan Results: Lightweight analysis outputs:
malfind/ - Process memory… See the full description on the dataset page: https://huggingface.co/datasets/Vedaang/malware_analysis.SMU_MalwareDetection_Year
SMU_MalwareDetection PE Assembly Dataset
This dataset consists of assembly code fragments extracted from malicious and benign Portable Executable (PE) files. It was created to support deep learning-based malware classification and concept drift experiments across malware families and time periods. Assembly code was segmented using a sliding window technique to preserve contextual information.
⚠️ Note: Class Imbalance
This dataset has a class imbalance, with fewer benign… See the full description on the dataset page: https://huggingface.co/datasets/Genticca/SMU_MalwareDetection_Year.SMU_MalwareDetection
SMU_MalwareDetection PE Assembly Dataset
This dataset consists of assembly code fragments extracted from malicious and benign Portable Executable (PE) files. It was created to support deep learning-based malware classification. Assembly code was segmented using a sliding window technique to preserve contextual information.
⚠️ Note: Class Imbalance
This dataset has a class imbalance, with fewer benign samples (0 label) compared to malware samples (1 label).While the… See the full description on the dataset page: https://huggingface.co/datasets/Genticca/SMU_MalwareDetection.africa-malware-dataset
Malware Distribution Networks (Africa) | Africa (Electric Sheep Africa metadata inventory)
Size category: 10K<n<100K - Formats: parquet - Sector: governance_security - Engineered by Electric Sheep Africa
TL;DR
This dataset is part of the Electric Sheep Africa catalog on Hugging Face. It is indexed for African data discovery with standardized metadata, loading guidance, provenance notes, and analyst-oriented context.
What This Dataset Covers… See the full description on the dataset page: https://huggingface.co/datasets/electricsheepafrica/africa-malware-dataset.Malware200M
Zia Malware Detection — 200M Synthetic Records
Dataset Description
A production-grade dataset containing over 200,000,000 rows of high-fidelity synthetic malware analysis events. Built specifically for training binary malware classifiers, multi-class family attribution models, and behavioral anomaly detectors — without exposing real binaries, live telemetry, or proprietary threat intelligence.
Massive Scale: 200M+ rows delivered in Parquet format
Rich Schema: 23… See the full description on the dataset page: https://huggingface.co/datasets/Zia-Data-Labs/Malware200M.XAI_Malware_Predictionmalware-detection-dataset-metadata
Malware Detection Dataset Metadata (No Raw Data)
This repository is a metadata-only reproducibility companion for the malware detection project.
It does not include raw dataset rows, binaries, or redistributable source files.
What this repo includes
feature_schema.json: schema of the 22 numeric PE-header features and target mapping used in the project
download_from_source.py: utility script that downloads the original source archive from the upstream repository
citation… See the full description on the dataset page: https://huggingface.co/datasets/mihai-chindris/malware-detection-dataset-metadata.
